Connect
Vendor:
First CVE: Feb 28, 2020 · Active for 6 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Connect over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 28, 2020
6 years ago
Most Recent CVE
May 26, 2026
59 days ago
CVE Severity & Scoring
Connect8 CVEs
13%
88%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (75.0%)
Network2 (25.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low5 (62.5%)
High0 (0.0%)
None3 (37.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9560HIGH Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC ch | May 26, 2026 | 7.8 | 37 | NO | NO |
CVE-2024-8474HIGH OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to d | Jan 6, 2025 | 7.5 | 25 | NO | NO |
CVE-2020-9442HIGH OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a ma | Feb 28, 2020 | 7.8 | 25 | NO | NO |
CVE-2021-3613HIGH OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbit | Jul 2, 2021 | 7.8 | 24 | NO | NO |
CVE-2023-7224HIGH OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable | Jan 8, 2024 | 7.8 | 23 | NO | NO |
CVE-2020-15075HIGH OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp. | Mar 30, 2021 | 7.1 | 23 | NO | NO |
CVE-2023-7245HIGH The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs | Feb 20, 2024 | 7.8 | 22 | NO | NO |
CVE-2022-3761MEDIUM OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download re | Oct 17, 2023 | 5.9 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Connect
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.1.3 | 1 | 7.8 | 0.3% | 0 | 0 |
| 3.1.2 | 1 | 7.8 | 0.3% | 0 | 0 |
| 3.1.1 | 1 | 7.8 | 0.3% | 0 | 0 |
| 3.1.0 | 1 | 7.8 | 0.3% | 0 | 0 |
| 3.0.2 | 1 | 7.8 | 0.3% | 0 | 0 |
| 3.0.1 | 1 | 7.8 | 0.3% | 0 | 0 |
| 3.0.0 | 1 | 7.8 | 0.3% | 0 | 0 |