Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-74899: Old OpenSSL Library Allows Attackers to Run Commands

CVE-2026-74899 · published 1 month ago
Summary

Old versions of OpenSSL's encryption library can be exploited by attackers to access system functions and run arbitrary commands on a server. This is a concern for any server that uses the OpenSSL library for encryption. To protect your server, update to the latest version of the OpenSSL library.

What to do
  • Update jahlives openssl_encrypt to version 1.4.0 or later.
Affected software
VendorProductAffected versions
jahlives openssl_encrypt < 1.4.0
Original advisory text
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Pyt...
openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system functions and execute arbitrary OS commands.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Timeline
Published17 Aug 2026
Updated27 Sep 2026
First seen17 Aug 2026
Sources
CVE-2026-74899 · MITRE
Track software like this
Free during beta