CVE-2026-9560Disclosure(openvpn / connect)

MEDIUMCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch openvpn connect systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78CWE-267CWE-270CWE-648

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 15 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 5 mentions (2026-06-08); latest day: 1
  • 15 total mentions across 7 days

Affected systems

Vendors
Products
connect

Deep dive

Activity timeline15 mentions / 7d
01345Mentions · 2026-05-26: 1Mentions · 2026-05-28: 3Mentions · 2026-05-29: 3Mentions · 2026-06-04: 1Mentions · 2026-06-08: 5Mentions · 2026-06-15: 1Mentions · 2026-06-27: 1Active Exploitation · 2026-06-08: 1Patch / Workaround · 2026-05-28: 2Patch / Workaround · 2026-05-29: 2Patch / Workaround · 2026-06-27: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 3Technical Details · 2026-05-29: 3Technical Details · 2026-06-04: 1Technical Details · 2026-06-08: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-27: 105-2605-2805-2906-0406-0806-1506-27
Signal classification4 categories
Disclosure
640.0%
Patch
533.3%
General
320.0%
Active Exploitation
16.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-261
Disclosure1
2026-05-283
Disclosure1Patch2
2026-05-293
Disclosure1Patch2
2026-06-041
Disclosure1
2026-06-085
Active Exploitation1Disclosure2General2
2026-06-151
General1
2026-06-271
Patch1
Full discourse15 posts
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad crítica en OpenVPN Connect para macOS permite ejecutar comandos arbitrarios CVE-2026-9560 Afecta a todas las versiones desde la 3.5.1 hasta la 3.8.1 y cuenta con una puntuación de gravedad CVSS 4.0 de 9.4 (Crítica) https://blog.elhacker.net/2026/05/vulnerabilidad-critica-en-openvpn.html

    Post summary

    The post announces a critical arbitrary command execution flaw (CVE‑2026‑9560) affecting OpenVPN Connect for macOS, providing technical details but no evidence of exploit code, active exploitation, or a patch.

    025067133.5K
    140.9K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Learn about the critical OpenVPN Connect macOS vulnerability (CVE-2026-9560) that allows local privilege escalation, and how to patch it now. #Cybersecurity #OpenVPN #macOS #Infosec #PrivilegeEscalation #PatchUpdate https://securityonline.info/openvpn-connect-macos-vulnerability-patched/ https://t.co/3HTvcmXoxX

    Post summary

    The post announces a critical local privilege escalation flaw in OpenVPN Connect for macOS (CVE‑2026‑9560) and urges users to apply the available patch immediately.

    0701841.3K
    12.5K followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【OpenVPN Connect for macOSに権限昇格脆弱性】 OpenVPN ConnectのmacOS版に、深刻な脆弱性 CVE-2026-9560 が確認され、修正版が公開されました。特権ヘルパーコンポーネントに起因するOSコマンドインジェクションで、ローカルIPCチャネルを通じて昇格権限で任意コマンドを実行される可能性があります。 影響を受けるのはOpenVPN Connect 3.5.1から3.8.1までのバージョンで、修正版は3.8.2です。単独ではローカル権限昇格ですが、フィッシングやマルウェア感染後の権限拡大に組み込まれると、被害拡大につながります。 Mac端末を開発者、管理者、リモート接続用途で利用している組織は、MDMやEDRでOpenVPN Connectのバージョンを確認してください。日本企業では、VPN機器だけでなくVPNクライアント側の更新管理もSOCの監視対象に含めるべきです。 #サイバーセキュリティ #OpenVPN #macOS #VPN #CVE #権限昇格 #MDM #SOC https://www.security-next.com/185001

    Post summary

    The post reports a privilege‑escalation bug (CVE‑2026‑9560) in OpenVPN Connect for macOS, details the injection vector, and confirms a fixed 3.8.2 release, urging organizations to update and monitor via MDM/EDR.

    01020478
    3.7K followersView on X
  • Tre B@trerbbb
    Patch

    vendor dropped CVE-2026-9560. privilege escalation, CVSS 9.4, exploit available. if you run the affected stack, block external access to the affected endpoint until patched. #PrivEsc #vpn #CVE-2026-9560 https://valtikstudios.com

    Post summary

    The post announces CVE‑2026‑9560, a high‑severity privilege escalation flaw, and urges users to block external traffic until a vendor patch is applied.

    0101082
    17 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    16:06 UTC: First exploit attempt in the wild. 0day Intel: Learn about the critical OpenVPN Connect macOS vulnerability (CVE-2026-9560) tha

    Post summary

    The text announces that CVE-2026-9560 in OpenVPN Connect for macOS has been exploited for the first time in the wild at 16:06 UTC, providing evidence of active exploitation but no PoC, exploit code, patch, or technical details.

    1000080
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    13:20 UTC: Thread live on @lyrie_ai. 0day Intel: Learn about the critical OpenVPN Connect macOS vulnerability (CVE-2026-9560) tha

    Post summary

    The post merely references a thread and a CVE identifier with minimal context, offering no substantive details or actionable information.

    1000061
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    13:17 UTC: GPT-5 enrichment complete. 59 words. 1 citations. 0day Intel: Learn about the critical OpenVPN Connect macOS vulnerability (CVE-2026-9560) tha

    Post summary

    The message merely announces the existence of CVE‑2026‑9560 without offering any additional technical or operational information.

    1000060
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    13:09 UTC: Lyrie Sentinel flagged it. 0day Intel: Learn about the critical OpenVPN Connect macOS vulnerability (CVE-2026-9560) tha

    Post summary

    The tweet announces a new critical vulnerability (CVE‑2026‑9560) in OpenVPN Connect for macOS, without providing additional technical details, PoC, or patch information.

    1000051
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    13:06 UTC: CVE-2026-9560 disclosed. Learn about the critical OpenVPN Connect macOS vulnerability (CVE-2026-9560) that allows local privilege escalation, and

    Post summary

    New vulnerability CVE-2026-9560 disclosed affecting OpenVPN Connect on macOS, enabling local privilege escalation.

    1000052
    258 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-9560: OpenVPN Connect macOS Privilege Escalation - What It Means for Your Business and How to Respond https://hubs.li/Q04ln2H40

    Post summary

    The article describes a privilege escalation vulnerability in OpenVPN Connect for macOS and offers general guidance on responding to the risk.

    0000018
    31 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    OpenVPN for macOS の脆弱性 CVE-2026-9560 が FIX:任意のコード実行の可能性 https://iototsecnews.jp/2026/05/28/critical-openvpn-connect-for-macos-vulnerability-let-attackers-execute-arbitrary-commands/ OpenVPN Connect for macOS の脆弱性は、 特権ヘルパーと呼ばれるバックグラウンド・サービスにおいて、プロセス間通信 (IPC) 経由で受け取る際のデータ検証の不備に起因します。昇格したシステム権限で動作するコンポーネントが、通信チャネルから送られてくる命令を処理する際に、適切なサニタイズを行っていません。そのため、OS コマンド・インジェクションの弱点が生じ、ローカル環境のユーザーから渡された悪意のコマンドが root 権限で実行される状態を招いています。ご利用のチームは、ご注意ください。 #CVE20269560 #OpenVPN #Vulnerability

    Post summary

    The post announces CVE‑2026‑9560 in OpenVPN Connect for macOS, outlining an OS command‑injection flaw that could allow local users to execute arbitrary commands with root privileges, but it provides no PoC, exploitation code, or evidence of active use.

    0000093
    491 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerability CVE-2026-9560 in OpenVPN Connect for macOS allows privilege escalation. Update to the latest version now to secure your system. #CyberSecurity #OpenVPN #macOS #Vulnerability Link: https://thedailytechfeed.com/critical-privilege-escalation-flaw-in-openvpn-connect-for-macos-requires-immediate-update/ https://t.co/IVkwKppQQC

    Post summary

    The tweet highlights a privilege‑escalation flaw in OpenVPN Connect for macOS and urges users to update to the latest version.

    0000072
    345 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🔐🚨 CVE-2026-9560: Critical privilege escalation in OpenVPN Connect for macOS (CVSS 9.4). Any local attacker can execute arbitrary commands as root via insecure IPC channel. 🔗 https://threataft.com/articles/openvpn-connect-macos-cve-2026-9560-command-injection #CyberSecurity #OpenVPN #CVE20269560

    Post summary

    The post announces a critical privilege‑escalation flaw (CVE‑2026‑9560) in OpenVPN Connect for macOS, detailing how local attackers can elevate privileges via an insecure IPC channel.

    0000078
    26 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 Critical OpenVPN Connect #macOS Flaw (#CVE-2026-9560) Allows Root Command Injection – Patch Now! + Video https://undercodetesting.com/critical-openvpn-connect-macos-flaw-cve-2026-9560-allows-root-command-injection-patch-now-video/ Educational Purposes!

    Post summary

    The post announces a CVE‑2026-9560 exploit allowing root command injection on macOS OpenVPN Connect and urges users to apply the available patch, without indicating active attacks or providing exploit code.

    0000077
    582 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-9560 Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands via local IPC channel https://www.cve.org/CVERecord?id=CVE-2026-9560

    Post summary

    The text announces CVE-2026-9560, describing a privilege escalation flaw in OpenVPN Connect on macOS, but does not provide attack code or evidence of exploitation.

    00000209
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenvpnconnect-macos-

Explore more