PULSE
FEED
ransomshinyhunters reclama a WARNING · Not Foundransomm3rx reclama a intense.pl · PL · Technologyransomkairos reclama a Unique Repair Services · US · Otherransomchaos reclama a advantech.com · TW · Manufacturingransominterlock reclama a Tekko Enterprises, Inc · US · Not Foundransomwallstreet reclama a Gibson Area Hospital & Health Services · US · Healthcareransomemperador reclama a Polikem · TR · Manufacturingransomgammax reclama a AHeadStart Tutoring · NZ · Educationransomgammax reclama a Crowder Industries, Inc · US · Manufacturingransombraincipher reclama a latitudesubro.com · BR · Manufacturingransomlockbit5 reclama a spg.co.kr · KR · Otherransombraincipher reclama a trailerbridge.com · US · Transportationransombraincipher reclama a mccordclaims.com · US · Financial Servicesransombraincipher reclama a goriteway.com · GE · Not Foundransomshinyhunters reclama a WARNING · Not Foundransomm3rx reclama a intense.pl · PL · Technologyransomkairos reclama a Unique Repair Services · US · Otherransomchaos reclama a advantech.com · TW · Manufacturingransominterlock reclama a Tekko Enterprises, Inc · US · Not Foundransomwallstreet reclama a Gibson Area Hospital & Health Services · US · Healthcareransomemperador reclama a Polikem · TR · Manufacturingransomgammax reclama a AHeadStart Tutoring · NZ · Educationransomgammax reclama a Crowder Industries, Inc · US · Manufacturingransombraincipher reclama a latitudesubro.com · BR · Manufacturingransomlockbit5 reclama a spg.co.kr · KR · Otherransombraincipher reclama a trailerbridge.com · US · Transportationransombraincipher reclama a mccordclaims.com · US · Financial Servicesransombraincipher reclama a goriteway.com · GE · Not Found
← All CVEs
CVE WatchSep 30, 2026

CVE-2026-81433

A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attac

CVSS

—

No CVSS

EPSS

—

KEV

—

Exploit Today

0

0-100

Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-120 · CWE-121 · CWE-787

EPSS · 30d

Not enough EPSS history yet.

Technical description

A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-18145—
—
——0A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.5h
CVE-2026-742257.1 HIG
—
——0U-Boot before 2026.10-rc5 contains out-of-bounds memory access in dhcp6_parse_options() that fails to validate SERVERID and CLIENTID option lengths from DHCPv6 packets. Attackers on the local network can send crafted DHCPv6 ADVERTISE or REPLY packets during netboot to corrupt memory and crash the bootloader.7h
CVE-2026-719744.8 MED
—
——0U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply crafted boot media with oversized headers to write past the load buffer into bootloader memory on devices without Android Verified Boot protection.7h
CVE-2026-719725.9 MED
—
——0U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory adjacent to the framebuffer and crash the bootloader.7h
CVE-2026-719718.2 HIG
—
——0U-Boot before 2026.10-rc3 with CONFIG_IP_DEFRAG enabled contains an out-of-bounds write vulnerability in the __net_defragment() function in net/net.c. Remote attackers can send a crafted IP fragment with non-zero offset and More-Fragments flag set during netboot to corrupt adjacent memory and crash the bootloader.7h
CVE-2026-1023028.8 HIG
—
——0Buffer overflow in V8 in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)8h