Product
An unauthenticated memory exhaustion vulnerability in the Mooncake transfer engine (CVE-2026-103761) allows remote attackers to trigger a denial-of-service condition by repeatedly sending large notify frames to the handshake RPC port.