# OpenSSL and WolfSSL Patch High-Severity Flaws

OpenSSL and WolfSSL released fixes for multiple vulnerabilities, including remotely exploitable high-severity flaws that could expose memory, cause denial of service, or bypass peer authentication. WolfSSL 5.9.4 was released September 25. Agencies and contractors using these libraries in VPN, VoIP, IoT, web-server, or other TLS-enabled systems should identify affected deployments, assess configurations, and prioritize patching to reduce security exposure across government-supported services and systems.

- Contractors should inventory systems and products that incorporate OpenSSL or WolfSSL and determine whether affected versions or configurations are in use.
- Procurement and technical teams can use the affected components and patch status to inform supplier risk reviews and remediation coordination for systems supporting government work.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 30, 2026

### Vendors
- OpenSSL (Cryptographic software publisher)
- wolfSSL (Cryptographic software publisher)

### Sources
- [High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL - SecurityWeek](https://www.securityweek.com/high-severity-vulnerabilities-patched-in-openssl-wolfssl) - SecurityWeek