CVE-2026-18798Patch(openssl / openssl)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch openssl openssl systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-415

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-08-26); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-08-25: 1Mentions · 2026-08-26: 2Mentions · 2026-08-27: 1Mentions · 2026-08-30: 2Mentions · 2026-08-31: 1Active Exploitation · 2026-08-30: 2Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-30: 2Patch / Workaround · 2026-08-31: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-30: 2Technical Details · 2026-08-31: 108-2508-2608-2708-3008-31
Signal classification3 categories
Patch
457.1%
Active Exploitation
228.6%
Disclosure
114.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-251
Patch1
2026-08-262
Disclosure1Patch1
2026-08-271
Patch1
2026-08-302
Active Exploitation2
2026-08-311
Patch1
Full discourse7 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now. #OpenSSL #CyberSecurity #CVE #DenialOfService #InfoSec https://securityonline.info/openssl-security-update-august-2026/

    Post summary

    The August 2026 OpenSSL update addresses multiple flaws, including CVE-2026-18798, and a patch is now available.

    02040454
    13.0K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    OpenSSLの脆弱性(CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssh #openssl #ssl https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260826/

    Post summary

    The tweet announces the presence of several OpenSSL CVEs and links to a site for further information, but provides no deeper technical or exploit details.

    00021250
    374 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Nodemailer flaw (CVE-2026-82662) disables TLS cert checks, exposing OAuth2 tokens. OpenSSL patches critical QUIC/TLS bugs (CVE-2026-18798), risking real-time comms & data integrity. Patch now! #Cybersecurity #DataPrivacy #Vulnerabilities

    Post summary

    The post alerts to a Nodemailer flaw (CVE‑2026‑82662) that bypasses TLS certificate verification, exposing OAuth tokens, and urges users to patch immediately. It also references OpenSSL patching of related QUIC/TLS bugs to mitigate associated data integrity risks.

    0000039
    17 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Active Exploitation

    Recent critical flaws: OpenSSL patched QUIC double free (CVE-2026-18798, Aug 25), risking data integrity in transit. Actively exploited Zimbra RCE (CVE-2026-73570) jeopardizes real-time comms privacy & integrity. Patch immediately! #Cybersecurity #ZeroDay #News

    Post summary

    The post alerts that two critical CVEs are known, with the Zimbra RCE actively exploited, and urges immediate patching while also mentioning the OpenSSL double‑free flaw.

    0000091
    17 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Active Exploitation

    Recent RCE in Redis TLS (CVE-2026-81934) exposes data privacy. OpenSSL QUIC (CVE-2026-18798) faces DoS. PaperCut (CVE-2026-81578) RCE actively exploited, threatening backend integrity. Patch now! #Cybersecurity #News #Vulnerabilities

    Post summary

    PaperCut RCE (CVE-2026-81578) is actively exploited, prompting an urgent patch, while Redis TLS and OpenSSL QUIC vulnerabilities are highlighted but not reported as currently exploited.

    0000082
    17 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    OpenSSL patched 9 flaws (Aug 26), notably a QUIC server double-free (CVE-2026-18798). This jeopardizes data integrity & transit availability via secure protocols. Patch ASAP! #Cybersecurity #Vulnerabilities #OpenSSL

    Post summary

    OpenSSL highlights a QUIC server double‑free (CVE‑2026‑18798) that could affect data integrity and availability, urging users to apply the patch immediately.

    0000038
    17 followersView on X
  • 必殺 ちゃぶ台返し@Sh1n_K_NO_S01aR
    Patch

    OpenSSLの脆弱性(CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803)と4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22, 1.1.1zi,1.0.2zrリリース https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260826/

    Post summary

    The post highlights newly released OpenSSL versions that address multiple CVEs, emphasizing patch availability rather than exploitation or technical details.

    0000050
    219 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more