CVE-2026-28387Patch(openssl / openssl)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-free on the client side. Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, the issue only affects clients that make use of TLSA records with both the PKIX-TA(0/PKIX-EE(1) certificate usages and the DANE-TA(2) certificate usage. By far the most common deployment of DANE is in SMTP MTAs for which RFC7672 recommends that clients treat as 'unusable' any TLSA records that have the PKIX certificate usages. These SMTP (or other similar) clients are not vulnerable to this issue. Conversely, any clients that support only the PKIX usages, and ignore the DANE-TA(2) usage are also not vulnerable. The client would also need to be communicating with a server that publishes a TLSA RRset with both types of TLSA records. No FIPS modules are affected by this issue, the problem code is outside the FIPS module boundary.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-04-08); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline10 mentions / 6d
01345Mentions · 2026-04-07: 1Mentions · 2026-04-08: 5Mentions · 2026-04-12: 1Mentions · 2026-04-14: 1Mentions · 2026-04-16: 1Mentions · 2026-07-18: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 3Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-08: 2Technical Details · 2026-04-14: 1Technical Details · 2026-07-18: 104-0704-0804-1204-1404-1607-18
Signal classification3 categories
Patch
550.0%
Disclosure
330.0%
General
220.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-071
Patch1
2026-04-085
Disclosure1General1Patch3
2026-04-121
General1
2026-04-141
Disclosure1
2026-04-161
Patch1
2026-07-181
Disclosure1
Full discourse10 posts
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.54 is now available: • ea-openssl11 patched (CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390) • ea-php85 → 8.5.5, ea-php84 → 8.4.20 • ea-nginx → 1.29.8 (related packages built against it) Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache https://t.co/fXdQMK7NCk

    Post summary

    This tweet announces the EasyApache 4 v25.54 update, noting that several CVEs in ea-openssl11 are patched and providing updated PHP and Nginx versions.

    00020525
    28.8K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl モジュール更新情報 3.5.6-1 https://kusanagi.tokyo/releases/24085/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 openssl 3.5.6-1 この更新には脆弱性(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-317...

    Post summary

    The release notes announce a module update that patches multiple CVEs, providing new versions to mitigate the listed vulnerabilities.

    01010104
    200 followersView on X
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2026-28387: Siemens SIMATIC CN 4100 Memory Corruption Chain Threatens Communication Node Availability https://breachspider.com/intel/2026-07-18-cve-2026-28387-siemens-simatic-cn-4100-memory-corruption-cha #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The post announces CVE-2026-28387, a memory corruption chain in Siemens SIMATIC CN 4100, but provides no PoC, exploit code, active exploitation evidence, nor patch information.

    0000051
    2.3K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-28387 impacts openssl-fips-provider-latest in 20 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/468 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE (CVE-2026-28387) impacting the OpenSSL FIPS provider in AWS Lambda base images has been detected, with basic vulnerability details provided but no exploit or patch information.

    0000028
    34 followersView on X
  • ますだまさる@m_masaru
    General

    SSLの観点で見ていくと https://nvd.nist.gov/vuln/detail/CVE-2026-28386 CVE-2026-31790 RSA KEMはSSLで使用しないので影響なし CVE-2026-28386 CFBモードはSSLで使用しないので影響なし CVE-2026-28387 DONEはDNSSECベースの証明書検証の仕組みだけどSSL実装レイヤで対応はないので影響なし CVE-2026-28388 delta CRLは、ブラウザは独自にCRLをチェックしているしブラウザ以外は基本CRLをチェックしていないのでSSLに影響なし。SSLでのVPNとかに限定するとあるかも CVE-2026-28389 CMSはSSLで使用していないので影響なし CVE-2026-28390 CMSは同上 CVE-2026-31789 32bit環境で1GiBを超えるOCTET STRINGを含んだ証明書をロードすると発生するのだけど、SSL handshakeのserver cerfificatesのlengthが24bitでmax 16MiBなのでSSLには影響なし

    Post summary

    The text lists multiple CVEs and notes they do not impact SSL, without providing PoC, exploit, patch, or technical details.

    00000188
    149 followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl Module Update 3.5.6-1 https://kusanagi.tokyo/en/releases/24086/ KUSANAGI 9 modules have been updated. The updated modules are as follows: openssl 3.5.6-1 This update includes support for vulnerability(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388,...

    Post summary

    This brief release announcement confirms that KUSANAGI has issued an OpenSSL patch (3.5.6‑1) to address multiple CVEs, indicating a vendor mitigation update without any details on exploits or vulnerability specifics.

    0000091
    200 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in OpenSSL 3.6.x (eight CVEs: RSA KEM, AES-CFB-128, DANE, CMS, delta CRL, hex conversion) 📅 **Timeline:** Disclosure: 2026-03-13, Patch: 2026-04-07 🆔 **CVE-2026-31790** 🆔 **CVE-2026-2673** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 13.657% 🆔 **CVE-2026-28386** 🆔 **CVE-2026-28387** 🆔 **CVE-2026-28388** 🆔 **CVE-2026-28389** 🆔 **CVE-2026-28390** 🆔 **CVE-2026-31789** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** OpenSSL 3.6.x, OpenSSL 3.5.x 🔧 **Fixed Versions:** OpenSSL 3.6.2, OpenSSL 3.5.6 🫨 **Attack Vectors:** - Network-facing TLS/KEM operations (RSASVE) - AES-CFB-128 processing on x86-64 with AVX-512 - DANE TLSA-based client processing - Processing of attacker-controlled CRLs (delta CRL) - Processing of attacker-controlled CMS EnvelopedData (KeyAgree and KeyTransport) - Conversion/printing of large X.509 extension OCTET STRINGS (32-bit platforms) 📝 **Summary:** Multiple memory-safety and parsing bugs in OpenSSL 3.6.x (and some 3.5.x) can cause crashes (DoS), memory disclosure (notably RSA KEM and AES-CFB-128 on AVX‑512), and in constrained cases heap overflow leading to potential code execution on 32‑bit. Prioritize patching systems that perform TLS/KEM operations, process CMS/CRLs/TLSA records, or run on x86‑64 with AVX‑512. 📈 **Impact Scope:** Library-level issues in OpenSSL 3.6.x (and some 3.5.x) enabling crashes (DoS), memory disclosure (RSA KEM, AES-CFB read), and potential memory corruption or code execution (heap overflow on 32-bit); affects servers and clients that use the vulnerable APIs or process untrusted CMS/CRL/certificates. Prioritize AES-CFB-128 on x86-64 with AVX-512 due to memory-read exposure. 🛡️ **Recommended Actions:** - Upgrade affected deployments to OpenSSL 3.6.2 (or OpenSSL 3.5.6 for 3.5 users) and redeploy dependent software immediately. - Apply vendor patches and rebuild/redeploy static-linked/OpenSSL-linked binaries. - For RSASVE (CVE-2026-31790), validate RSA public keys before encapsulation (EVP_PKEY_public_check() / EVP_PKEY_public_check_quick()); avoid processing untrusted CMS/CRL/TLSA inputs where possible. 🪢 **Related Resources:** - https://github.com/openssl/openssl/releases/tag/openssl-3.6.2 - https://openssl-library.org/news/secadv/20260407.txt 🏷 **Tags:** #Cybersecurity #OpenSSL #Crypto

    Post summary

    The advisory discloses multiple OpenSSL 3.6.x CVEs, specifies exploitation vectors and impacts, and provides patching instructions and mitigation recommendations.

    0000041
    276 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28387 Use-After-Free Vulnerability in DANE TLSA Client Authentication Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28387

    Post summary

    The text announces CVE-2026-28387, describing a use‑after‑free vulnerability in DANE TLSA client authentication, but provides no PoC, exploit, or patch information.

    0000056
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28387 Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result i… https://www.cve.org/CVERecord?id=CVE-2026-28387

    Post summary

    The text is a brief CVE record reference without details on PoC, exploit, mitigation, or real-world activity.

    00000138
    57.0K followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.2 Is Now Available for Download with Important Security Fixes Patches CVE-2026-31790, CVE-2026-2673, CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, and CVE-2026-31789. https://9to5linux.com/openssl-3-6-2-is-now-available-for-download-with-important-security-fixes

    Post summary

    Article announces that OpenSSL 3.6.2 includes patches for several CVEs, offering important security fixes.

    0000064
    139 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more