Request for Security Update – Bundled OpenSSL Libraries in Microsoft Store Applications and OneDrive

parag sarode 20 Reputation points
2026-08-04T12:07:04.7133333+00:00

Dear Microsoft Support Team,

We have identified multiple OpenSSL vulnerabilities reported by our enterprise vulnerability management solution (ManageEngine Vulnerability Manager Plus) in Microsoft applications.

The affected components are:

ApplicationInstalled VersionEmbedded OpenSSL VersionMicrosoft Paint11.2605.71.03.5.6------------------------Microsoft Paint11.2605.71.03.5.6Microsoft Photos2026.11060.2004.03.5.6Microsoft OneDrive26.134.0713.00033.4.4Microsoft Office Hub19.2607.58021.03.6.3The vulnerability scanner reports that these embedded OpenSSL libraries are affected by multiple CVEs, including:

  • CVE-2026-34180
  • CVE-2026-34181
  • CVE-2026-34182
  • CVE-2026-34183
  • CVE-2026-42764
  • CVE-2026-42766
  • CVE-2026-42767
  • CVE-2026-42768
  • CVE-2026-42769
  • CVE-2026-42770
  • CVE-2026-45445
  • CVE-2026-45446
  • CVE-2026-7383
  • CVE-2026-9076

We have verified the embedded OpenSSL versions using PowerShell:


The applications have been updated to the latest versions currently available through Microsoft Store and the OneDrive updater. However, the bundled OpenSSL libraries remain at the versions listed above.

Since these DLLs are Microsoft-signed and embedded within the application packages, they cannot be upgraded independently without breaking the package signature.

We request your assistance with the following:

  1. Can you confirm whether these application versions are the latest releases currently available?
  2. Has Microsoft already addressed these OpenSSL vulnerabilities through backported security fixes without changing the embedded OpenSSL version?
  3. If not, is there a planned release of updated Microsoft Paint, Microsoft Photos, Microsoft OneDrive, and Microsoft Office Hub packages that include OpenSSL 3.5.7 (or later), or the appropriate secure version?
  4. Is there any Microsoft Security Advisory, KB article, or official documentation confirming the OpenSSL version bundled with these applications or documenting the remediation status of these CVEs?
  5. If these findings are expected until updated application packages are released, can Microsoft provide an official statement or guidance that we can use for our security audit and vulnerability management records?

We would appreciate any available information regarding the planned remediation timeline or official guidance.

Thank you for your assistance.

Kind regards,

Microsoft 365 and Office | OneDrive | Other | Windows
0 comments No comments

Answer accepted by question author
Kai-H 25,940 Reputation points Microsoft External Staff Moderator
2026-08-05T07:17:56.0066667+00:00

Hi, parag sarode

The scanner is identifying the OpenSSL version embedded in each signed application package. Those DLLs should not be replaced or deleted manually, because doing so can damage the app or invalidate its package signature.

The listed builds appear current or newer than the publicly documented releases. However, Store and OneDrive updates roll out gradually, so there is no single “latest” build for every device. The official OneDrive release notes specifically note that installed versions can be newer than the published list.

I could not find a public confirmation that these specific CVEs were backported while retaining OpenSSL 3.4.4, 3.5.6, or 3.6.3. Without a Microsoft VEX or product advisory marking a CVE as fixed or not affected, it should not be assumed remediated.

OpenSSL’s June advisory identifies 3.4.6, 3.5.7, and 3.6.3 as corrected versions for the documented issues, depending on the release branch. No public Microsoft release date is currently documented for updated Paint, Photos, OneDrive, or Office Hub packages.

Check the MSRC Security Update Guide for each CVE. MSRC has published VEX data for at least CVE-2026-9076, but I found no public KB covering the complete application list.

For audit evidence, open a Microsoft enterprise support case and request a written product-team statement covering affected status, backports, and remediation dates. Until then, record the finding as vendor-managed, keep the apps updated, and do not modify the signed DLLs.

Please be advised that this is a user-to-user support forum. Moderators and contributors, including external Microsoft employees, are not allowed to directly interfere with Microsoft product features or access back-end systems. Our role is limited solely to providing technical guidance on reported incidents, requests, or ideas.   

Thank you for your patience in reading, I hope this information has been helpful to you. 


If the answer is helpful, please click "Yes" and kindly upvote it. If you have extra questions about this answer, please click "Comment."    

Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

Was this answer helpful?

4 people found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.