OpenVPN 2.7.8 Released with Certificate and Windows Security Fixes
OpenVPN 2.7.8 fixes three security vulnerabilities: CVE-2026-84790 (certificates with embedded NULL bytes in subject fields), CVE-2026-88964 (unsigned underflow when clearing domain_search_list) and CVE-2026-84256 (cmd.exe variable expansion in quoted arguments on Windows). The release also addresses DCO issues, including Linux Netlink races and errors that could terminate the whole server instead of a single client.
- CVE-2026-84790: certificates with NULL bytes in subject fields are now rejected
- CVE-2026-84256: cmd.exe variable expansion in quoted arguments fixed on Windows
- DCO fixes cover stale iroutes and Linux Netlink race conditions
- Peer or key setup errors no longer terminate the entire server process
Read next
Security