Skip to content
Threat Feed

Tag

Networking

20 briefs RSS
low advisory

CVE-2026-93488 Denial of Service in Netty SpdySessionHandler

The Netty SpdySessionHandler component is vulnerable to a denial of service attack via uncontrolled concurrent stream allocation, potentially exhausting JVM heap and direct memory.

Netty denial-of-service java networking
1c
high advisory

CoreDNS DoH/DoQ/gRPC RFC 2136 UPDATE Bypass

CoreDNS versions up to 1.14.6 fail to validate DNS UPDATE opcodes over DoH, DoH3, DoQ, and gRPC, allowing attackers to relay unauthorized updates to upstream servers.

CoreDNS dns vulnerability rfc-2136 denial-of-service cve-2026-82399 networking
1r 3t 1c
medium advisory

Certified Address Hijacking in libp2p PeerStore

The @libp2p/peer-store package incorrectly validates PeerRecord envelopes, allowing attackers to inject fraudulent, certified addresses into the records of victim peers.

@libp2p/peer-store supply-chain peer-to-peer networking cve-2026-86039
2t 1c
critical advisory

Remote Code Execution in EFM ipTIME C200E via Command Injection

An unauthenticated remote command injection vulnerability in EFM ipTIME C200E firmware version 1.094 allows remote attackers to execute arbitrary operating system commands via the iux_set.cgi script.

ipTIME C200E remote-code-execution cve-2026-90847 networking command-injection
2t 1c
critical advisory

Stack-based Buffer Overflow in sngrep SIP Parsing

sngrep versions up to 1.8.4 are vulnerable to a stack-based buffer overflow in SIP header formatting routines, allowing attackers to trigger crashes or achieve remote code execution via malformed SIP packets.

sngrep vulnerability rce sip networking
1t 1c
high threat

Cisco IOS XR Software Security Hardening Updates

Cisco has released critical security hardening updates for IOS XR Software addressing seven internally discovered vulnerabilities (CVE-2026-20274 through CVE-2026-20280) that have no known workarounds.

exploited IOS XR Software networking security-update informational
7c updated
high advisory

Multiple Critical Vulnerabilities in HPE Aruba Networking Products

HPE has disclosed a wide range of vulnerabilities across AOS-CX and Fabric Composer, including RCE, privilege escalation, and DoS flaws, impacting numerous versions of the network operating system.

AOS-CX +5 vulnerability networking infrastructure
3t
critical advisory

OS Command Injection in D-Link Virtual Volume Handler

D-Link DNS-340L and DNS-345 network storage devices are susceptible to remote OS command injection via the /cgi-bin/virtual_vol.cgi component, enabling unauthenticated remote code execution.

DNS-340L +4 webserver vulnerability remote-code-execution cve-2026-82692 storage-device cve-2026-85222 command-injection nas +1
3r 3t 1c updated
high advisory

NetworkManager Local Privilege Escalation and Credential Theft via CA Path Manipulation

An improper authorization vulnerability in NetworkManager allows unprivileged local users to bypass 802.1X server certificate validation, facilitating credential theft through rogue access points.

NetworkManager +7 credential-access local-privilege-escalation linux networking 802.1x vulnerability
1t 2c
critical advisory

Critical Traffic Redirection Vulnerability in Submariner

CVE-2026-66785 allows a malicious Kubernetes cluster to intercept inter-cluster traffic by injecting crafted network endpoints into the Submariner control plane.

Submariner kubernetes networking cve-2026-66785 traffic-interception
2t 1c
critical threat

Stack-based Buffer Overflow in TRENDnet TEW-755AP Access Points

A critical stack-based buffer overflow vulnerability in the /sbin/mycli binary of TRENDnet TEW-755AP access points allows remote unauthenticated attackers to execute arbitrary code via the 'ssid' argument.

exploited TEW-755AP remote-code-execution buffer-overflow iot networking vulnerability network-security cve-2026-76590 cve-2026-76591 +2
2r 3t 1c
high advisory

Remote Command Injection in GL.iNet Router Firewall RPC

An OS command injection vulnerability in the Firewall-management RPC component of GL.iNet BE9300 and MT6000 routers allows remote, unauthenticated attackers to execute arbitrary system commands via crafted network parameters.

BE9300 +1 remote-code-execution firewall networking cve
2t 1c
low advisory

Denial of Service Vulnerability in Cisco ASA and FTD

A vulnerability in the web-based management interface of Cisco ASA and Secure Firewall Threat Defense allows an unauthenticated, remote attacker to trigger a device crash via crafted HTTP requests.

Adaptive Security Appliance +1 denial-of-service networking security-appliance
1c
low advisory

MediaTek mt76 Wireless Driver Memory Access Vulnerability

CVE-2026-68310 in the MediaTek mt76 wireless driver for mt7915 chipsets allows for potential memory access issues due to inadequate validation during HE capability lookups.

mt7915 vulnerability networking informational
1c
medium advisory

NULL Pointer Dereference in Linux ath11k Wi-Fi Driver

CVE-2026-68362 describes a NULL pointer dereference vulnerability in the Linux kernel ath11k driver that may lead to denial-of-service or potential code execution via crafted interactions.

ath11k linux kernel-vulnerability denial-of-service vulnerability linux-kernel networking cve-2026-68355
1t 1c
medium advisory

Linux Kernel binfmt_misc Privilege Escalation Vulnerability

CVE-2026-68186 describes a vulnerability in the Linux kernel binfmt_misc module where the have_execfd flag is set prematurely, potentially enabling local privilege escalation.

Linux Kernel +1 linux kernel vulnerability privilege-escalation mac802154 cve linux-kernel networking +2
critical advisory

OS Command Injection Vulnerability in Zyxel WAH7601

An OS command injection vulnerability in Zyxel WAH7601 devices (CVE-2026-13206) allows unauthenticated remote attackers to execute arbitrary system commands.

WAH7601 cve-2026-13206 command-injection zyxel network-device rce credential-access vulnerability networking +1
3t 1c
high advisory

Multiple Vulnerabilities in Cisco IOS XE

Cisco IOS XE contains multiple vulnerabilities that can be exploited by an attacker to achieve remote code execution, bypass security controls, perform unauthorized data disclosure or manipulation, or cause a denial-of-service condition.

IOS XE vulnerability cisco networking dos
1t
medium advisory

CVE-2026-11331: BIND 9 RPZ Bypass and Denial of Service Vulnerability

An attacker can exploit CVE-2026-11331, a flaw in ISC BIND 9's RPZ (Response Policy Zone) processing, by crafting long query names to trigger a mishandled NAMETOOLONG error, leading to either a bypass of RPZ rules or a denial of service due to an unexpected exit of the BIND 9 software.

BIND 9 +4 vulnerability denial-of-service dns bind networking
1c
medium advisory

GoBGP Remote Denial of Service via Malformed BGP Update Message

GoBGP version 4.4.0 is vulnerable to a remote denial-of-service attack where a malformed BGP UPDATE message triggers a nil pointer dereference, crashing the GoBGP process.

gobgp/v4 bgp denial-of-service networking
2r 1t