Cryptorank Critical Suricata Flaws Allow Network Crashes
Article Content
- •Two critical vulnerabilities in Suricata released on September 20, 2026.
- •CVE-2026-94084 and CVE-2026-94083 allow unauthenticated attackers to crash the IDS/IPS.
- •Suricata 8.0.7 is available to patch these vulnerabilities.
On September 20, 2026, the OISF released Suricata 8.0.7 to address two critical vulnerabilities, CVE-2026-94084 and CVE-2026-94083, both with a CVSS score of 9.4. These flaws allow unauthenticated attackers to crash the Suricata IDS/IPS, bypassing network monitoring. CVE-2026-94084 is a use-after-free vulnerability in HTTP/2 inspection, while CVE-2026-94083 involves type confusion in the DoH2 parser. Both vulnerabilities affect all Suricata versions prior to 8.0.7. The flaws expose significant risks, especially in environments using default configurations. Organizations are urged to update to the latest version to mitigate these risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CVE-2026-94083 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…