Tag
#Suricata
Critical Vulnerability in Suricata: CVE-2026-94084
A critical use-after-free vulnerability (CVE-2026-94084) has been discovered in Suricata versions before 8.0.7. This vulnerability can be exploited remotely, allowing attackers to potentially achieve high confidentiality, integrity, and low availability impacts. Security professionals should update Suricata to version 8.0.7 or later immediately.
Critical Type Confusion Vulnerability in Suricata (CVE-2026-94083)
A critical type confusion vulnerability (CVE-2026-94083) has been discovered in Suricata, a widely-used network intrusion detection and prevention system. This vulnerability, with a CVSS score of 9.4, can lead to an invalid free operation, potentially causing a denial-of-service (DoS) or remote code execution. The vulnerability affects Suricata versions before 8.0.7 and is triggered when the app-layer.protocols.doh2 is enabled, which is the default setting in Suricata 8.x versions. Immediate patching is recommended to mitigate this critical threat.