CVE-2026-63072Patch(openssl / openssl)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure. The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation. FIPS impact: no As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-26); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-25: 1Mentions · 2026-08-26: 2Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-25: 1Technical Details · 2026-08-27: 108-2508-2608-27
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-251
Patch1
2026-08-262
Disclosure1Patch1
2026-08-271
Patch1
Full discourse4 posts
  • Welsh ICP Conviction 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏉@ICPLEGEND1966
    Patch

    🚨 $ICP — THIS IS WHY THE INTERNET COMPUTER ARCHITECTURE MATTERS.** OpenSSL has just patched **9 security vulnerabilities**, including heap corruption, double-free, remote crashes and memory-exhaustion issues. CVE-2026-63072 alone allows a specially crafted CMS message to cause an **out-of-bounds heap write**, typically resulting in denial of service. Now think about how most internet applications are built. Servers. Operating systems. Web servers. Databases. CDNs. TLS libraries. Cloud infrastructure. And an endless cycle of patching every layer. Then look at **Internet Computer Protocol. ♾️** Applications on $ICP can run their backend logic, store data AND serve web frontends directly from **canisters**, without developers needing external servers, databases or CDNs. Canisters execute as **sandboxed WebAssembly** across replicated subnet nodes, while update calls are executed across the subnet and agreed through consensus. That fundamentally changes the infrastructure developers have to operate themselves. And THIS is the part people still underestimate. Every major vulnerability affecting traditional internet infrastructure is another reminder of just how enormous the attack surface of Web2 has become. $ICP isn't simply trying to create another blockchain. **It is trying to replace chunks of the traditional cloud stack itself.** No AWS server to configure. No backend VM to maintain. No database server to babysit. Far less infrastructure sitting there waiting to be misconfigured or forgotten. ⚠️ To be accurate: ICP still uses HTTPS infrastructure and TLS termination at its edge, so this does **not** mean ICP is immune to OpenSSL or infrastructure vulnerabilities. But reducing the amount of infrastructure an application developer has to own, configure and secure? **That is a VERY big deal.** The world keeps discovering why $ICP was built. ♾️ #ICP #InternetComputer #DFINITY #CyberSecurity #OpenSSL #Blockchain #CloudComputing #Web3 ☕ ICP: `1e672d038cebc619d93186418fa98f6499dbdb9cfdfac54f366c61a4a4ee4362` The OpenSSL vulnerability details and the ICP architectural claims above are verified against the official OpenSSL advisory and ICP developer documentation.

    Post summary

    The tweet announces that OpenSSL has patched nine vulnerabilities, including CVE‑2026‑63072, which is an out‑of‑bounds heap write, and highlights how the Internet Computer Architecture reduces infrastructure attack surface.

    360310778
    1.8K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    OpenSSLの脆弱性(CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssh #openssl #ssl https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260826/

    Post summary

    The tweet lists several OpenSSL CVEs and links to a SIOS security page, indicating a disclosure of newly identified vulnerabilities.

    00021250
    374 followersView on X
  • HOL@HashgraphOnline
    Patch

    Upgrade OpenSSL to 3.0.22, 3.4.7, 3.5.8, 3.6.4, or 4.0.2. CVE-2026-63072 https://hol.org/blog/cve-2026-63072-openssl-cms-decrypt-unwrap-heap-overflow

    Post summary

    This notice recommends updating OpenSSL to multiple patched versions to remediate CVE‑2026‑63072, a CMS decrypt unwrap heap overflow vulnerability.

    0001097
    18.7K followersView on X
  • 必殺 ちゃぶ台返し@Sh1n_K_NO_S01aR
    Patch

    OpenSSLの脆弱性(CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803)と4.0.2, 3.6.4, 3.5.8, 3.4.7, 3.0.22, 1.1.1zi,1.0.2zrリリース https://security.sios.jp/vulnerability/openssl-security-vulnerability-20260826/

    Post summary

    Announcement of new OpenSSL releases that address multiple CVEs, with no PoC, exploit, or active exploitation details provided.

    0000050
    219 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more