CVE-2026-22795Patch(openssl / openssl)

MEDIUMCVSS 5.5 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch openssl openssl systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid pointer read. The location is constrained to a 1-byte address space, meaning any attempted pointer manipulation can only target addresses between 0x00 and 0xFF. This range corresponds to the zero page, which is unmapped on most modern operating systems and will reliably result in a crash, leading only to a Denial of Service. Exploiting this issue also requires a user or application to process a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted PKCS#12 files in applications as they are usually used to store private keys which are trusted by definition. For these reasons, the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS12 implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0 and 1.1.1 are vulnerable to this issue. OpenSSL 1.0.2 is not affected by this issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 3 mentions (2026-01-27); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline9 mentions / 7d
01223Mentions · 2026-01-27: 3Mentions · 2026-01-28: 1Mentions · 2026-02-03: 1Mentions · 2026-02-17: 1Mentions · 2026-02-19: 1Mentions · 2026-03-15: 1Mentions · 2026-03-19: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-01-27: 2Patch / Workaround · 2026-02-03: 1Technical Details · 2026-01-27: 2Technical Details · 2026-02-03: 1Technical Details · 2026-02-17: 1Technical Details · 2026-03-19: 101-2701-2802-0302-1702-1903-1503-19
Signal classification4 categories
Patch
444.4%
Disclosure
333.3%
General
111.1%
Active Exploitation
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-01-273
Disclosure1Patch2
2026-01-281
Disclosure1
2026-02-031
Patch1
2026-02-171
Disclosure1
2026-02-191
General1
2026-03-151
Patch1
2026-03-191
Active Exploitation1
Full discourse9 posts
  • Kazuki Omo@omokazuki
    Patch

    OpenSSLの脆弱性(High: CVE-2025-15467, Moderate: CVE-2025-11187, Low: CVE-2025-15468等, CVE-2026-22795, 22796)と新バージョン(3.6.1, 3.5.5, 3.4.4, 3.3.6, 3.0.19) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssl #openssl https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260128/

    Post summary

    The post announces multiple OpenSSL CVEs with severity rankings and references new versions that presumably patch them.

    00021425
    360 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎤 RadioCSIRT Ep.602 – Jeudi 19 mars 2026 Neuf sujets. Veille cyber quotidienne. 🔴 KEV / CISA – Ajout de CVE-2026-20131 affectant Cisco Secure Firewall et CVE-2026-20963 impactant Microsoft SharePoint. Deux vulnérabilités de type Deserialization of Untrusted Data activement exploitées. 🔴 Endpoint Management – La CISA alerte sur une attaque visant Stryker avec abus de Microsoft Intune. Exploitation de privilèges et détournement de capacités d’administration centralisée. 🔴 Ubiquiti – Vulnérabilité critique dans UniFi Network affectant plusieurs versions. Impact non documenté mais exposition directe des consoles de gestion réseau. 🔴 CERT-FR / Microsoft – Multiples vulnérabilités référencées CVE-2026-23941 à CVE-2026-4111. Impact non spécifié, dépendances Erlang, libexif et libarchive concernées. 🔴 Roundcube – Vulnérabilités multiples incluant SSRF, XSS et CSRF sur Webmail. Atteinte à la confidentialité et exécution de requêtes côté serveur possibles. 🔴 Mitel – Vulnérabilité XSS affectant MiContact Center et MCX. Injection de code côté client permettant manipulation de session et contenu. 🔴 Splunk – Vulnérabilités multiples dans Universal Forwarder. Références CVE-2025-15467, CVE-2026-22795 et CVE-2026-22796. Impact non précisé. 🔴 Python – CVE-2026-3479. Contournement de politique de sécurité dans CPython. Mécanisme d’exploitation non détaillé publiquement. 🔴 VMware Tanzu – Plus de 100 CVE dans les Buildpacks et composants plateforme. Risque Supply Chain étendu sur dépendances logicielles. 🔴 DPRK – IBM X-Force et Flare identifient une opération impliquant 100 000 faux IT workers infiltrant des entreprises occidentales. Usage de VPN, identités frauduleuses et plateformes freelance. 🔴 NCSC – Publication de recommandations sur la sécurisation des visioconférences. Risques liés aux accès, à la gestion des données et aux fonctionnalités IA. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-602-radiocsirt-edition-francaise-veille-cyber-du-jeudi-19-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #CISA #KEV #Cisco #SharePoint #Deserialization #Endpoint #Intune #Ubiquiti #UniFi #CERTFR #Roundcube #SSRF #XSS #CSRF #Mitel #Splunk #Python #VMware #Tanzu #SupplyChain #NorthKorea #DPRK #IBM #Flare #NCSC #ZeroTrust #CVE #CERT #SOC #CISO #CyberDefense #BlueTeam #InfoSec

    Post summary

    The episode reports on multiple CVEs, noting that several are actively exploited; however, it does not provide PoC, exploit code, or patch details.

    00000101
    413 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-22795 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/422 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Amazon’s Lambda base image no longer includes CVE-2026-22795, indicating the vulnerability has been removed from recent builds and effectively patched.

    0000031
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-22795 impacts openssl-fips-provider-latest in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/422 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE (CVE‑2026‑22795) affecting AWS Lambda base images has been reported, but no PoC, exploit, or patch details are provided.

    0000040
    30 followersView on X
  • Grok@grok
    Disclosure

    The recent OpenSSL vulnerabilities, reportedly found with AI like Claude Opus, include CVE-2025-15467 (high-severity stack buffer overflow in CMS parsing), CVE-2026-22795 (PKCS#12 parsing issue), CVE-2026-22796 (PKCS#7 signature flaw), and others up to 12 total. They were disclosed in late Jan 2026. Check http://openssl.org for full list.

    Post summary

    OpenSSL CVEs were disclosed in late January 2026, detailing several parsing and buffer overflow vulnerabilities. No exploitation, patch, or PoC information is provided.

    00000112
    8.0M followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #SUSE security update patches 7 #OpenSSL 1.1 vulnerabilities (CVE-2025-68160, CVE-2026-22795+). Affects SLES 15 SP4, openSUSE Leap 15.4, Micro distributions. Memory corruption, parsing flaws, encryption issues. Patch now! Read more: 👉 https://tinyurl.com/2a33bca3 #Security https://t.co/NJP1oMfkRX

    Post summary

    SUSE released a critical security update for OpenSSL 1.1 vulnerabilities (CVE-2025-68160, CVE-2026-22795+) affecting SLES 15 SP4, openSUSE Leap 15.4, and micro distributions, addressing memory corruption, parsing flaws, and encryption issues, with an immediate patch available.

    0000060
    1.3K followersView on X
  • DACBARBOS Brand@dacbarbos
    Disclosure

    OpenSSL Security Advisory (corrected - added CVE-2026-22795 and CVE-2026-22796) https://groups.google.com/a/openssl.org/g/openssl-project/c/pwBoo9Tac6M #infosec

    Post summary

    The message announces the addition of two CVEs to an OpenSSL advisory but lacks details on the vulnerability, exploitability, or remediation.

    0000073
    318 followersView on X
  • 〒@teenigma_
    Disclosure

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    The advisory announces several OpenSSL CVEs with associated severity levels but contains no technical details or mitigation information.

    00000156
    348 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-22795: Malformed PKCS#12 files can crash OpenSSL apps (NULL pointer deref, remote, no auth). Update to 3.6.1 / 3.5.5 / 3.4.4 now. Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-22795 #OpenSSL #infosec #AppSec

    Post summary

    The tweet announces CVE-2026-22795, highlighting that malformed PKCS#12 files can crash OpenSSL applications via a NULL pointer deref, and urges users to update to OpenSSL 3.6.1, 3.5.5, or 3.4.4, with a link to the full advisory.

    0000085
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more