CVE-2026-78221: Openvpn
Medium severity, CVSS 5.9. EPSS: 0.1% chance of exploitation in the next 30 days.
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
Affected products
- Openvpn Openvpn: from 2.7_alpha1, up to and including 2.7.6
Published 2026-09-07. Last modified 2026-09-08.