The current version of OpenSSL is 3.6.5 (as of 01/10/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists this vulnerability in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2014-0160OpenSSL Information Disclosure Vulnerability
7.5 high · over the network, without login · CISA deadline was 25 May 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- OpenSSL: Mehrere Schwachstellen
WID-SEC-W-2026-1852 · 8 Oct
- OpenSSL: Mehrere Schwachstellen
WID-SEC-W-2026-3638 · 8 Oct
- OpenSSL: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2026-2843 · 8 Oct
- OpenSSL: Mehrere Schwachstellen
WID-SEC-W-2026-3005 · 8 Oct
- OpenSSL: Mehrere Schwachstellen
WID-SEC-W-2026-0234 · 5 Oct
- OpenSSL: Mehrere Schwachstellen
WID-SEC-W-2026-0995 · 5 Oct
- OpenSSL und LibreSSL: Mehrere Schwachstellen
WID-SEC-W-2025-2166 · 28 Sept
- OpenSSL: Schwachstelle ermöglicht Denial of Service und Offenlegung von Informationen
WID-SEC-W-2024-1469 · 11 Sept
OpenSSL at a glance
OpenSSL is the cryptographic library underpinning TLS across a vast share of software and servers — one of the most security-critical components in the stack. The project ships releases across supported branches plus coordinated security advisories, occasionally high-severity (Heartbleed being the infamous example).
For admins OpenSSL usually comes from the distribution, which backports fixes — for serious advisories, confirm the patched package is installed and, crucially, that dependent services were restarted to load the new library (a patched library still leaves running processes vulnerable until restart). Statically linked applications and containers bundle their own OpenSSL and must be rebuilt. Track which OpenSSL branch your system ships and its end-of-life. Because so much depends on it, OpenSSL advisories are among the most important to act on promptly — patchletter surfaces new releases and the pre-announced high-severity fixes.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 3.6.5 | STABLE | 01/10/2026 | – |
| 3.6.4 | STABLE | 01/09/2026 | – |
| 3.6.3 | STABLE | 08/07/2026 | – |
Frequently asked questions
- What is the latest version of OpenSSL?
- OpenSSL 3.6.5, released 01/10/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the OpenSSL release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new OpenSSL updates?
- Tick OpenSSL off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new OpenSSL version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current OpenSSL version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/openssl)https://patchletter.com/badge/openssl.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).