CVE-2026-28389Patch(openssl / openssl)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 4 mentions (2026-04-08); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline10 mentions / 7d
01234Mentions · 2026-04-07: 1Mentions · 2026-04-08: 4Mentions · 2026-04-12: 1Mentions · 2026-04-14: 1Mentions · 2026-04-16: 1Mentions · 2026-04-18: 1Mentions · 2026-07-20: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 2Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-08: 3Technical Details · 2026-04-12: 1Technical Details · 2026-04-14: 1Technical Details · 2026-07-20: 104-0704-0804-1204-1404-1604-1807-20
Signal classification3 categories
Patch
440.0%
Disclosure
440.0%
General
220.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-071
Patch1
2026-04-084
Disclosure2Patch2
2026-04-121
General1
2026-04-141
Disclosure1
2026-04-161
Patch1
2026-04-181
General1
2026-07-201
Disclosure1
Full discourse10 posts
  • cPanel@cPanel
    Patch

    EasyApache 4 v25.54 is now available: • ea-openssl11 patched (CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390) • ea-php85 → 8.5.5, ea-php84 → 8.4.20 • ea-nginx → 1.29.8 (related packages built against it) Full change log → https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ #EasyApache https://t.co/fXdQMK7NCk

    Post summary

    The announcement details EasyApache 4 version 25.54 with updated openssl, php, and nginx packages that patch multiple CVEs, highlighting the availability of vendor fixes.

    00020525
    28.8K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-openssl モジュール更新情報 3.5.6-1 https://kusanagi.tokyo/releases/24085/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 openssl 3.5.6-1 この更新には脆弱性(CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-317...

    Post summary

    The post announces a Kusanagi‑OpenSSL module update (v3.5.6‑1) that addresses a set of CVEs, indicating a patch release without reporting exploits or PoC details.

    01010104
    200 followersView on X
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2026-28389: Siemens SIMATIC CN 4100 Memory Corruption Chain Threatens Communication Node Availability https://breachspider.com/intel/2026-07-20-cve-2026-28389-siemens-simatic-cn-4100-memory-corruption-cha #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    Alert about CVE-2026-28389, a memory corruption chain in Siemens SIMATIC CN 4100 that could disrupt communication node availability.

    0001051
    2.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28389 Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Application… https://www.cve.org/CVERecord?id=CVE-2026-28389

    Post summary

    Announcement of CVE-2026-28389, detailing a NULL pointer dereference in CMS EnvelopedData processing; no PoC, exploit, patch, or active exploitation information provided.

    00010161
    57.0K followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 61% of vulnerabilities from past week, CVE-2026-28389 has 55 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The tweet signals that CVE‑2026‑28389 has attracted unusually high media attention with 55 articles, providing a link for further details but no technical or exploit information.

    0000058
    69 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-28389 impacts openssl-fips-provider-latest in 20 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/470 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE‑2026‑28389 affecting the openssl‑fips‑provider in 20 AWS Lambda base images has been identified, with issue details linked on GitHub and additional information through lambdawatchdog.com.

    0000029
    34 followersView on X
  • ますだまさる@m_masaru
    General

    SSLの観点で見ていくと https://nvd.nist.gov/vuln/detail/CVE-2026-28386 CVE-2026-31790 RSA KEMはSSLで使用しないので影響なし CVE-2026-28386 CFBモードはSSLで使用しないので影響なし CVE-2026-28387 DONEはDNSSECベースの証明書検証の仕組みだけどSSL実装レイヤで対応はないので影響なし CVE-2026-28388 delta CRLは、ブラウザは独自にCRLをチェックしているしブラウザ以外は基本CRLをチェックしていないのでSSLに影響なし。SSLでのVPNとかに限定するとあるかも CVE-2026-28389 CMSはSSLで使用していないので影響なし CVE-2026-28390 CMSは同上 CVE-2026-31789 32bit環境で1GiBを超えるOCTET STRINGを含んだ証明書をロードすると発生するのだけど、SSL handshakeのserver cerfificatesのlengthが24bitでmax 16MiBなのでSSLには影響なし

    Post summary

    The post reviews a set of CVEs, noting that SSL implementations are unaffected by them, but provides no PoC, exploit, patch, or active exploitation information.

    00000188
    149 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in OpenSSL 3.6.x (eight CVEs: RSA KEM, AES-CFB-128, DANE, CMS, delta CRL, hex conversion) 📅 **Timeline:** Disclosure: 2026-03-13, Patch: 2026-04-07 🆔 **CVE-2026-31790** 🆔 **CVE-2026-2673** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 13.657% 🆔 **CVE-2026-28386** 🆔 **CVE-2026-28387** 🆔 **CVE-2026-28388** 🆔 **CVE-2026-28389** 🆔 **CVE-2026-28390** 🆔 **CVE-2026-31789** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** OpenSSL 3.6.x, OpenSSL 3.5.x 🔧 **Fixed Versions:** OpenSSL 3.6.2, OpenSSL 3.5.6 🫨 **Attack Vectors:** - Network-facing TLS/KEM operations (RSASVE) - AES-CFB-128 processing on x86-64 with AVX-512 - DANE TLSA-based client processing - Processing of attacker-controlled CRLs (delta CRL) - Processing of attacker-controlled CMS EnvelopedData (KeyAgree and KeyTransport) - Conversion/printing of large X.509 extension OCTET STRINGS (32-bit platforms) 📝 **Summary:** Multiple memory-safety and parsing bugs in OpenSSL 3.6.x (and some 3.5.x) can cause crashes (DoS), memory disclosure (notably RSA KEM and AES-CFB-128 on AVX‑512), and in constrained cases heap overflow leading to potential code execution on 32‑bit. Prioritize patching systems that perform TLS/KEM operations, process CMS/CRLs/TLSA records, or run on x86‑64 with AVX‑512. 📈 **Impact Scope:** Library-level issues in OpenSSL 3.6.x (and some 3.5.x) enabling crashes (DoS), memory disclosure (RSA KEM, AES-CFB read), and potential memory corruption or code execution (heap overflow on 32-bit); affects servers and clients that use the vulnerable APIs or process untrusted CMS/CRL/certificates. Prioritize AES-CFB-128 on x86-64 with AVX-512 due to memory-read exposure. 🛡️ **Recommended Actions:** - Upgrade affected deployments to OpenSSL 3.6.2 (or OpenSSL 3.5.6 for 3.5 users) and redeploy dependent software immediately. - Apply vendor patches and rebuild/redeploy static-linked/OpenSSL-linked binaries. - For RSASVE (CVE-2026-31790), validate RSA public keys before encapsulation (EVP_PKEY_public_check() / EVP_PKEY_public_check_quick()); avoid processing untrusted CMS/CRL/TLSA inputs where possible. 🪢 **Related Resources:** - https://github.com/openssl/openssl/releases/tag/openssl-3.6.2 - https://openssl-library.org/news/secadv/20260407.txt 🏷 **Tags:** #Cybersecurity #OpenSSL #Crypto

    Post summary

    OpenSSL 3.6.x suffers multiple memory‑safety and parsing bugs that can cause DoS, memory disclosure, and limited code execution, but patches are available—immediately upgrade to OpenSSL 3.6.2 or 3.5.6.

    0000041
    276 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28389 NULL Pointer Dereference in OpenSSL CMS EnvelopedData KeyAgreeRecipientInfo Processing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28389

    Post summary

    The text announces CVE-2026-28389, a NULL pointer dereference in OpenSSL CMS EnvelopedData KeyAgreeRecipientInfo, but provides no PoC, exploitation details, or patch information.

    0000073
    4.0K followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.2 Is Now Available for Download with Important Security Fixes Patches CVE-2026-31790, CVE-2026-2673, CVE-2026-28386, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, and CVE-2026-31789. https://9to5linux.com/openssl-3-6-2-is-now-available-for-download-with-important-security-fixes

    Post summary

    The post announces the release of OpenSSL 3.6.2, highlighting that it contains patches for a series of newly identified CVEs.

    0000064
    139 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more