Skip to content
Critical Vulnerability in Kea DHCP Server Allows Remote Crash

Critical Vulnerability in Kea DHCP Server Allows Remote Crash

First seen 27 Mar 2026, 07:45 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 28, 2026 at 07:45 UTC
  • •CVE-2026-3608 allows unauthenticated remote attacks to crash the Kea DHCP server.
  • •The vulnerability affects enterprise networks and ISPs using the Kea DHCP server.
  • •Immediate action is recommended to prevent service disruptions.

The Internet Systems Consortium (ISC) has issued a critical security advisory regarding a high-severity vulnerability in the Kea DHCP server, tracked as CVE-2026-3608. This vulnerability, published on 2026-03-25, permits unauthenticated remote attackers to exploit a stack overflow error, leading to the crashing of the receiving daemon. The flaw poses a significant risk to enterprise networks and internet service providers that utilize the Kea DHCP server for managing IP allocations. Network administrators are urged to take immediate action to mitigate potential disruptions. The scope of impact includes essential network services that rely on the Kea DHCP server, potentially affecting millions of users. As of the advisory date, there are no known exploits in the wild, but the severity of the vulnerability necessitates prompt attention.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 194d ago How this analysis works

Timeline

2026-03-25
CVE-2026-3608 published
2026-03-27
ISC issues critical advisory on Kea DHCP vulnerability

More articles in this cluster (2)

Following this threat?

Track Internet Systems Consortium and CVE-2026-3608 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed