CVE-2026-82325: Openvpn Ovpn-Dco-Win

Medium severity, CVSS 6.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages

Affected products

  • Openvpn Ovpn-Dco-Win: from 2.5.0, up to and including 2.8.6

Published 2026-09-07. Last modified 2026-09-08.