CVE-2026-63650EPSS p27.9%
CVE-2026-63650CVE-2026-63650
Description
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
Scoring
| EPSS | 0.36% probability of exploitation · percentile 27.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-01 |