Skip to content
Critical Memory Vulnerabilities in Mooncake Transfer Engine Disclosed

Critical Memory Vulnerabilities in Mooncake Transfer Engine Disclosed

First seen 2 Oct 2026, 06:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 15:08 UTC
  • •CVE-2026-103764 allows arbitrary memory read/write with CVSS 9.3.
  • •CVE-2026-103761 enables memory exhaustion, potentially disrupting services.
  • •Patches are available, and immediate updates are recommended for affected systems.

On October 1, 2026, multiple critical vulnerabilities were disclosed in the Mooncake transfer engine, particularly CVE-2026-103764 and CVE-2026-103761. CVE-2026-103764, with a CVSS score of 9.3, allows unauthenticated remote attackers to read and write arbitrary memory, potentially leading to code execution. CVE-2026-103761 presents a memory exhaustion vulnerability that can disrupt service by filling memory without limits. Both vulnerabilities affect versions prior to 0.3.13, with patches available for CVE-2026-103764. Attackers can exploit these vulnerabilities via the TCP transport data port and the handshake RPC port, respectively. The urgency of exploitation for CVE-2026-103761 remains uncertain due to the absence of public proof-of-concept or confirmed exploitation. Security professionals are advised to apply patches immediately and restrict network access to vulnerable ports.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 17h ago How this analysis works

Timeline

2026-10-01
CVE-2026-103764 published
Critical vulnerability allowing arbitrary memory access disclosed with CVSS 9.3.
Feedly
2026-10-01
CVE-2026-103761 published
Memory exhaustion vulnerability disclosed, posing high operational risk.
Redpacketsecurity
2026-10-01
CVE-2026-103765 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-02
Patch released for CVE-2026-103764
Update Mooncake transfer engine to version 0.3.13 or later to mitigate the vulnerability.
Feedly

More articles in this cluster (6)

Following this threat?

Track CVE-2026-103761 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Mooncake are affected?
Versions prior to 0.3.13 are affected by CVE-2026-103764 and CVE-2026-103761.
Is there confirmed exploitation of these vulnerabilities?
No public proof-of-concept or confirmed exploitation has been reported for either vulnerability.
What immediate actions should be taken?
Administrators should upgrade to version 0.3.13 or later and restrict access to vulnerable ports.