Linuxsecurity Kerberos Vulnerabilities Lead to Denial of Service Risks
Article Content
- •Kerberos has critical vulnerabilities that can lead to denial of service attacks.
- •Affected CVEs include CVE-2026-11850, CVE-2026-40355, and CVE-2026-40356.
- •Users must update their systems and restart Kerberos to apply necessary security fixes.
Multiple vulnerabilities were discovered in Kerberos, specifically an integer underflow in the berval2tl_data() function (CVE-2026-11850) and issues in the NegoEx mechanism parsing (CVE-2026-40355, CVE-2026-40356). These vulnerabilities could allow remote attackers to crash Kerberos, resulting in denial of service. The vulnerabilities affect various versions of the MIT Kerberos Network Authentication Protocol. Users are advised to update their systems to the latest package versions to mitigate these risks. Affected systems include Ubuntu 26.04 LTS and earlier versions. After applying updates, a restart of Kerberos is necessary to implement changes. The vulnerabilities were disclosed in July 2026, with prior CVE publications dating back to April and June 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Ubuntu and CVE-2026-11850 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…