Denial-of-Service
Cisco ASA and FTD Under Active Attack: Unauthenticated VPN Flaw Reloads Firewalls On Demand (CVE-2026-20349)
CVE-2026-20349, an unauthenticated heap inspection flaw in Cisco ASA and FTD's Remote Access SSL VPN service, is being actively exploited to remotely crash firewalls — CISA gave federal agencies until August 14 to patch, and no workaround exists.
A Third NGINX Heap Overflow in Two Months: CVE-2026-42533 Hits the map Directive
F5 patched CVE-2026-42533, a CVSS 9.2 unauthenticated heap buffer overflow in NGINX's script engine reachable through the map directive's regex handling, plus two lower-severity sibling bugs — all landing in Ingress Controller, Gateway Fabric, and App Protect WAF.
HollowByte: An 11-Byte TLS Handshake Payload That Bloats OpenSSL Server Memory
A memory-allocation flaw in OpenSSL's TLS handshake parsing, dubbed HollowByte, lets an unauthenticated attacker exhaust server memory with an 11-byte payload per connection. No CVE was assigned; patched in 4.0.1 and backported across the 3.x line.
HTTP/2 Bomb: One Cheap Client Pins 32GB on NGINX, Apache, IIS, Envoy and Cloudflare
A new HPACK-plus-flow-control DoS lets a home broadband connection hold 32GB of server memory in ~20 seconds. Affects the default HTTP/2 config of every major web server and proxy. NGINX and Apache have fixes; IIS, Envoy and Cloudflare Pingora do not yet.
CVE-2026-23442: Remote Kernel Panic via SRv6 NULL Pointer Dereference Threatens IPv6 Infrastructure
A CVSS 8.2 flaw in the Linux kernel's SRv6 implementation lets remote attackers crash systems with crafted IPv6 packets. Patches are out—update now.
15-Year-Old strongSwan Integer Underflow Lets Unauthenticated Attackers Crash VPN Gateways
CVE-2026-25075 is an integer underflow in strongSwan's EAP-TTLS AVP parser that lets remote, unauthenticated attackers crash the charon IKE daemon — affecting every version since 4.5.0.