For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
-
## OpenVPN 2.6.17 -- Released 28 November 2025
-
The OpenVPN community project team is proud to release OpenVPN 2.6.17. This is a bugfix release containing one security fix.
-
-
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.17/Changes.rst)
-
-
Security fixes:
-
-
* [CVE-2025-13751](https://www.cve.org/CVERecord?id=CVE-2025-13751): Windows/interactive service: fix erroneous exit on error that could be
-
used by a local Windows users to achieve a local denial-of-service
-
-
Bug fixes:
-
-
* Windows/interactive service: improve service pipe robustness against
-
file access races (uuid) and access by unauthorized processes (ACL).
-
* upgrade bundled build instruction (vcpkg and patch) for pkcs11-helper
-
to 1.31, fixing a parser bug
-
-
Windows MSI changes since 2.6.16-I001:
-
* Built against OpenSSL 3.6.0
-
* Included openvpn-gui updated to 11.59.0.0
-
* Authorize config before opening the service pipe
-
* Remove dependence on pathcch.dll not in Windows 7
-
* Included win-dco driver updated to 2.8.0
-
+
## OpenVPN 2.6.18 -- Released 4 February 2026
+
The OpenVPN community project team is proud to release OpenVPN 2.6.18. This is a bugfix release.
+
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.18/Changes.rst)
+
+
User visible changes:
+
* disable DCO if `--bind-dev` option is given (no support for this in
+
the old out-of-kernel Linux DCO implementation)
+
* on Windows, if using `--ip-win32 netsh` and not using the interactive
+
service, IPv4 addresses would be installed as "permanent", possibly
+
causing problems later on with using that IPv4 address on a different
+
interface. Change to "store=active". (GH: [#915](https://github.com/OpenVPN/openvpn/issues/915))
+
* improve pull-filter documentation, emphasizing possible problems if
+
used as a naive security measure (reported by SRLabs)