## OpenVPN 2.7.7 -- Released 3 September 2026
The OpenVPN community project team is proud to release OpenVPN 2.7.7. This is a bugfix release fixing
many security issues.

For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst)

Security fixes:

- reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
  for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))

  Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
  Github: OpenVPN/openvpn-private-issues#161

- windows: fix `CreateProcess()` command line quoting for characters that
  are special to `cmd.exe`, where a combination of validation script plus
  rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))

  Bug found by Clouditera Security, tracked in Github:
  OpenVPN/openvpn-private-issues#159

- windows: fix `tapctl` to always call `netsh.exe` with full path
  (as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))

  Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
  Github: OpenVPN/openvpn-private-issues#164

- windows: don't use NULL DACL with system objects, namely the `--service`
  exit event and the `netsh.exe` guard semaphore.  The old approach was
  prone to a local DoS where one user could interfere with other users'
  openvpn processes by blocking the netsh semaphore or sending events.
  This only affects setups not using the iservice, or using the automatic
  service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))

  Bug found by DEBRAJ BASAK, tracked in Github:
  OpenVPN/openvpn-private-issues#167

- openvpnserv (windows): pass correct NRPT domains size - when IDN domains
  with UTF8 encoding were involved, a buffer overread could be achieved
  ([CVE-2026-78221](https://www.cve.org/CVERecord?id=CVE-2026-78221))

  Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
  OpenVPN/openvpn-private-issues#162

- openvpnserv (windows): don't allow '/' in config paths.  The APIs windows
  uses for path validation do not handle '/' as path separator, while the
  file open APIs do, so this could be used to circumvent our config path
  validation, leading to openvpn.exe starting a user-controlled config file
  even if administratively not allowed ([CVE-2026-78043](https://www.cve.org/CVERecord?id=CVE-2026-78043))

  Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github:
  OpenVPN/openvpn-private-issues#162

- dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
  guard - suitable DHCP options could lead to a single-byte overflow of a
  temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))

  Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
  OpenVPN/openvpn-private-issues#165

- linux netlink: validate netlink replies against the request

  Suggested by Joshua Rogers as a security improvement, tracked in Github:
  OpenVPN/openvpn-private-issues#9

- openvpnserv (windows): fix off-by-one on input validation
  (discovered while fixing CVE-2026-78221)

- openvpnserv (windows): harden `CheckConfigPath()` a bit more
  (another improvement while working on CVE-2026-78043)

User-visible Changes:

- when using EPOCH data channel format, reduce the number of future keys
  from 16 to 4 - the previous calculation was wrong, and 4 spare keys are
  sufficient for 100+ Gbit/s links.  This means less log spam in userland
  and fewer resources used in in-kernel implementations.

Bugfixes:

- work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0
  (supposedly fixed in 4.3.0)

- multi: don't let stale-routes-check delete permanent routes -
  `--stale-routes-check` did not only delete dynamic cached routes, but
  also routes installed by `--iroute` and `--ifconfig-push`.  Fixed by
  introducing route flags and restraining the check on them
  (Github: [OpenVPN/openvpn#1063](https://github.com/OpenVPN/openvpn/issues/1063))

- ssl: do not queue control ciphertext while a packet is still queued
  (fixes problems in TCP p2p handshake when both sides try to handshake
   at the same time)
  (Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))

- reenable xmit_hold when using p2p tcp-server and tls-server - in TCP
  server mode the server is not expected to initiate the TLS handshake.
  This was introduced by the multisocket code checking the wrong variable
  for socket protocol
  (Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089))

- clinat: do not adjust UDP checksum if zero (as per RFC768)
  (Github: [OpenVPN/openvpn#1037](https://github.com/OpenVPN/openvpn/issues/1037))

- openssl: avoid resetting the HMAC key on every packet
  (Github: [OpenVPN/openvpn#1088](https://github.com/OpenVPN/openvpn/issues/1088))

- openvpnserv (windows): fix log lines format string - interface names with
  international characters printed in some error messages need to be
  converted from UTF8 to UCS16 first.

- fix format string specifier for size_t (%zu)

- fix test_misc compile issues with -Werror

Windows MSI changes since 2.7.6-I001:
* Update included dco-win driver to v2.8.7
  * peer: fix use-after-free in multipeer peer table handling (Github: [OpenVPN/ovpn-dco-win#140](https://github.com/OpenVPN/ovpn-dco-win/pull/140))([CVE-2026-82325](https://www.cve.org/CVERecord?id=CVE-2026-82325))
  * inf: set the device security descriptor in the hardware key (Github: [OpenVPN/ovpn-dco-win#139](https://github.com/OpenVPN/ovpn-dco-win/pull/139))

| | | |
|-|-|-|
|**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi.asc)|[OpenVPN-2.7.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi)|
|**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi.asc)|[OpenVPN-2.7.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi)|
|**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi.asc)|[OpenVPN-2.7.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi)|
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz.asc)|[openvpn-2.7.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz)|

For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos).

## OpenVPN 2.6.23 -- Released 23 September 2026
The OpenVPN community project team is proud to release OpenVPN 2.6.23. This is a bugfix release fixing
several security issues.

> [!IMPORTANT]  
> After 2.6.22 release the [support status](../Pages/Supported%20versions) of OpenVPN 2.6 changed from "Full Support" to "Old Stable Support".
> This means that we do not provide Windows installer downloads of future 2.6.x releases.

For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.23/Changes.rst)

Security fixes:

- ssl: do not trust the peer's request to resend the wrapped client key

  Tracked in Github: OpenVPN/openvpn-private-issues#181

- reliability layer: avoid unbounded reliable TLS timeout, and ignore acks
  for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732))

  Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in
  Github: OpenVPN/openvpn-private-issues#161

- improve on `check_session_buf_not_used()`, catch possible double-free in
  the lame duck case ([CVE-2026-84471](https://www.cve.org/CVERecord?id=CVE-2026-84471))

  Bug reported by Andreas Gabriel Berbescu, tracked in Github:
  OpenVPN/openvpn-private-issues#157, and by Haruki Oyama (Waseda
  University), tracked in OpenVPN/openvpn-private-issues#132

- windows: fix `CreateProcess()` command line quoting for characters that
  are special to `cmd.exe`, where a combination of validation script plus
  rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256))

  Bug found by Clouditera Security, tracked in Github:
  OpenVPN/openvpn-private-issues#159

- windows: fix `tapctl` to always call `netsh.exe` with full path
  (as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226))

  Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in
  Github: OpenVPN/openvpn-private-issues#164

- windows: don't use NULL DACL with system objects, namely the `--service`
  exit event and the `netsh.exe` guard semaphore.  The old approach was
  prone to a local DoS where one user could interfere with other users'
  openvpn processes by blocking the netsh semaphore or sending events.
  This only affects setups not using the iservice, or using the automatic
  service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312))

  Bug found by DEBRAJ BASAK, tracked in Github:
  OpenVPN/openvpn-private-issues#167

- dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer
  guard - suitable DHCP options could lead to a single-byte overflow of a
  temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738))

  Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github:
  OpenVPN/openvpn-private-issues#165

- openvpnserv (windows): detect and refuse sibling dirs in
  `CheckConfigPath()` ([CVE-2026-81830](https://www.cve.org/CVERecord?id=CVE-2026-81830))

  Bug found by Harshit Varu, tracked in Github:
  OpenVPN/openvpn-private-issues#166

| | | |
|-|-|-|
|**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz.asc)|[openvpn-2.6.23.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz)|

#### [Full Release History](https://community.openvpn.net/ReleaseHistory)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9