CVE-2025-15467: Critical OpenSSL Flaw Enables Pre-Auth Remote Code Execution

A critical vulnerability (CVE-2025-15467, CVSS 9.8) dropped on January 27, 2026. It affects OpenSSL 3.0, 3.3, 3.4, 3.5, and 3.6 – and it’s nasty. An attacker can trigger a stack buffer overflow by sending a malformed encrypted message. The kicker? The overflow fires before OpenSSL validates anything. No encryption keys needed. No authentication. Just a […]

The post CVE-2025-15467: Critical OpenSSL Flaw Enables Pre-Auth Remote Code Execution appeared first on Orca Security.

原始链接: https://orca.security/resources/blog/cve-2025-15467-openssl-pre-auth-rce/
侵权请联系站方: [email protected]

相关推荐

换一批