OpenSSL security release of 29 September 2026 fixes a high-severity DTLS flaw, CVE-2026-84782, and a use-after-free
EditorialBy TrustList Editorial
OpenSSL published fixes on 29 September 2026, led by high-severity CVE-2026-84782, where DTLS retransmits handshake messages from a stale buffer offset, and a moderate use-after-free. Fixed in 4.0.3, 3.6.5, 3.5.9, 3.4.8 and 3.0.23.
- Cybersecurity
- Encryption
- Vulnerability Management
- Patch Management
About OpenSSL security release of 29 September 2026 fixes a high-severity DTLS flaw, CVE-2026-84782, and a use-after-free
OpenSSL security release of 29 September 2026 fixes a high-severity DTLS flaw, CVE-2026-84782, and a use-after-free
29 September 2026 — The OpenSSL project published a set of vulnerability fixes on 29 September 2026. OpenSSL is the cryptography library behind TLS in a large share of servers, appliances and applications. The release is led by one high-severity issue and one moderate one; the rest are rated low.
The two most serious issues
- CVE-2026-84782 (High): "DTLS Retransmits Handshake Messages From a Stale Buffer Offset". It affects DTLS, the datagram version of TLS used by VPNs, VoIP, WebRTC and some IoT protocols. It was found by Laurent Gaffie and fixed by Ryan Hooper. Affected versions: 4.0.0 before 4.0.3, 3.6.0 before 3.6.5, 3.5.0 before 3.5.9, and further lines listed on the advisory.
- CVE-2026-84783 (Moderate): "Use-After-Free in X.509 Extension Cache Under Concurrent Use". It affects certificate handling in multi-threaded programs, and was found by Tim Becker (Xint.io) and aydinmercan.
The project's list for the same date also includes a series of low-severity fixes: QUIC denial-of-service issues, timing side channels in ECDSA and SM2, and excessive memory allocation from crafted certificates. For that last one, the advisory lists every affected line: 4.0 before 4.0.3, 3.6 before 3.6.5, 3.5 before 3.5.9, 3.4 before 3.4.8, 3.0 before 3.0.23, and the premium-support 1.1.1 and 1.0.2 lines.
Who is affected
OpenSSL is linked into operating systems, language runtimes, web servers, network appliances and many commercial applications, often as a bundled copy. The high-severity flaw matters only where DTLS is in use. Anything that parses certificates in several threads at once is exposed to the use-after-free. The project has not reported exploitation of any of these issues.
What to do
- Update to OpenSSL 4.0.3, 3.6.5, 3.5.9, 3.4.8 or 3.0.23, whichever matches your line, or take your operating-system vendor's patched package when it ships.
- Software vendors that bundle OpenSSL should ship an update to customers, and state which OpenSSL version it contains.
- Prioritise products that use DTLS (VPN gateways, VoIP and real-time media servers, IoT gateways).
- Buyers should ask their appliance and software suppliers when a fixed build will be available.
Sources
Categories & features
- Cybersecurity
- Encryption
- Vulnerability Management
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.