Skip to content
Denial of Service Vulnerability in Net-SNMP (CVE-2026-89147)

Denial of Service Vulnerability in Net-SNMP (CVE-2026-89147)

First seen 12 Sep 2026, 00:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 12, 2026 at 02:55 UTC
  • CVE-2026-89147 affects Net-SNMP versions up to 5.9.5.2.
  • Unauthenticated remote clients can exploit the SMUX module to cause denial of service.
  • Immediate patching and disabling of unnecessary SMUX services are recommended.

A denial of service vulnerability (CVE-2026-89147) has been identified in Net-SNMP versions up to 5.9.5.2, specifically in the SMUX module. This flaw allows unauthenticated remote clients to connect to the SMUX listener and execute a blocking read without a timeout, causing the SNMP daemon (snmpd) to halt indefinitely. Affected systems include internet-facing infrastructure devices and servers running SNMP, particularly where SMUX is enabled. The vulnerability poses a high operational risk as it can disrupt monitoring and alerting capabilities, potentially enabling lateral movement during broader intrusions. Immediate action is advised, including applying vendor patches and disabling SMUX if not required. The vulnerability was published on 2026-09-11, and organizations are urged to monitor for unusual connections and stalled processes. No proof-of-concept or active exploitation has been reported yet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-11
CVE-2026-89147 published
Net-SNMP vulnerability disclosed, allowing denial of service via unauthenticated SMUX read.
Redpacketsecurity
Recent
Advisory issued for mitigation
Organizations are advised to apply patches and monitor for unusual connections to the SMUX service.
www.vulncheck.com

More articles in this cluster (3)

Following this threat?

Track CVE-2026-89147 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed