New Critical AdGuard Home Flaw Lets Attackers Bypass Authentication
ID: ab126a81-d2fd-50e6-8db2-298ba4221956
STIX ID: report--ab126a81-d2fd-50e6-8db2-298ba4221956
Feed Name: GBHackers
Threat Score
AdGuard Home released an emergency hotfix (0.107.73) for CVE-2026-32136, a critical (CVSS 9.8) authentication-bypass vulnerability that lets unauthenticated remote attackers gain full administrative control by sending an HTTP/1.1 request that upgrades to HTTP/2 cleartext (h2c) and bypasses authentication via an internal multiplexer; users are urged to update immediately, block public access to the management interface, and audit logs and DNS rules for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
