WireGuard gets the headlines, but OpenVPN solves problems WireGuard cannot. TCP mode over port 443 is indistinguishable from HTTPS traffic, making it nearly impossible to block on corporate networks, hotel Wi-Fi, and in countries with deep packet inspection. WireGuard's UDP-only design fails in these environments.
OpenVPN also supports a wider range of cipher suites and authentication methods, including certificate-based auth with a full PKI infrastructure. For organizations that need per-user certificates with revocation capabilities, OpenVPN's X.509 PKI is unmatched.
Two decades of security auditing, CVE tracking, and real-world deployment have hardened OpenVPN into one of the most reliable VPN solutions available. It may not be the newest, but it is the most proven.