www.vulncheck.com Critical Memory Vulnerabilities in Mooncake Transfer Engine Disclosed
Article Content
- •CVE-2026-103764 allows arbitrary memory read/write with CVSS 9.3.
- •CVE-2026-103761 enables memory exhaustion, potentially disrupting services.
- •Patches are available, and immediate updates are recommended for affected systems.
On October 1, 2026, multiple critical vulnerabilities were disclosed in the Mooncake transfer engine, particularly CVE-2026-103764 and CVE-2026-103761. CVE-2026-103764, with a CVSS score of 9.3, allows unauthenticated remote attackers to read and write arbitrary memory, potentially leading to code execution. CVE-2026-103761 presents a memory exhaustion vulnerability that can disrupt service by filling memory without limits. Both vulnerabilities affect versions prior to 0.3.13, with patches available for CVE-2026-103764. Attackers can exploit these vulnerabilities via the TCP transport data port and the handshake RPC port, respectively. The urgency of exploitation for CVE-2026-103761 remains uncertain due to the absence of public proof-of-concept or confirmed exploitation. Security professionals are advised to apply patches immediately and restrict network access to vulnerable ports.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track CVE-2026-103761 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Mooncake are affected?
Is there confirmed exploitation of these vulnerabilities?
What immediate actions should be taken?
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…