CVE-2026-74872Disclosure(jahlives / openssl_encrypt)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jahlives openssl_encrypt systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so pattern in site-packages directories to achieve native code execution when the module is loaded.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl_encrypt

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-17); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openssl_encrypt

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-17: 2Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 2Technical Details · 2026-08-18: 108-1708-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-08-172
Disclosure2
2026-08-181
Disclosure1
Full discourse3 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: multiple critical/high vulnerabilities in #openssl_encrypt version<1.4.0 CVE-2026-74872 - CVE-2026-74880 - CVE-2026-74899 CVSS: 9.8. They can lead to sandbox escape, auth bypass or remote code execution #RCE #Patch #Patch #Patch

    Post summary

    The tweet announces three critical OpenSSL encryption library CVEs, warns of potential RCE via sandbox escape or auth bypass, but does not supply patches, PoC, or exploit tools.

    01000321
    7.2K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-74872: Critical 9.8 RCE in openssl_encrypt via Malicious Whirlpool .so… "The National Vulnerability Database has published CVE-2026-74872, a CVSS 9.8 (Critical)…" 🔗 https://securityarsenal.com/blog/cve-2026-74872-critical-98-rce-in-opensslencrypt-via-malicious-whirlpool-so-loading-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve202674872 #critical #cve

    Post summary

    The post announces a critical RCE vulnerability (CVE‑2026‑74872) in openssl_encrypt, providing CVSS score and technical details, and references a remediation guide without claiming active exploitation or PoC availability.

    0000046
    23 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - openssl_encrypt RCE via Whirlpool .so Glob Module Hijack (CVE-2026-74872) openssl_encrypt’s Whirlpool hash implementation uses broad glob patterns to load native modules (e.g., whirlpool*py313*.so) from site-packages without integrity verification. An attacker who can write to that path can drop a matching malicious .so to get arbitrary native code execution when Whirlpool is invoked. 👉Affected: openssl_encrypt < 1.4.0 | Upgrade to 1.4.0

    Post summary

    The advisory announces a critical remote code execution flaw in openssl_encrypt’s Whirlpool hash implementation, details the technical mechanism, and recommends upgrading to version 1.4.0 to remediate the issue.

    00000112
    291 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjahlivesopenssl_encrypt-python-

Explore more