Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

OpenVPN Inc.

First CVE: Aug 24, 2005Active for: 21 yearsTotal CVEs: 76
44.8
VTI Score
High

OpenVPN Inc. maintains a focused portfolio of virtual private network software and access servers that provide remote connectivity and network encryption across enterprise and consumer deployments, making vulnerabilities in these products high-impact despite the narrow product scope. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and reflect the authentication and cryptographic demands intrinsic to VPN implementations—recurring weakness classes include authentication bypasses, assertion failures, and exposure of sensitive information alongside protocol and parsing issues. The exposure concentrates in the core OpenVPN client and server products, as well as the OpenVPN Access Server and kernel-space data-path components, reflecting the layered architecture spanning user-space and kernel implementations. Defenders should treat updates to this vendor's products as high-priority given the network-critical role of VPN appliances and the potential for authentication or encryption weakening; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
76
Total CVEs
More Total CVEs than 99% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by OpenVPN Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2005
20 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Self-Reporting Analysis

Of all the CVEs published by OpenVPN Inc. as a CNA, 95.8% affect products that OpenVPN Inc. develops as a vendor.

95.8%
Self-reported: 46 (95.8%)
Third-party: 2 (4.2%)

Of all the CVEs published that affect products developed by OpenVPN Inc., 60.5% are self-published by OpenVPN Inc. as a CNA.

60.5%
39.5%
Self-published: 46 (60.5%)
Other CNAs: 30 (39.5%)

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (76 CVEs).

76 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7478HIGH
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
May 15, 20177.544NOYES
CVE-2024-1305CRITICAL
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting i
Jul 8, 20249.839NONO
CVE-2026-9560HIGH
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC ch
May 26, 20267.837NONO
CVE-2025-10680HIGH
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use
Oct 24, 20258.836NONO
CVE-2026-13698HIGH
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially
Jul 6, 20267.535NONO
CVE-2023-46850CRITICAL
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
Nov 11, 20239.834NONO
CVE-2025-3110HIGH
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behi
Jul 8, 20267.533NONO
CVE-2024-27903CRITICAL
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact w
Jul 8, 20249.833NONO
CVE-2017-12166CRITICAL
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
Oct 4, 20179.833NONO
CVE-2017-5868MEDIUM
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation
May 26, 20176.133NOYES
View all 76 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products76 CVEs
34%
46%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (23.7%)
Network45 (59.2%)
Unknown13 (17.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low51 (67.1%)
High12 (15.8%)
Unknown13 (17.1%)
User Interaction
None57 (75.0%)
Unknown13 (17.1%)
Required4 (5.3%)
Privileges Required
Low25 (32.9%)
High0 (0.0%)
None38 (50.0%)
Unknown13 (17.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (76 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.3% of CVEs· 95th percentile
ExploitDB
2 CVEs
2.6% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by OpenVPN Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by OpenVPN Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For OpenVPN Inc.'s Products

View all 3 CNAs →

Top CWEs