OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101276

CRITICAL · CVSS 9.2 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical vulnerability in iperf3 version 3.21 allows remote, unauthenticated attackers to exploit a heap use-after-free condition, potentially leading to arbitrary code execution. This occurs when the server's watchdog function frees streams without properly managing associated worker threads, resulting in dereferencing freed memory. Organizations using iperf3 for network performance testing should prioritize upgrading to version 3.22 to mitigate this risk.

CVE
CVE-2026-101276
Severity
CRITICAL
CVSS
9.2
EPSS
0.40%

Original NVD Description

iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.