#Denial of Service
17 stories taggedDenial of Service.

A single bad character can crash a vLLM server, and the fix is still pending
A moderate-severity flaw in the popular AI serving engine lets any logged-in user kill the whole process with one malformed request.

A Fresh Citrix Zero-Day Is Already Being Exploited, and Federal Agencies Have Three Days to Fix It
CVE-2026-88779 hit live networks almost immediately after Citrix shipped patches for two earlier flaws, leaving IT teams scrambling again.

Three High-Severity BIND Flaws Let Attackers Crash the Internet's Phone Book
ISC patched 14 vulnerabilities in BIND 9 on 16 September 2026, including three remotely exploitable bugs that can knock DNS resolvers offline with a single crafted packet.

AMD, Arm, and Nvidia Fix Security Flaws in Graphics and AI Chips
Three of the world's biggest chipmakers released patches this week for flaws that could let attackers crash systems or quietly read private data. Here is what each company fixed and who needs to act.

Mitsubishi Electric factory gear can be knocked offline by a single crafted network packet
A flaw tracked as CVE-2025-3511 lets a remote attacker freeze dozens of Mitsubishi factory automation products with one malformed UDP message, forcing a manual reset to recover.

Cisco firewalls are being crashed through a VPN flaw, and the fix is a full software upgrade
A high-severity bug in Cisco's Secure Firewall ASA and FTD software lets attackers reboot devices remotely with a single crafted web request. Cisco says the attacks started in August.

Cisco Warns Windows Users of High-Severity ClamAV Flaws, Two With Working Attack Code Released
Seven vulnerabilities in the ClamAV antivirus engine affect Cisco's Secure Endpoint Connector software across Windows, macOS, and Linux. Patches land in August.

Researchers Find 84 Flaws in the Guts of 4G and 5G Networks
A Singapore university team says weaknesses in mobile core software could let attackers knock users offline or hijack their sessions.

NASA's Core Flight System has a flaw that can crash spacecraft software
A researcher found that NASA's open-source flight software can be knocked offline by a single malformed command, and the patch for an earlier version of the same bug did not fully close the hole.

Mitsubishi Electric Factory Gear Vulnerable to Network Tampering Attack
A flaw in the CC-Link IE TSN protocol lets a nearby attacker knock dozens of industrial products offline. Mitsubishi has not shipped a fix.

Critical NGINX Flaw Lets Attackers Crash Web Servers From Afar
F5 has patched CVE-2026-42533, a memory bug in nginx that a remote attacker can trigger with a single crafted request.

An 11-byte message can knock OpenSSL servers offline, researchers warn
A newly disclosed flaw nicknamed HollowByte lets attackers exhaust memory on servers running vulnerable versions of OpenSSL, the software that secures most of the web.

A malformed packet can knock Rockwell's Flex 5000 Adapter offline until someone power-cycles it
Rockwell Automation has patched a denial-of-service flaw in a widely deployed factory-floor module. The fix ships as firmware 6.012.

Four Security Firms Patch Serious Flaws in Their Own Products
Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

Unpatched Flaw in Alibaba's XQUIC Lets Anyone Crash HTTP/3 Servers With 260 Bytes
FoxIO researcher Sébastien Féry disclosed the bug on 8 July. There's no fix, no login required, and no malformed packets involved.