EXECUTIVE SUMMARY
OpenSSL has released security updates addressing multiple vulnerabilities affecting OpenSSL 3.x releases, including issues in cryptographic message parsing that could be exploited via crafted CMS, PKCS#7, or PKCS#12 inputs. Organizations using OpenSSL to process untrusted cryptographic data are strongly advised to upgrade to the latest patched versions to mitigate the risk of denial-of-service, memory corruption, or potential code execution.
- Total CVE: 12
- Active Region: Global
- Affected Sector: IT, Cloud Services, Web Hosting, Enterprise Applications, Email & PKI Services
- Affected Product: OpenSSL (versions 3.0–3.6; some CVEs also affect 1.1.1 and 1.0.2 premium releases)
- Severity: High (1), Moderate (1), Low (10)
- Published Date: January 28, 2026
CVE LIST
- ……



