CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-12996

highCVSS 8.1covered by 4 sourcesfirst seen 2026-07-03
Ein lokaler Angreifer kann mehrere Schwachstellen in OpenVPN ausnutzen, um beliebigen Programmcode auszuführen, Daten zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.

CSIRTS triage

What
Multiple vulnerabilities allow a local attacker to execute arbitrary code, manipulate data, or cause a denial-of-service condition.
Who is affected
Local deployments of OpenVPN are affected by these vulnerabilities.
Urgency
Remediation is urgent due to the high severity of the vulnerabilities, although they are not currently exploited.
Action
Update to the latest version of OpenVPN to mitigate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-12996

Get an email if CVE-2026-12996 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (4)

External references

NVD record for CVE-2026-12996

CVE.org record

Embed the live status

CVE-2026-12996 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-12996 status](https://www.csirts.com/badge/CVE-2026-12996)](https://www.csirts.com/cve/CVE-2026-12996)