CVE-2026-42769 | OpenSSL up to 3.4.5/3.5.6/3.6.2/4.0.0 OSSL_CMP_get1_rootCaKeyUpdate certificate validation
A vulnerability classified as problematic has been found in OpenSSL up to 3.4.5/3.5.6/3.6.2/4.0.0. This issue affects the function OSSL_CMP_get1_rootCaKeyUpdate. This manipulation causes improper certificate validation.
This vulnerability…
A vulnerability classified as problematic has been found in OpenSSL up to 3.4.5/3.5.6/3.6.2/4.0.0. This issue affects the function OSSL_CMP_get1_rootCaKeyUpdate. This manipulation causes improper certificate validation.
This vulnerability is handled as CVE-2026-42769. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
Verschlüsselung im Ruhezustand & Unveränderbare SIEM-Logs
Geschützt (KMS Envelope Encryption)
Angreifer penetrieren Perimeter und WAF ungehindert. Schicht 3 (Micro-Segmentierung & Port-Drop) bildet die entscheidende Stop-Linie zur Schadenseindämmung.
Analyse für CVE-2026-42769 auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
🛡️ Angriffsfläche & Exposure
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
⚡ Empfohlene Sofortmaßnahmen
1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Verwandte Schwachstellen (gleicher Hersteller)
CVE-2026-63073CVE-2026-63073 | Issue summary: OpenSSL CMP response validation passed an unexpected response
sender distinguished name directly as the format string to `ERR_raise_data()`.
Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client
that enforces an expected sender or uses a pinned server certificate whose
subject becomes the default expected sender.
CWE: CWE-134 (Use of Externally-Controlled Format String)
Description: When validating a received CMP mes
CVSS 9.8
CVE-2022-2068CVE-2022-2068 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distrib
CVSS 9.8
CVE-2022-1292CVE-2022-1292 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1
CVSS 9.8
Synthetische RAG-Antwort
HAND-OFF
Auf Smartphone übergeben (CVE-2026-42769)
Scannen Sie den QR-Code mit der Smartphone-Kamera für sofortigen mobilen Zugriff: