* [CVE-2026-105390](https://www.cve.org/CVERecord?id=CVE-2026-105390) — a locking flaw allowed a local user with access to the driver's device to cause a system deadlock and denial of service, hanging the host until it was power-cycled.
* Performance improvements by moving to multi-core data processing. See [Release Notes](https://github.com/OpenVPN/ovpn-dco-win/releases/tag/2.8.13) for details.