OpenSSL security advisory (AV26-846)
Serial Number: AV26-846 Date: August 25, 2026 As of August 25, 2026, OpenSSL is affected by vulnerabilities in the following product: OpenSSL Prior to 1.0.2zr Prior to 1.1.1zi Prior to 3.0.22 Prior to 3.4.7 Prior to 3.5.8 Prior to 3.6.4 Prior to 4.0.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Vulnerabilities | OpenSSL Library
CSIRTS triage
- What
- OpenSSL contains multiple unspecified security vulnerabilities across multiple release branches.
- Who is affected
- Systems and applications using OpenSSL in affected version ranges: 1.0.2, 1.1.1, 3.0, 3.4, 3.5, 3.6, and 4.0 families.
- Urgency
- Unknown; specific vulnerability details and severity not disclosed in advisory.
- Action
- Review OpenSSL security advisory and upgrade to the recommended patched versions for each branch.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch OpenSSL
Get an email when a new OpenSSL advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/openssl-security-advisory-av26-846
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24
- unknownDell security advisory (AV26-843)2026-08-24