CVE-2026-34054: Microsoft Vcpkg

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set openssldir to a path on the build machine, making that path be attackable later on customer machines. This issue has been patched in version 3.6.1#3.

Affected products

  • Microsoft Vcpkg: before 3.6.1#3 (fixed in 3.6.1#3)

Published 2026-03-31. Last modified 2026-06-17.