Tag
CVE-2026-93488 Denial of Service in Netty SpdySessionHandler
1 CVEThe Netty SpdySessionHandler component is vulnerable to a denial of service attack via uncontrolled concurrent stream allocation, potentially exhausting JVM heap and direct memory.
CoreDNS DoH/DoQ/gRPC RFC 2136 UPDATE Bypass
1 rule 3 TTPs 1 CVECoreDNS versions up to 1.14.6 fail to validate DNS UPDATE opcodes over DoH, DoH3, DoQ, and gRPC, allowing attackers to relay unauthorized updates to upstream servers.
Certified Address Hijacking in libp2p PeerStore
2 TTPs 1 CVEThe @libp2p/peer-store package incorrectly validates PeerRecord envelopes, allowing attackers to inject fraudulent, certified addresses into the records of victim peers.
Remote Code Execution in EFM ipTIME C200E via Command Injection
2 TTPs 1 CVEAn unauthenticated remote command injection vulnerability in EFM ipTIME C200E firmware version 1.094 allows remote attackers to execute arbitrary operating system commands via the iux_set.cgi script.
Stack-based Buffer Overflow in sngrep SIP Parsing
1 TTP 1 CVEsngrep versions up to 1.8.4 are vulnerable to a stack-based buffer overflow in SIP header formatting routines, allowing attackers to trigger crashes or achieve remote code execution via malformed SIP packets.
Cisco IOS XR Software Security Hardening Updates
7 CVEsCisco has released critical security hardening updates for IOS XR Software addressing seven internally discovered vulnerabilities (CVE-2026-20274 through CVE-2026-20280) that have no known workarounds.
Multiple Critical Vulnerabilities in HPE Aruba Networking Products
3 TTPsHPE has disclosed a wide range of vulnerabilities across AOS-CX and Fabric Composer, including RCE, privilege escalation, and DoS flaws, impacting numerous versions of the network operating system.
OS Command Injection in D-Link Virtual Volume Handler
3 rules 3 TTPs 1 CVED-Link DNS-340L and DNS-345 network storage devices are susceptible to remote OS command injection via the /cgi-bin/virtual_vol.cgi component, enabling unauthenticated remote code execution.
NetworkManager Local Privilege Escalation and Credential Theft via CA Path Manipulation
1 TTP 2 CVEsAn improper authorization vulnerability in NetworkManager allows unprivileged local users to bypass 802.1X server certificate validation, facilitating credential theft through rogue access points.
Critical Traffic Redirection Vulnerability in Submariner
2 TTPs 1 CVECVE-2026-66785 allows a malicious Kubernetes cluster to intercept inter-cluster traffic by injecting crafted network endpoints into the Submariner control plane.
Stack-based Buffer Overflow in TRENDnet TEW-755AP Access Points
2 rules 3 TTPs 1 CVEA critical stack-based buffer overflow vulnerability in the /sbin/mycli binary of TRENDnet TEW-755AP access points allows remote unauthenticated attackers to execute arbitrary code via the 'ssid' argument.
Remote Command Injection in GL.iNet Router Firewall RPC
2 TTPs 1 CVEAn OS command injection vulnerability in the Firewall-management RPC component of GL.iNet BE9300 and MT6000 routers allows remote, unauthenticated attackers to execute arbitrary system commands via crafted network parameters.
Denial of Service Vulnerability in Cisco ASA and FTD
1 CVEA vulnerability in the web-based management interface of Cisco ASA and Secure Firewall Threat Defense allows an unauthenticated, remote attacker to trigger a device crash via crafted HTTP requests.
MediaTek mt76 Wireless Driver Memory Access Vulnerability
1 CVECVE-2026-68310 in the MediaTek mt76 wireless driver for mt7915 chipsets allows for potential memory access issues due to inadequate validation during HE capability lookups.
NULL Pointer Dereference in Linux ath11k Wi-Fi Driver
1 TTP 1 CVECVE-2026-68362 describes a NULL pointer dereference vulnerability in the Linux kernel ath11k driver that may lead to denial-of-service or potential code execution via crafted interactions.
Linux Kernel binfmt_misc Privilege Escalation Vulnerability
CVE-2026-68186 describes a vulnerability in the Linux kernel binfmt_misc module where the have_execfd flag is set prematurely, potentially enabling local privilege escalation.
OS Command Injection Vulnerability in Zyxel WAH7601
3 TTPs 1 CVEAn OS command injection vulnerability in Zyxel WAH7601 devices (CVE-2026-13206) allows unauthenticated remote attackers to execute arbitrary system commands.
Multiple Vulnerabilities in Cisco IOS XE
1 TTPCisco IOS XE contains multiple vulnerabilities that can be exploited by an attacker to achieve remote code execution, bypass security controls, perform unauthorized data disclosure or manipulation, or cause a denial-of-service condition.
CVE-2026-11331: BIND 9 RPZ Bypass and Denial of Service Vulnerability
1 CVEAn attacker can exploit CVE-2026-11331, a flaw in ISC BIND 9's RPZ (Response Policy Zone) processing, by crafting long query names to trigger a mishandled NAMETOOLONG error, leading to either a bypass of RPZ rules or a denial of service due to an unexpected exit of the BIND 9 software.
GoBGP Remote Denial of Service via Malformed BGP Update Message
2 rules 1 TTPGoBGP version 4.4.0 is vulnerable to a remote denial-of-service attack where a malformed BGP UPDATE message triggers a nil pointer dereference, crashing the GoBGP process.