Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-2673

28
FAUCET Score

CVE-2026-2673 is a high-severity (CVSS 7.5) vulnerability affecting OpenSSL TLS 1.3 servers in versions 3.5 and 3.6. This flaw occurs when the server's key exchange group configuration uses the 'DEFAULT' keyword, leading to the negotiation of a less preferred key exchange group, such as a classical one instead of a more robust post-quantum group, even when the latter is mutually supported. This network-exploitable issue carries a high confidentiality impact due to the use of a weaker cryptographic agreement than intended, though it does not affect integrity or availability. There is currently no evidence of active exploitation, no public exploit code available, and it is not listed on CISA's KEV catalog. Affected organizations should plan to upgrade to OpenSSL 3.5.6 or 3.6.2 once these patched versions are released.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.5.0, < 3.5.6CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.6.0, < 3.6.2CPE match
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
< 5.0CPE matchmatch criteria
cpe:2.3:o:siemens:simatic_cn_4100_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.43%
Probability of exploitation in next 30 days
EPSS Percentile
35.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0043 is in the 22nd percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
jitsipatch availablevia llm_extracted
Fixed in: 3.6.2
View patch
microsoftpatch availablevia msrc
Product: 21192-17084Fixed in: 24.14.1-1
microsoftpatch availablevia msrc
Product: azl3 nodejs24 24.14.1-1 on Azure Linux 3.0Fixed in: 24.14.1-1
microsoftpatch availablevia msrc
Product: 21059-17084Fixed in: 24.14.1-1
microsoftpatch availablevia msrc
Product: azl3 nodejs24 24.13.0-3 on Azure Linux 3.0Fixed in: 24.14.1-1
ubuntupatch availablevia ubuntu_usn
Product: openssl (questing)Fixed in: 3.5.3-1ubuntu3.3
ubuntupatch availablevia ubuntu_usn
Product: openssl (jammy)Fixed in: 3.0.2-0ubuntu1.23
ubuntupatch availablevia ubuntu_usn
Product: openssl (noble)Fixed in: 3.0.13-0ubuntu3.9

Vendor Advisories (3)

ubuntuUSN-8155-1

OpenSSL vulnerabilities

Apr 8, 2026
jitsillm-jitsi-6a7d4fa3d6ec1ab3LOW

OpenSSL TLS 1.3 server may choose unexpected key agreement group

Mar 13, 2026
microsoft2026-Mar/CVE-2026-2673Moderate

OpenSSL TLS 1.3 server may choose unexpected key agreement group

Mar 10, 2026

References

cert-portal.siemens.com / productcert/html/ssa-032379.html
Third Party Advisory
openwall.com / lists/oss-security/2026/03/13/3
Mailing ListThird Party Advisory
github.com / openssl/openssl/commit/2157c9d81f7b0bd7dfa25b960e928ec28e8dd63f
Patch
github.com / openssl/openssl/commit/85977e013f32ceb96aa034c0e741adddc1a05e34
Patch
openssl-library.org / news/secadv/20260313.txt
Vendor Advisory