CVE-2026-81738: OpenVPN OpenVPN vulnerability
Published Sep 7, 2026
·Updated
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
Affected Software
1 affected component
OpenVPN OpenVPN>=2.5.0<=2.7.6
Event History
Sep 7, 2026
CVE Published
via MITRE·07:32 AM
Data Sourced
via MITRE·07:32 AM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
Affected deployments are OpenVPN 2.5.0 through 2.7.6 running on Windows and using the tap-windows6 driver. The provided information does not indicate that non-Windows deployments or other drivers are affected.
2
What does an attacker need to exploit this issue?
An attacker needs to supply crafted DOMAIN-SEARCH entries. The provided information does not state how those entries are delivered or whether authentication is required.