1 vulnerability across 1 product scored HIGH or above on September 07, 2026.
- ๐ HIGH: 1
Exploit Status Upgrades
The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:
- [UPGRADED] CVE-2026-85046 (google/chrome) โ F1: exploitable โ functional, AAS: 10.6 โ 12.6 (HIGH โ CRITICAL). Originally in 2026-09-03 bulletin.
- [UPGRADED] CVE-2026-20212 (cisco/cisco_nx-os_software) โ F1: theoretical โ poc, AAS: 10.9 โ 12.9 (HIGH โ CRITICAL). Originally in 2026-09-02 bulletin.
๐ [HIGH] openvpn/openvpn
1 CVE | CVSS 4.0: 8.7 | AAS 9.1
cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*:*
OpenVPN versions through 2.6.22 and 2.7.6 are affected by a high-severity denial-of-service vulnerability (CVE-2026-84732, CVSS 8.7) in which a remote unauthenticated attacker can craft retransmitted ACK packet IDs that trigger a timeout integer overflow, causing the VPN service to become unresponsive. Organizations running OpenVPN in any internet-facing capacity should treat this as a priority, since no authentication is required to exploit it.
Administrators should consult the vendor advisory at community.openvpn.net and upgrade to a patched release as soon as one is available. In the interim, consider applying network-level rate limiting or access controls to restrict exposure of OpenVPN endpoints to trusted sources where feasible.
- ๐ CVE-2026-84732 (CVSS 4.0: 8.7)