We had a non-vulnerable version of OpenSSL on our server, and while we've patched regardless - it's my understanding that it isn't necessary to force a password reset.Just going to quote myself to confirm this - every other VB board that I've used has needed to patch and force password changes; so I'm guessing that here is the same. Its something that needs patched if its affected; even though no money is involved.