A vulnerability, which was classified as critical, has been found in OpenSSL up to 3.5.5/3.6.1. This issue affects some unknown processing of the component TLS 1.3. The manipulation leads to algorithm downgrade.

This vulnerability is documented as CVE-2026-2673. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.