Tag
#Network Security
Critical Type Confusion Vulnerability in Suricata (CVE-2026-94083)
A critical type confusion vulnerability (CVE-2026-94083) has been discovered in Suricata, a widely-used network intrusion detection and prevention system. This vulnerability, with a CVSS score of 9.4, can lead to an invalid free operation, potentially causing a denial-of-service (DoS) or remote code execution. The vulnerability affects Suricata versions before 8.0.7 and is triggered when the app-layer.protocols.doh2 is enabled, which is the default setting in Suricata 8.x versions. Immediate patching is recommended to mitigate this critical threat.
Understanding and Defending Against CVE-2026-61876: LuCI DHCPv6 Lease Hostname Injection
CVE-2026-61876 is a high-severity vulnerability in LuCI, a popular open-source interface for OpenWRT routers. The vulnerability allows adjacent network attackers to inject HTML markup into DHCPv6 lease hostnames, potentially leading to XSS attacks. This analysis provides an in-depth look at the vulnerability, its exploitation mechanics, and defensive strategies.