Defender reports libssl vulnerabilities in numerous Windows components for months

Sergio Bettiol 0 Reputation points
2026-09-02T14:59:20.64+00:00

Microsoft Defender has flagged around 25 vulnerabilities in Openssl 3.4.4, 3.5.6 and 3.6.1.0 ranging from Low to Critical, affecting Microsoft OneDrive and Microsoft Photos. These vulnerabilities have been live since April-June, and I can't find a single Microsoft resource about the vulnerability, planned patches, or potential workarounds.

We're running the latest version of both applications. When can we expect a patch? Has anyone been able to resolve this issue?

defender

The vulnerabilities showing up: CVE-2026-28386, CVE-2026-31790, CVE-2026-34183, CVE-2026-28387, CVE-2026-45446, CVE-2026-31789, CVE-2026-28388, CVE-2026-42764, CVE-2026-34181, CVE-2026-35188, CVE-2026-28390, CVE-2026-42769, CVE-2026-42770, CVE-2026-42765, CVE-2026-34182, CVE-2026-9076, CVE-2026-45447, CVE-2026-42766, CVE-2026-7383, CVE-2026-42767, CVE-2026-34180, CVE-2026-2673, CVE-2026-45445, CVE-2026-28389, CVE-2026-42768.

Windows for business | Windows 365 Business
0 comments No comments

1 answer

Sort by: Most helpful
  1. Chen Tran 12,765 Reputation points Independent Advisor
    2026-09-02T16:26:07.89+00:00

    Hello Sergio,

    Thank you for posting question on Microsoft Windows Forum!

    Based on the issue description. Well! The plausible explanation to this might be of that Microsoft Defender Vulnerability Management (MDVM) performs file-level binary inspection and flags embedded third-party libraries (like libcrypto.dll or libssl.dll) compiled directly into application packages. Probably because Microsoft treats library version updates inside client apps as routine maintenance rather than distinct product vulnerabilities.

    On the other hand, the product teams for OneDrive and Photos (along with apps like Paint or Office Hub) might update their embedded OpenSSL dependencies on their own build release schedules. An app can be on its "latest" public build while still shipping an older OpenSSL build branch. Also for orphaned Cache & installer files. MDVM scans the entire disk surface. It frequently flags inactive, legacy binaries sitting in installer caches or temp directories.

    For an enterprise environment. It is worth considering to open a Microsoft support case for this.

    You can refer to the following link for further reference.

    Hope the above information is helpful!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.