CVE-2026-81738CWE-121CWE-193CWE-787

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

Low · published September 7, 2026

CVSS v4.0
2.3
EPSS
In the wild
Unconfirmed
What it is

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

The record
Technical detail
CVSS v4.0
2.3 · LOW
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L
EPSS
Not scored
Weaknesses
CWE-121 · Stack-based Buffer Overflow; CWE-193 · Off-by-one Error; CWE-787 · Out-of-bounds Write
Published
2026-09-07T07:32Z
Timeline
  • 07 SEP 07:32Z
    OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
    cvelistv5