CVE-2025-10680: Openvpn
High severity, CVSS 8.8. EPSS: 7.3% chance of exploitation in the next 30 days.
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use
Affected products
- Openvpn Openvpn: from 2.7_alpha1, up to and including 2.7_beta1
Published 2025-10-24. Last modified 2026-06-17.