logo

ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely

ID: ac1f5d34-f7a8-55cc-a2d3-d46772ed4d65

STIX ID: report--ac1f5d34-f7a8-55cc-a2d3-d46772ed4d65

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-27

Date Updated: 2026-05-05

Author: Abinaya

...
...

The ISC published an advisory for CVE-2026-3608 — a CVSS 7.5 stack-overflow vulnerability in Kea DHCP daemons (kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, kea-dhcp6) that allows unauthenticated remote attackers to crash services and cause widespread DHCP outages; ISC recommends immediate upgrades (Kea 2.6.5 / 3.0.3) and temporary mitigation by securing API sockets with TLS and mutual authentication. No active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.