The news
The OpenSSL Project disclosed a high-severity OpenSSL DTLS flaw on September 29, 2026, along with a batch of lower-rated bugs in the widely used encryption library. Separately, the makers of wolfSSL, a smaller TLS library common in embedded devices, released version 5.9.4 on September 25 with fixes for three high-severity authentication bugs.
The OpenSSL bug, CVE-2026-84782, affects DTLS (Datagram TLS), a version of the TLS encryption protocol used over UDP by applications such as VPNs and real-time communications. According to OpenSSL's advisory, a retransmitted handshake message can disclose heap memory to the other side of the connection as plaintext or cause a crash. The Hacker News explained that the problem arises when a resend starts while a larger message is still partly sent, so leftover bytes end up in a wrongly labeled message.
SecurityWeek reported a CVSS severity score of 8.2 for the flaw and said it can be triggered over the network without authentication or user interaction. OpenSSL rated it High, one step below Critical. The advisory lists affected branches 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2. Public fixes are in 4.0.3, 3.6.5, 3.5.9 and 3.4.8; fixes for 3.0, 1.1.1 and 1.0.2 (versions 3.0.23, 1.1.1zj and 1.0.2zs) are available to premium support customers. The advisory credits Laurent Gaffie of Secorizon with the report and says OpenSSL's FIPS module is not affected.
OpenSSL also fixed CVE-2026-84783, rated Moderate, which affects only the 4.0 branch. According to the advisory, a remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded server that requests client certificates. The remaining low-severity issues include denial-of-service bugs and timing side channels, which SecurityWeek said could in some cases enable private key recovery. The Hacker News said no exploitation of the high-severity flaw had been reported at the time of disclosure.
The wolfSSL bugs are about trust. SecurityWeek reported that CVE-2026-93302 can let a malicious server pass authentication by presenting a forged clone of a certificate authority, because public keys are ignored during certificate matching. CVE-2026-89102 could let an attacker holding any certificate chained to a trusted authority forge identity certificates, and CVE-2026-89136 could let a malicious server bypass authentication on clients that use raw public keys. Version 5.9.4 fixes 11 issues in total, the outlet said.
The numbers
- CVE-2026-84782 CVSS score (per SecurityWeek)
- 8.2
- OpenSSL branches affected by the DTLS flaw
- 7
- High-severity wolfSSL flaws fixed in 5.9.4
- 3
- Total issues fixed in wolfSSL 5.9.4 (per SecurityWeek)
- 11
Why CEOs should care
For CISOs, the job splits in two. Software your teams build or run directly on servers can be updated as soon as Linux distributions and package managers ship the fixed OpenSSL builds. Devices and products that embed OpenSSL or wolfSSL, from VPN appliances and routers to industrial controllers and medical devices, depend on their makers. Ask which suppliers use DTLS or wolfSSL, and request a dated patch plan in writing.
Procurement and vendor risk teams should use this as a test of software bills of materials (SBOMs), the ingredient lists of code inside a product. If a supplier cannot quickly say whether its product includes an affected library version, that is a gap worth raising at renewal. Organizations still on OpenSSL 1.1.1 or 1.0.2, which receive fixes only through premium support, should treat this as another reason to fund upgrades.
Boards should hear one plain message: the most serious bug here can leak fragments of memory, which might contain sensitive data, and the wolfSSL bugs could let a fake server pass as genuine. No exploitation was reported at disclosure, but encryption libraries are high-value targets once fixes are public.
The bigger picture
OpenSSL sits underneath a huge share of internet traffic, and wolfSSL is popular in embedded and IoT products where updates are slow. Bugs in these shared components ripple across thousands of products at once, which is why the speed of downstream vendors matters more than the speed of the original fix.
What’s next
Watch for Linux distributions, cloud providers and appliance makers to publish advisories naming fixed builds, and for any reports of exploitation of CVE-2026-84782 or the wolfSSL certificate flaws.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





