HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution in OpenSSL OCSP Stapling (CVE-2026-35188) Threatens TLS Deployments

A double‑free flaw in OpenSSL’s OCSP stapling verification (CVE‑2026‑35188) allows remote code execution with a CVSS score of 7.5. The vulnerability highlights the need for continuous patch monitoring and SOC 2 evidence of cryptographic control hygiene.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Remote Code Execution in OpenSSL OCSP Stapling (CVE‑2026‑35188) Threatens TLS Deployments

What It Is — OpenSSL 1.1.1 and later contain a double‑free flaw in the processing of malformed OCSP stapling responses. An attacker who can cause a client to request a crafted OCSP response can trigger remote code execution (RCE) in the context of the vulnerable process.

Exploitability — Remote exploitation is possible; user interaction is limited to the client making a TLS request to a malicious server. CVSS v3.1 7.5 (High) – AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H. A proof‑of‑concept has been disclosed to the vendor, and an official patch is available.

Affected Products — OpenSSL library (all versions impacted by the OCSP stapling verification routine).

Why It Matters for Compliance & Audit Readiness

  • Continuous control monitoring must capture library version drift; an unpatched OpenSSL component represents a control gap in the “Cryptographic Key Management” and “System Hardening” domains of SOC 2.
  • Demonstrating timely remediation (patch management) is a core audit evidence point; the vulnerability underscores the need for automated evidence collection to prove due diligence.
  • Enterprise buyers increasingly require proof that TLS‑terminating services are patched against high‑severity flaws before signing contracts.

Recommended Actions

  • Identify all assets running vulnerable OpenSSL versions via an inventory scan.
  • Apply the vendor‑released patch immediately and verify the fix.
  • Update your SOC 2 control mappings to include OpenSSL version checks as part of the “System Operations” control set.
  • Enable continuous monitoring (e.g., automated vulnerability scanning) to capture future library updates as audit evidence.

Source: Zero Day Initiative Advisory – ZDI‑26‑425

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-425/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →