CVE-2026-2673 is a high-severity (CVSS 7.5) vulnerability affecting OpenSSL TLS 1.3 servers in versions 3.5 and 3.6. This flaw occurs when the server's key exchange group configuration uses the 'DEFAULT' keyword, leading to the negotiation of a less preferred key exchange group, such as a classical one instead of a more robust post-quantum group, even when the latter is mutually supported. This network-exploitable issue carries a high confidentiality impact due to the use of a weaker cryptographic agreement than intended, though it does not affect integrity or availability. There is currently no evidence of active exploitation, no public exploit code available, and it is not listed on CISA's KEV catalog. Affected organizations should plan to upgrade to OpenSSL 3.5.6 or 3.6.2 once these patched versions are released.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, < 3.5.6CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.6.0, < 3.6.2CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
< 5.0CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_cn_4100_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.