Redpacketsecurity Denial of Service Vulnerability in Cockpit (CVE-2026-91149)
Article Content
- •CVE-2026-91149 allows unauthenticated DoS attacks on Cockpit.
- •Attackers can exhaust system resources by flooding connections to the service.
- •No active exploitation reported, but urgent remediation is recommended.
A critical vulnerability identified as CVE-2026-91149 affects the Cockpit management interface, allowing unauthenticated remote attackers to exploit the `cockpit-tls` service. By initiating numerous simultaneous connections, attackers can create an unbounded number of detached threads, leading to denial of service (DoS) and making the service unavailable for legitimate users. The flaw primarily affects systems with exposed Cockpit deployments, particularly those on servers and bastion hosts. The vulnerability was published on September 18, 2026, and while it poses a high availability risk, there are currently no reports of active exploitation. Recommended mitigations include restricting access and applying vendor fixes promptly. Monitoring for unusual connection patterns is also advised.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-91149 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…