Kritische OpenSSL-Schwachstellen ermöglichen Remote-Code-Execution-Angriffe
A security advisory from OpenSSL June 9, 2026, warns of a critical vulnerability that could allow remote code execution when applications process specially crafted PKCS7 or S/MIME signed messages.

Kurzfassung
Warum das wichtig ist
- A security advisory from OpenSSL June 9, 2026, warns of a critical vulnerability that could allow remote code execution when applications process specially crafted PKCS7 or S/MIME signed messages.
- The flaw, tracked as CVE‑2026‑45447, is a heap use‑after‑free bug in the PKCS7_verify function that can corrupt memory and, in some deployment scenarios, allow attackers to run arbitrary code on vulnerable systems.
- The issue occurs when a signed message contains an empty SignedData.digestAlgorithms ASN.1 SET, which causes OpenSSL to free a BIO object owned still leaving that application unaware of the change.
SvyTech-Check
Redaktionelle Einordnung
Kernpunkt
A security advisory from OpenSSL June 9, 2026, warns of a critical vulnerability that could allow remote code execution when applications process specially crafted PKCS7 or S/MIME signed messages.
Warum relevant
If the application later reuses or frees the same BIO, it may encounter a use‑after‑free condition that can result in crashes, heap corruption, or controlled exploitation, depending on the allocator’s behavior...
Einordnung
SvyTech ordnet die Meldung aus Cyber Security News als Teil des Themenfelds Technologie ein und verweist auf den Originalartikel, damit Leser Fakten, Quelle und Kontext nachvollziehen koennen.
If the application later reuses or frees the same BIO, it may encounter a use‑after‑free condition that can result in crashes, heap corruption, or controlled exploitation, depending on the allocator’s behavior and how the BIO is managed.
Critical OpenSSL RCE Vulnerabilities The vulnerability affects applications that use OpenSSL’s PKCS7 APIs to verify PKCS7 or S/MIME signatures. In contrast, those that rely on the CMS APIs for the same functionality are not impacted.
The advisory states that OpenSSL versions 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1, and 1.0.2 are all vulnerable to CVE‑2026‑45447, and it provides patched releases for each affected branch. Administrators are urged to upgrade OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, or 3.0.21, while customers with extended support for legacy lines should move to 1.1.1zh or 1.0.2zq.
Technik und Auswirkungen
The FIPS modules for 4.0, 3.6, 3.5, 3.4, and 3.0 are not impacted, as the vulnerable code lies outside the FIPS boundary. Alongside the critical PKCS7 bug, the advisory details numerous additional vulnerabilities, ranging from high to moderate severity, targeting different parts of the OpenSSL codebase.
These include weaknesses in CMS AuthEnvelopedData processing that can grant key‑equivalent capabilities or integrity bypass. QUIC logic flaws that enable denial‑of‑service through memory exhaustion or NULL pointer dereferences.

An AES‑OCB misuse issue where IVs are silently ignored when using the low‑level EVP_Cipher interface, breaking nonce uniqueness and tag authenticity. Several ASN.1 parsing bugs, PKCS12 PBMAC1 validation issues, CMS password‑based decryption problems.
CMP handling flaws also appear, many
CMP handling flaws also appear, many of which primarily lead to denial‑of‑service but in some cases may enable more advanced cryptographic attacks. OpenSSL’s own protocols such as TLS, QUIC, CMS, PKCS7, HPKE, and S/MIME are affected in different combinations depending on the specific vulnerability, configuration, and feature usage.
However, some of the most dangerous cryptographic weaknesses affect only custom applications that use low‑level EVP primitives or implement bespoke messaging protocols on top OpenSSL. Especially when they fail to enforce strict input validation or rely on error codes as oracles.
The OpenSSL team recommends that organizations not only patch to the latest versions but also audit their use of PKCS7, CMS, QUIC, AES‑OCB, AES‑SIV, and PKCS12 workflows to identify any high‑risk exposure. Where upgrading is delayed, turn off nonessential features such as OCSP stapling and vulnerable PKCS7‑based paths as an interim hardening step.
Abi is Security Editor and fellow reporter with
Quelllink
Originalquelle: Cyber Security News
Thema weiterverfolgen
Interne Verlinkung
Im Kontext weiterlesen
Diese weiterfuehrenden Links verbinden das Thema mit relevanten Archivseiten, Schlagwoertern und inhaltlich nahen Artikeln.
Technologie Archiv
Weitere Meldungen aus derselben Hauptkategorie.
Mehr von Cyber Security News
Alle veroeffentlichten Inhalte derselben Quelle im Archiv.
Niedrige Plasmaspiegel von Vitamin C korrelieren mit geringerer grauer Substanz und Lücken in neuronalen Netzwerken
Redaktionell verwandter Beitrag aus dem selben Themenumfeld.
Lesen von verwirrendem Code löst sprachkorrigierende Gehirnwellen aus
Redaktionell verwandter Beitrag aus dem selben Themenumfeld.
Quellenprofil
Quelle und redaktionelle Angaben
- Quelle
- Cyber Security News
- Originaltitel
- Critical OpenSSL Vulnerabilities Enable Remote Code Execution Attacks
- Canonical
- https://cybersecuritynews.com/openssl-rce-vulnerability/
- Quell-URL
- https://cybersecuritynews.com/openssl-rce-vulnerability/
Aehnliche Inhalte
Verwandte Themen und interne Verlinkung
Weitere Artikel aus aehnlichen Themenfeldern, damit Leser direkt im selben Kontext weiterlesen koennen.

Niedrige Plasmaspiegel von Vitamin C korrelieren mit geringerer grauer Substanz und Lücken in neuronalen Netzwerken
Zusammenfassung: Forscher haben eine signifikante strukturelle und funktionelle Verbindung zwischen dem systemischen Mikronährstoffstatus und der altersbedingten Erhaltung des Gehirns aufgezeigt.
10.06.2026
Live Redaktion
Lesen von verwirrendem Code löst sprachkorrigierende Gehirnwellen aus
Zusammenfassung: Eine interdisziplinäre Studie zur Neuro-Software-Engineering enthüllte die genaue Aktivität des Gehirns Millisekunden-Takt, die auftritt, wenn Programmierer verwirrenden Quellcode verarbeiten.
10.06.2026
Live Redaktion
Intel Nova Lake Mainboards mit PCIe 5.0: PCH um 22 % kleiner und Spitzenverbrauch nur 14 Watt
Kopieren Sie den Link
10.06.2026
Live Redaktion
Lenovo erhöht Preise erneut: Bis zu 147 Dollar Aufschlag auf gesamte PC-Reihe
Ein weiterer Preisanstieg wird ößten OEMs umgesetzt, was den Kauf wird.
10.06.2026
Live Redaktion