OpenSSL Security Updates – 01 February 2026

OpenSSL has released security updates to address several vulnerabilities affecting OpenSSL Software Services.

The addressed vulnerabilities could allow the attacker to perform denial-of-service attacks or execute arbitrary code and gain access to the affected system.

Sample of the addressed vulnerabilities:

OpenSSL Stack Buffer Overflow in CMS AuthEnvelopedData Parsing Vulnerability (CVE-2025-15467):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service
Vulnerabilities
  • CVE-2025-11187
  • CVE-2025-15467
  • CVE-2025-15468
  • CVE-2025-15469
  • CVE-2025-69420
  • CVE-2026-22795
  • CVE-2025-66199
  • CVE-2025-68160
  • CVE-2025-69418
  • CVE-2025-69419
  • CVE-2025-69421
  • CVE-2026-22796
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

OpenSSL Security Updates

References