Redpacketsecurity Critical Buffer Overflow Vulnerabilities in SIPp Discovered
Article Content
- •CVE-2026-90778 and CVE-2026-90779 affect SIPp versions up to 3.7.7.
- •Both vulnerabilities allow unauthenticated remote exploitation, leading to process crashes.
- •Immediate patching and access restrictions are critical for internet-facing deployments.
Two critical vulnerabilities, CVE-2026-90778 and CVE-2026-90779, have been identified in SIPp versions up to 3.7.7. CVE-2026-90778 allows unauthenticated remote attackers to exploit a buffer overflow in the get_peer_tag() function, while CVE-2026-90779 affects the createAuthHeader() function, leading to stack corruption. Both vulnerabilities can cause the SIPp process to crash, disrupting call generation and monitoring workflows. The vulnerabilities are particularly dangerous for internet-facing deployments, where attackers can send crafted SIP messages to exploit the flaws without requiring authentication or user interaction. No proof-of-concept code or active exploitation has been confirmed yet, but the urgency for remediation is high. Affected systems include automated SIP test harnesses and monitoring systems connected to untrusted endpoints. Immediate patching and access restrictions are recommended for vulnerable systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-90778 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…