OpenSSL's advisory of 29 September covers 14 vulnerabilities: one high, one moderate and 12 low. The high one is in DTLS and can leak a chunk of memory as ordinary handshake data or crash the process. No active exploitation is reported.
- CVE-2026-84782 affects every supported branch from 1.0.2 to 4.0.
- Free fixes exist for 4.0, 3.6, 3.5 and 3.4. For 3.0, 1.1.1 and 1.0.2 they are for premium support only.
- Two of the low-severity holes were also reported by Trail of Bits in collaboration with OpenAI.
Two of the fourteen holes were reported by Trail of Bits "in collaboration with OpenAI". It says so in the advisory itself, among the low-severity ones.
It is not the headline, but it is the direction. OpenAI's name now appears in the list of finders for the cryptographic library that a huge share of servers stand on. Whether and how a model helped, the advisory does not say.
The practical part is duller than the news. DTLS is not the ordinary TLS that opens a website. VPNs, voice and video connections and devices that talk over UDP use it. If you do not know whether yours does, that is today's task.
A separate issue is the 3.0 branch, still sitting on plenty of servers. There is no free fix for it in this advisory: 3.0.23 is for premium support only. And 3.1, 3.2 and 3.3 were not checked at all, because they are out of support.
Check which OpenSSL sits in your images and containers, not just on the host. You update on the next deploy, not next quarter.