* [CVE-2026-13122 - Server assert via malformed auth-token with external-auth](./CVE-2026-13122) (July 2026)
* [CVE-2026-12932](./CVE-2026-12932) (July 2026)
* [CVE-2026-11771](./CVE-2026-11771) (July 2026)
-
* [CVE-2026-13698](./CVE-2026-13698) (July 2026)
+
* [CVE-2026-13698 - Server memory leak via repeated tls-crypt-v2 HARD_RESET_CLIENT_V3 packets](./CVE-2026-13698) (July 2026)
* [CVE-2026-40215 - fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances](./CVE-2026-40215) (Apr 2026)
* [CVE-2026-35058 - fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key](./CVE-2026-35058) (Apr 2026)
* [CVE-2026-2738 - ovpn-dco-win 2.8.0 buffer overflow with AEAD using epoch data keys](./CVE-2026-2738)