CVE-2026-2673Disclosure(openssl / openssl)

HIGHCVSS 6.5 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch openssl openssl systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the client's initial predicated keyshares. This will sometimes be the case with the new hybrid post-quantum groups, if the client chooses to defer their use until specifically requested by the server. If an OpenSSL TLS 1.3 server's configuration uses the 'DEFAULT' keyword to interpolate the built-in default group list into its own configuration, perhaps adding or removing specific elements, then an implementation defect causes the 'DEFAULT' list to lose its 'tuple' structure, and all server-supported groups were treated as a single sufficiently secure 'tuple', with the server not sending a Hello Retry Request (HRR) even when a group in a more preferred tuple was mutually supported. As a result, the client and server might fail to negotiate a mutually supported post-quantum key agreement group, such as 'X25519MLKEM768', if the client's configuration results in only 'classical' groups (such as 'X25519' being the only ones in the client's initial keyshare prediction). OpenSSL 3.5 and later support a new syntax for selecting the most preferred TLS 1.3 key agreement group on TLS servers. The old syntax had a single 'flat' list of groups, and treated all the supported groups as sufficiently secure. If any of the keyshares predicted by the client were supported by the server the most preferred among these was selected, even if other groups supported by the client, but not included in the list of predicted keyshares would have been more preferred, if included. The new syntax partitions the groups into distinct 'tuples' of roughly equivalent security. Within each tuple the most preferred group included among the client's predicted keyshares is chosen, but if the client supports a group from a more preferred tuple, but did not predict any corresponding keyshares, the server will ask the client to retry the ClientHello (by issuing a Hello Retry Request or HRR) with the most preferred mutually supported group. The above works as expected when the server's configuration uses the built-in default group list, or explicitly defines its own list by directly defining the various desired groups and group 'tuples'. No OpenSSL FIPS modules are affected by this issue, the code in question lies outside the FIPS boundary. OpenSSL 3.6 and 3.5 are vulnerable to this issue. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.2 once it is released. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.6 once it is released. OpenSSL 3.4, 3.3, 3.0, 1.0.2 and 1.1.1 are not affected by this issue.

6.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-757

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl
  • simatic_cn_4100
  • simatic_cn_4100_firmware

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 17 mentions across 12 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-08); latest day: 1
  • 17 total mentions across 12 days

Affected systems

Products
opensslsimatic_cn_4100simatic_cn_4100_firmware

1 version affected across 3 products

Deep dive

Activity timeline17 mentions / 12d
01223Mentions · 2026-03-13: 1Mentions · 2026-03-14: 2Mentions · 2026-03-16: 1Mentions · 2026-03-17: 2Mentions · 2026-03-22: 1Mentions · 2026-03-23: 1Mentions · 2026-04-02: 1Mentions · 2026-04-07: 1Mentions · 2026-04-08: 3Mentions · 2026-04-17: 1Mentions · 2026-04-18: 2Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-03-17: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-22: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 3Patch / Workaround · 2026-04-18: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 2Technical Details · 2026-03-17: 2Technical Details · 2026-03-23: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-08: 103-1303-1403-1603-1703-2203-2304-0204-0704-0804-1704-1804-23
Signal classification4 categories
Disclosure
741.2%
Patch
635.3%
General
211.8%
Active Exploitation
211.8%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-03-131
Disclosure1
2026-03-142
Disclosure2
2026-03-161
General1
2026-03-172
Active Exploitation1Disclosure1
2026-03-221
Active Exploitation1
2026-03-231
Disclosure1
2026-04-021
Disclosure1
2026-04-071
Patch1
2026-04-083
Patch3
2026-04-171
General1
2026-04-182
Patch2
2026-04-231
Disclosure1
Full discourse17 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-2673: OpenSSL: TLS 1.3 server may choose unexpected key agreement group https://www.openwall.com/lists/oss-security/2026/03/13/3 Severity: Low A less preferred key exchange may be used even when a more preferred group is supported. OpenSSL 3.6 and 3.5 are vulnerable; 3.4, 3.3, 3.0, 1.0.2, 1.1.1 are not.

    Post summary

    CVE-2026-2673 discloses a TLS 1.3 key agreement group selection flaw affecting OpenSSL 3.6 and 3.5, with low severity and no known exploit or patch instructions in the provided text.

    020511.6K
    4.4K followersView on X
  • ゆき@flano_yuki
    Disclosure

    OpenSSL Security Advisory [13th March 2026] OpenSSL TLS 1.3 server may choose unexpected key agreement group (CVE-2026-2673) == https://openssl-library.org/news/secadv/20260313.txt

    Post summary

    OpenSSL released a security advisory announcing CVE-2026-2673, highlighting a TLS 1.3 server issue that may select an unexpected key agreement group.

    01011441
    3.1K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos OpenSSL ❗ CVE-2026-2673 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-openssl/ https://t.co/WgQzg1C8nK

    Post summary

    A new OpenSSL vulnerability (CVE-2026-2673) is noted, with a link provided for further details. No additional exploitation or patch information is offered.

    01001128
    6.7K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl モジュール更新情報 3.5.6-1 https://kusanagi.tokyo/releases/24085/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 openssl 3.5.6-1 この更新には脆弱性(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-317...

    Post summary

    The post announces an OpenSSL module update that patches several CVEs, without providing any exploit details, PoC links, or active exploitation evidence.

    01010104
    200 followersView on X
  • Komodo Cyber Security@Komodosec
    Patch

    Security-only OpenSSL tarball releases for CVE-2026-2673 https://blog.surgut.co.uk/2026/03/security-only-openssl-tarball-releases.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces that new security‑only OpenSSL tarball releases have been made available to address CVE‑2026‑2673, effectively providing a patch or workaround.

    0001061
    1.5K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting OpenSSL (CVE-2026-2673) https://vuldb.com/?ctiid.350982

    Post summary

    The text reports that elevated activity targeting OpenSSL CVE-2026-2673 has been observed, indicating possible active exploitation, though no PoC, patch, or technical details are provided.

    0000169
    2.1K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-2673 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/454 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda images have been updated to no longer contain CVE-2026-2673, indicating the vulnerability has been addressed.

    0000037
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-2673 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/454 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The announcement notes that CVE‑2026‑2673 has been removed from the latest AWS Lambda base images, with no PoC, exploit, or patch details disclosed.

    0000020
    34 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl Module Update 3.5.6-1 https://kusanagi.tokyo/en/releases/24086/ KUSANAGI 9 modules have been updated. The updated modules are as follows: openssl 3.5.6-1 This update includes support for vulnerability(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388,...

    Post summary

    The release notes announce an OpenSSL module update that patches several CVEs, with no additional exploit or proof‑of‑concept details provided.

    0000091
    200 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in OpenSSL 3.6.x (eight CVEs: RSA KEM, AES-CFB-128, DANE, CMS, delta CRL, hex conversion) 📅 **Timeline:** Disclosure: 2026-03-13, Patch: 2026-04-07 🆔 **CVE-2026-31790** 🆔 **CVE-2026-2673** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 13.657% 🆔 **CVE-2026-28386** 🆔 **CVE-2026-28387** 🆔 **CVE-2026-28388** 🆔 **CVE-2026-28389** 🆔 **CVE-2026-28390** 🆔 **CVE-2026-31789** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** OpenSSL 3.6.x, OpenSSL 3.5.x 🔧 **Fixed Versions:** OpenSSL 3.6.2, OpenSSL 3.5.6 🫨 **Attack Vectors:** - Network-facing TLS/KEM operations (RSASVE) - AES-CFB-128 processing on x86-64 with AVX-512 - DANE TLSA-based client processing - Processing of attacker-controlled CRLs (delta CRL) - Processing of attacker-controlled CMS EnvelopedData (KeyAgree and KeyTransport) - Conversion/printing of large X.509 extension OCTET STRINGS (32-bit platforms) 📝 **Summary:** Multiple memory-safety and parsing bugs in OpenSSL 3.6.x (and some 3.5.x) can cause crashes (DoS), memory disclosure (notably RSA KEM and AES-CFB-128 on AVX‑512), and in constrained cases heap overflow leading to potential code execution on 32‑bit. Prioritize patching systems that perform TLS/KEM operations, process CMS/CRLs/TLSA records, or run on x86‑64 with AVX‑512. 📈 **Impact Scope:** Library-level issues in OpenSSL 3.6.x (and some 3.5.x) enabling crashes (DoS), memory disclosure (RSA KEM, AES-CFB read), and potential memory corruption or code execution (heap overflow on 32-bit); affects servers and clients that use the vulnerable APIs or process untrusted CMS/CRL/certificates. Prioritize AES-CFB-128 on x86-64 with AVX-512 due to memory-read exposure. 🛡️ **Recommended Actions:** - Upgrade affected deployments to OpenSSL 3.6.2 (or OpenSSL 3.5.6 for 3.5 users) and redeploy dependent software immediately. - Apply vendor patches and rebuild/redeploy static-linked/OpenSSL-linked binaries. - For RSASVE (CVE-2026-31790), validate RSA public keys before encapsulation (EVP_PKEY_public_check() / EVP_PKEY_public_check_quick()); avoid processing untrusted CMS/CRL/TLSA inputs where possible. 🪢 **Related Resources:** - https://github.com/openssl/openssl/releases/tag/openssl-3.6.2 - https://openssl-library.org/news/secadv/20260407.txt 🏷 **Tags:** #Cybersecurity #OpenSSL #Crypto

    Post summary

    The alert details multiple memory-safety and parsing bugs in OpenSSL 3.6.x and 3.5.x with comprehensive technical description, and it provides an immediate patch update and mitigation steps.

    0000041
    276 followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.2 Is Now Available for Download with Important Security Fixes Patches CVE-2026-31790, CVE-2026-2673, CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, and CVE-2026-31789. https://9to5linux.com/openssl-3-6-2-is-now-available-for-download-with-important-security-fixes

    Post summary

    OpenSSL 3.6.2 is released with patches for several critical CVEs.

    0000064
    139 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New LOW CVE detected in AWS Lambda 🚨 CVE-2026-2673 impacts openssl-fips-provider-latest in 20 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/454 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The post announces a newly detected low‑severity CVE‑2026‑2673 affecting OpenSSL FIPS provider in several AWS Lambda base images, providing links to discussion but lacking PoC, exploit, or patch details.

    0000037
    32 followersView on X
  • Technology Updates@DIYprojects55
    Disclosure

    https://pbxscience.com/openssl-tls-1-3-server-may-select-weaker-key-exchange-group/ OpenSSL TLS 1.3 Server May Select Weaker Key Exchange Group. A newly disclosed vulnerability — CVE-2026-2673 — causes OpenSSL TLS 1.3 servers to silently downgrade cryptographic key-exchange strength when the DEFAULT keyword appears in group...

    Post summary

    CVE-2026-2673 is a newly disclosed OpenSSL TLS 1.3 vulnerability that silently downgrades key‑exchange strength when the DEFAULT keyword is used, potentially weakening cryptographic security.

    0000036
    545 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🎤 RadioCSIRT Ep.600 – Mardi 17 mars 2026 Quatre sujets. Veille cyber quotidienne. 🔴 Wing FTP Server – CVE-2025-47813 ajoutée au catalogue KEV de la CISA. Exploitation active confirmée. Information Disclosure exploitable en chaîne avec CVE-2025-47812, une RCE critique. Correctif disponible depuis mai 2025 en version 7.4.4. Délai de remédiation de deux semaines imposé aux agences fédérales américaines sous BOD 22-01. 🔴 CERT-FR – Quatre avis publiés le 16 mars 2026. CVE-2026-3909 dans Google Chrome et CVE-2026-3910 dans Microsoft Edge confirmées comme activement exploitées. Trente et une CVE documentées sur Edge versions antérieures à 146.0.3856.59. OpenSSL affecté par CVE-2026-2673 sur les branches 3.5.x et 3.6.x. Six CVE additionnelles sur des composants Azure Linux : coredns, giflib, golang, azurelinux-image-tools. 🔴 Starcloud – Demande déposée auprès de la FCC pour le déploiement d'une mégaconstellation de 88 000 satellites en orbite héliosynchrone. Infrastructure de data centers orbitaux visant 5 gigawatts de puissance de calcul. Soutenue par NVIDIA. Proof-of-concept opérationnel avec un GPU H100 embarqué ayant exécuté des inférences IA depuis l'orbite. 🔴 DRILLAPP – Nouveau backdoor attribué avec faible confiance au groupe APT Laundry Bear (UAC-0190 / Void Blizzard). Campagne observée en février 2026 contre des organisations ukrainiennes. Abus des paramètres de debug de Microsoft Edge en mode headless pour accéder au système de fichiers, microphone, caméra et écran. Deux variants documentés : LNK puis CPL. Chrome DevTools Protocol utilisé pour contourner les restrictions JavaScript sur les téléchargements distants. 🎧 Écoutez l'épisode complet sur toutes les plateformes de podcast. Lien direct : https://www.radiocsirt.org/podcast/ep-600-radiocsirt-veille-cyber-du-mardi-17-mars-2026/ 📌 On ne réfléchit pas, on patch ! #RadioCSIRT #Cybersécurité #ThreatIntelligence #CTI #WingFTP #KEV #CISA #InfoDisclosure #RCE #CVE #CERTFR #GoogleChrome #MicrosoftEdge #OpenSSL #AzureLinux #Chromium #Starcloud #DataCenter #Space #NVIDIA #GPU #OrbitaleAI #FCC #DRILLAPP #LaundryBear #VoidBlizzard #UAC0190 #APT #Ukraine #Espionnage #EdgeDebug #Backdoor #ChromeDevTools #InfoSec #CERT #SOC #CISO #CyberDefense #OSINT #MalwareAnalysis #BlueTeam

    Post summary

    The episode reports several CVEs with confirmed active exploitation, including Wing FTP Server and Google Chrome/Edge, and notes available patches while also mentioning an operational PoC for Starcloud’s orbital data‑center project.

    00000124
    413 followersView on X
  • S.Komichevsen Matsuk@w4yh
    General

    Low 1件なので持ち越し< CVE-2026-2673:OpenSSL // https://openssl-library.org/news/secadv/20260313.txt

    Post summary

    The post minimally references CVE‑2026‑2673 as a low‑severity OpenSSL issue and links to the advisory, providing no further technical or exploit details.

    0000056
    324 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2673 Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default … https://www.cve.org/CVERecord?id=CVE-2026-2673

    Post summary

    The text announces OpenSSL TLS 1.3 vulnerability CVE-2026-2673 where the server may fail to negotiate the expected preferred key exchange group when its configuration includes the default group.

    0000092
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2673 - OpenSSL TLS 1.3 Key Exchange Group Selection Vulnerability Intel Report: https://ift.tt/K2M5arc

    Post summary

    A new CVE-2026-2673, affecting OpenSSL TLS 1.3 key exchange group selection, has been announced with a link to an Intel report, but no PoC, exploit code, or mitigation details are provided.

    0000038
    340 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---
HWsiemenssimatic_cn_4100---
OSsiemenssimatic_cn_4100_firmware---

Explore more