CVE-2026-63072 | OpenSSL up to 4.0.1 CMS CMS_decrypt out-of-bounds write

SecurityVulns

A vulnerability labeled as critical has been found in OpenSSL up to 3.0.21/3.4.6/3.5.7/3.6.3/4.0.1. Impacted is the function CMS_decrypt of the component CMS. Such manipulation leads to out-of-bounds write.

This vulnerability is listed as CVE-2026-63072. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.VulDB Recent EntriesRead More