CVE-2026-84732: Integer Overflow
Published Sep 7, 2026
·Updated
Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow
Affected Software
1 affected component
OpenVPN OpenVPN>=2.6.22<=2.7.6
Event History
Sep 7, 2026
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
DescriptionWeakness
Frequently Asked Questions
1
Does exploiting this issue require OpenVPN authentication or valid user credentials?
No. The issue is described as exploitable by remote unauthenticated attackers using crafted inputs involving retransmitted ACK packet IDs.