Security News > 2022 > October > Critical Vulnerability in Open SSL

There are no details yet, but it's really important that you patch Open SSL 3.x when the new version comes out on Tuesday.
How bad is "Critical"? According to OpenSSL, an issue of critical severity affects common configurations and is also likely exploitable.
It's likely to be abused to disclose server memory contents, and potentially reveal user details, and could be easily exploited remotely to compromise server private keys or execute code execute remotely.
In other words, pretty much everything you don't want happening on your production systems.
News URL
https://www.schneier.com/blog/archives/2022/10/critical-vulnerability-in-open-ssl.html
Related news
- Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability (source)
- Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence (source)
- Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code Execution (source)
- Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028) (source)
- Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise (source)
- Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin (source)