AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18726

MEDIUM · CVSS 6.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A vulnerability in open-iscsi allows remote attackers on the same local network segment to exploit the iscsiuio daemon, leading to a Denial of Service (DoS) by sending a specially crafted ICMPv6 Router Advertisement. This can cause the daemon to enter an infinite loop, resulting in high CPU usage and unresponsiveness, thereby affecting system availability. Organizations using open-iscsi should prioritize addressing this vulnerability to mitigate potential service disruptions.

CVE
CVE-2026-18726
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%

Original NVD Description

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with a zero-length option, the attacker can trigger an infinite loop. This leads to sustained CPU usage, rendering the daemon unresponsive and impacting system availability. A secondary risk of out-of-bounds reads exists with a short IPv6 payload, though no memory corruption or data exposure has been confirmed.