1 vulnerability across 1 product scored HIGH or above on September 07, 2026.

  • ๐ŸŸ  HIGH: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-85046 (google/chrome) โ€” F1: exploitable โ†’ functional, AAS: 10.6 โ†’ 12.6 (HIGH โ†’ CRITICAL). Originally in 2026-09-03 bulletin.
  • [UPGRADED] CVE-2026-20212 (cisco/cisco_nx-os_software) โ€” F1: theoretical โ†’ poc, AAS: 10.9 โ†’ 12.9 (HIGH โ†’ CRITICAL). Originally in 2026-09-02 bulletin.

๐ŸŸ  [HIGH] openvpn/openvpn

1 CVE | CVSS 4.0: 8.7 | AAS 9.1

  • cpe:2.3:a:openvpn:openvpn:*:*:*:*:*:*:*:*

OpenVPN versions through 2.6.22 and 2.7.6 are affected by a high-severity denial-of-service vulnerability (CVE-2026-84732, CVSS 8.7) in which a remote unauthenticated attacker can craft retransmitted ACK packet IDs that trigger a timeout integer overflow, causing the VPN service to become unresponsive. Organizations running OpenVPN in any internet-facing capacity should treat this as a priority, since no authentication is required to exploit it.

Administrators should consult the vendor advisory at community.openvpn.net and upgrade to a patched release as soon as one is available. In the interim, consider applying network-level rate limiting or access controls to restrict exposure of OpenVPN endpoints to trusted sources where feasible.

Vendor Advisory