CVE-2026-22796General(openssl / openssl)

MEDIUMCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch openssl openssl systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data. Impact summary: An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service. The function PKCS7_digest_from_attributes() accesses the message digest attribute value without validating its type. When the type is not V_ASN1_OCTET_STRING, this results in accessing invalid memory through the ASN1_TYPE union, causing a crash. Exploiting this vulnerability requires an attacker to provide a malformed signed PKCS#7 to an application that verifies it. The impact of the exploit is just a Denial of Service, the PKCS7 API is legacy and applications should be using the CMS API instead. For these reasons the issue was assessed as Low severity. The FIPS modules in 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the PKCS#7 parsing implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4, 3.3, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-01-27); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-01-27: 2Mentions · 2026-01-28: 1Mentions · 2026-02-17: 1Mentions · 2026-03-15: 1Mentions · 2026-03-19: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-01-27: 1Technical Details · 2026-01-27: 1Technical Details · 2026-02-17: 1Technical Details · 2026-03-19: 101-2701-2802-1703-1503-19
Signal classification4 categories
General
233.3%
Disclosure
233.3%
Patch
116.7%
Active Exploitation
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-272
General1Patch1
2026-01-281
Disclosure1
2026-02-171
Disclosure1
2026-03-151
General1
2026-03-191
Active Exploitation1
Full discourse6 posts
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎤 RadioCSIRT Ep.602 – Jeudi 19 mars 2026 Neuf sujets. Veille cyber quotidienne. 🔴 KEV / CISA – Ajout de CVE-2026-20131 affectant Cisco Secure Firewall et CVE-2026-20963 impactant Microsoft SharePoint. Deux vulnérabilités de type Deserialization of Untrusted Data activement exploitées. 🔴 Endpoint Management – La CISA alerte sur une attaque visant Stryker avec abus de Microsoft Intune. Exploitation de privilèges et détournement de capacités d’administration centralisée. 🔴 Ubiquiti – Vulnérabilité critique dans UniFi Network affectant plusieurs versions. Impact non documenté mais exposition directe des consoles de gestion réseau. 🔴 CERT-FR / Microsoft – Multiples vulnérabilités référencées CVE-2026-23941 à CVE-2026-4111. Impact non spécifié, dépendances Erlang, libexif et libarchive concernées. 🔴 Roundcube – Vulnérabilités multiples incluant SSRF, XSS et CSRF sur Webmail. Atteinte à la confidentialité et exécution de requêtes côté serveur possibles. 🔴 Mitel – Vulnérabilité XSS affectant MiContact Center et MCX. Injection de code côté client permettant manipulation de session et contenu. 🔴 Splunk – Vulnérabilités multiples dans Universal Forwarder. Références CVE-2025-15467, CVE-2026-22795 et CVE-2026-22796. Impact non précisé. 🔴 Python – CVE-2026-3479. Contournement de politique de sécurité dans CPython. Mécanisme d’exploitation non détaillé publiquement. 🔴 VMware Tanzu – Plus de 100 CVE dans les Buildpacks et composants plateforme. Risque Supply Chain étendu sur dépendances logicielles. 🔴 DPRK – IBM X-Force et Flare identifient une opération impliquant 100 000 faux IT workers infiltrant des entreprises occidentales. Usage de VPN, identités frauduleuses et plateformes freelance. 🔴 NCSC – Publication de recommandations sur la sécurisation des visioconférences. Risques liés aux accès, à la gestion des données et aux fonctionnalités IA. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-602-radiocsirt-edition-francaise-veille-cyber-du-jeudi-19-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #CISA #KEV #Cisco #SharePoint #Deserialization #Endpoint #Intune #Ubiquiti #UniFi #CERTFR #Roundcube #SSRF #XSS #CSRF #Mitel #Splunk #Python #VMware #Tanzu #SupplyChain #NorthKorea #DPRK #IBM #Flare #NCSC #ZeroTrust #CVE #CERT #SOC #CISO #CyberDefense #BlueTeam #InfoSec

    Post summary

    The brief highlights several actively exploited vulnerabilities in Cisco Secure Firewall, Microsoft SharePoint, and others, explaining their types and the current threat landscape.

    00000101
    413 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-22796 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/423 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post reports that CVE-2026-22796 is no longer present in the latest AWS Lambda base image scans, with no additional technical, exploit, or patch information provided.

    0000033
    32 followersView on X
  • Grok@grok
    Disclosure

    The recent OpenSSL vulnerabilities, reportedly found with AI like Claude Opus, include CVE-2025-15467 (high-severity stack buffer overflow in CMS parsing), CVE-2026-22795 (PKCS#12 parsing issue), CVE-2026-22796 (PKCS#7 signature flaw), and others up to 12 total. They were disclosed in late Jan 2026. Check http://openssl.org for full list.

    Post summary

    OpenSSL has disclosed multiple new CVEs, detailing stack buffer overflow and PKCS parsing issues, but the post does not provide any PoC, exploit code, or patch information.

    00000112
    8.0M followersView on X
  • DACBARBOS Brand@dacbarbos
    Disclosure

    OpenSSL Security Advisory (corrected - added CVE-2026-22795 and CVE-2026-22796) https://groups.google.com/a/openssl.org/g/openssl-project/c/pwBoo9Tac6M #infosec

    Post summary

    The OpenSSL advisory announces the addition of two new CVEs (CVE-2026-22795 and CVE-2026-22796) and links to the advisory for details.

    0000073
    318 followersView on X
  • 〒@teenigma_
    General

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    The advisory enumerates several OpenSSL CVE identifiers with associated severity levels but offers no technical details, proof of concept, exploit code, or mitigation information.

    00000156
    348 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-22796: Malformed PKCS#7 signatures can remotely crash apps using OpenSSL, leading to denial-of-service. Update to 3.6.1 / 3.5.5 / 3.4.4 or latest 1.x now! More info ➡️ https://volerion.com/vulnerabilities/CVE-2026-22796 #OpenSSL #infosec #AppSec

    Post summary

    CVE-2026-22796 causes denial‑of‑service via malformed PKCS#7 signatures in OpenSSL; patched in versions 3.6.1, 3.5.5, 3.4.4, and the latest 1.x.

    0000098
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more