logo

New Critical AdGuard Home Flaw Lets Attackers Bypass Authentication

ID: ab126a81-d2fd-50e6-8db2-298ba4221956

STIX ID: report--ab126a81-d2fd-50e6-8db2-298ba4221956

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-13

Date Updated: 2026-04-22

Author: Divya

...
...

AdGuard Home released an emergency hotfix (0.107.73) for CVE-2026-32136, a critical (CVSS 9.8) authentication-bypass vulnerability that lets unauthenticated remote attackers gain full administrative control by sending an HTTP/1.1 request that upgrades to HTTP/2 cleartext (h2c) and bypasses authentication via an internal multiplexer; users are urged to update immediately, block public access to the management interface, and audit logs and DNS rules for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.