CISA issues update on dnsmasq vulnerabilities enabling DoS and code execution
Multiple dnsmasq vulnerabilities could enable cache poisoning, DNSSEC-related DoS, information leakage, and DHCPv6-based local root code execution.
Decision Insights Threat Desk • May 11, 2026
Multiple dnsmasq vulnerabilities could enable cache poisoning, DNSSEC-related DoS, information leakage, and DHCPv6-based local root code execution.
Decision Insights Threat Desk • May 8, 2026
A local privilege escalation flaw in Linux kernel versions 4.17+ can let an unprivileged user gain root access. The issue, CVE-2026-31431 (“Copy Fail”), involves algif_aead/AF_ALG page-cache writes and targets in-memory setuid binaries.
Decision Insights Threat Desk • April 23, 2026
Unauthenticated access to DRC INSIGHT COS /v0/configuration lets same-network users modify config, enabling data exfiltration or disruption (CVE-2026-5756).
Decision Insights Threat Desk • April 22, 2026
Ollama’s model quantization engine has an unauthenticated remote information disclosure flaw in CVE-2026-5757 that can let an attacker with model upload access read and exfiltrate server heap memory.
Decision Insights Threat Desk • April 21, 2026
Terrarium vulnerability CVE-2026-5752 enables arbitrary code execution with root privileges via JavaScript prototype chain traversal.
Decision Insights Threat Desk • April 21, 2026
Radware Alteon 34.5.4.0 vADC has a reflected XSS flaw in ReturnTo on /protected/login, enabling JavaScript execution in victims’ browsers.