Description
Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow
Published: 2026-09-07
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Update
AI Analysis

Impact

The vulnerability is caused by retransmissions of ACK packet IDs in OpenVPN versions 2.6.22 and 2.7.6. Crafted ACK packets trigger a timeout integer overflow that forces the VPN process to fail, resulting in a denial of service for remote users. The flaw allows unauthenticated attackers to disrupt VPN services without authentication, impacting network availability.

Affected Systems

OpenVPN customers running software versions 2.6.22 or 2.7.6 are affected. These versions are commonly deployed in corporate and remote‑access environments.

Risk and Exploitability

The CVSS score of 8.7 categorises this as a high‑severity flaw. No EPSS score is available, and the vulnerability is not yet listed in CISA KEV, but the type of exploit—remote crafted packet injection—suggests a realistic threat if network traffic can be manipulated. An attacker can send malformed ACK packets from any location on the network to trigger the integer overflow and cause a service crash.

Generated by OpenCVE AI on September 7, 2026 at 13:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenVPN to a fixed release that addresses CVE‑2026‑84732 (e.g., 2.7.7 or later).
  • If an upgrade cannot be performed immediately, configure firewalls or IDS to detect and block anomalous ACK packet patterns or rate‑limit incoming ACK traffic to mitigate the overflow trigger.
  • Continuously monitor VPN logs and network traffic for repeated re‑establishment attempts or timeout spikes, and isolate affected hosts during the remediation window to contain potential disruptions.

Generated by OpenCVE AI on September 7, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn
Vendors & Products Openvpn
Openvpn openvpn

Mon, 07 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title openvpn: OpenVPN: Remote Denial of Service via crafted ACK packets
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Mon, 07 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow
Weaknesses CWE-190
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2026-09-08T15:01:45.505Z

Reserved: 2026-09-02T07:47:20.537Z

Link: CVE-2026-84732

cve-icon Vulnrichment

Updated: 2026-09-08T15:01:41.895Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T09:17:16.840

Modified: 2026-09-08T19:07:52.113

Link: CVE-2026-84732

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-07T08:16:40Z

Links: CVE-2026-84732 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:45:16Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound