{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aredisredis/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kaspersky:secure_mail_gateway:*:*:*:*:*:*:*:*","cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2023-41056"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Secure Mail Gateway (\u003c 3.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","network-appliance"],"_cs_type":"advisory","_cs_vendors":["Kaspersky"],"content_html":"\u003cp\u003eKaspersky has released a security advisory addressing a remote code execution vulnerability, identified as CVE-2023-41056, within its Secure Mail Gateway product. The vulnerability affects all versions prior to 3.1. This flaw permits an unauthenticated remote attacker to execute arbitrary code on the underlying appliance, potentially leading to a full system compromise. Given that email gateways are internet-facing and process external traffic, this vulnerability represents a high risk for organizations using this software. Defenders should prioritize updating affected appliances to version 3.1 or later as documented in the Kaspersky security bulletin.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated attacker to gain remote code execution capabilities on the gateway. This could result in unauthorized access to internal email communications, potential interception of sensitive information, or the use of the appliance as a beachhead to pivot into the internal corporate network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Kaspersky Secure Mail Gateway to version 3.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eMonitor external-facing network perimeters for anomalous traffic patterns directed at the mail gateway appliance, specifically checking for unconventional payloads in SMTP or management traffic.\u003c/li\u003e\n\u003cli\u003eReview the official Kaspersky security bulletin (12430#170926) for additional hardening steps or configuration changes recommended by the vendor.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T01:44:03Z","date_published":"2026-09-19T01:44:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kaspersky-smg-rce/","summary":"A critical remote code execution vulnerability, CVE-2023-41056, in Kaspersky Secure Mail Gateway allows unauthenticated attackers to execute arbitrary code on affected appliances.","title":"Remote Code Execution Vulnerability in Kaspersky Secure Mail Gateway","url":"https://feed.craftedsignal.io/briefs/2026-09-kaspersky-smg-rce/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-92925"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Redis"],"_cs_severities":["high"],"_cs_tags":["vulnerability","redis","memory-safety","denial-of-service"],"_cs_type":"advisory","_cs_vendors":["Redis"],"content_html":"\u003cp\u003eA memory safety vulnerability, identified as CVE-2026-92925, exists in the Redis cluster bus packet parsing logic. The issue specifically resides in the handling of string-carrying extensions within cluster bus packets, including PING, PONG, and MEET packet types. The parser fails to ensure that these extensions are properly null-terminated before processing, which can lead to an out-of-bounds memory read when the application accesses the payload data. This vulnerability affects Redis deployments utilizing the cluster bus protocol. A remote, unauthenticated attacker can exploit this flaw by sending a specially crafted packet to a target Redis node, potentially crashing the service (denial of service) or causing the system to leak sensitive information stored in memory.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-92925 allows for remote denial of service or the exposure of sensitive memory contents. This impacts the availability and confidentiality of the affected Redis infrastructure. The vulnerability is critical for environments where Redis cluster instances are exposed to potentially untrusted network segments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching Redis instances to the vendor-provided version that includes the fix for CVE-2026-92925. In environments where immediate patching is not possible, restrict network access to the Redis cluster bus port (default port 16379) to authorized internal nodes only using network-level access control lists (ACLs) to mitigate potential remote exploitation.\u003c/p\u003e\n","date_modified":"2026-09-17T19:58:59Z","date_published":"2026-09-17T19:58:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-redis-cve-2026-92925/","summary":"A vulnerability in the Redis cluster bus packet parser allows remote attackers to trigger an out-of-bounds read via crafted PING, PONG, or MEET packets, resulting in potential information disclosure or denial of service.","title":"Out-of-Bounds Read Vulnerability in Redis Cluster Bus","url":"https://feed.craftedsignal.io/briefs/2026-09-redis-cve-2026-92925/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}