CVE-2025-10680: Openvpn

High severity, CVSS 8.8. EPSS: 7.3% chance of exploitation in the next 30 days.

OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use

Affected products

  • Openvpn Openvpn: from 2.7_alpha1, up to and including 2.7_beta1

Published 2025-10-24. Last modified 2026-06-17.