CVE-2026-60109
Last modified
CVE-2026-60109 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a crafted KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED) containing a PA-DATA element with padata-type 2, 3, 11, or 19. Attackers can exploit a parser and analyzer state mismatch where proc_padata() dereferences an uninitialized pa_data_element field selected by the wrong parsing arm, triggering a crash via a single UDP or TCP packet to port 88 without any credentials or prior authentication.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending a crafted KRB_ERROR message with error-code 25 (KDC_ERR_PREAUTH_REQUIRED) containing a PA-DATA element with padata-type 2, 3, 11, or 19. Attackers can exploit a parser and analyzer state mismatch where proc_padata() dereferences an uninitialized pa_data_element field selected by the wrong parsing arm, triggering a crash via a single UDP or TCP packet to port 88 without any credentials or prior authentication.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zeek | Zeek | < 8.0.9 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-60109?
How severe is CVE-2026-60109?
How do I fix CVE-2026-60109?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-60103Blender 3.0.0 through 5.1.2 contains an out-of-bounds read v…6.8
- CVE-2026-60104Bitwarden Server before 2026.6.0 does not verify that the em…8
- CVE-2026-60105Monsta FTP before 2.14.5 contains a server-side request forg…8.6
- CVE-2026-60106Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-60107Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-60108Zeek before 8.0.9 contains an uncontrolled memory consumptio…8.7
- CVE-2026-6011A weakness has been identified in OpenClaw up to 2026.1.26. …8.1
- CVE-2026-60112AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a m…9.8
- CVE-2026-60113AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Inte…9.8
- CVE-2026-60114Sustainable Irrigation Platform (SIP) through version 5.2.16…8.7
- CVE-2026-60115Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-60118Hi.Events before 1.11.0 contains a missing server-side visib…6.9
Are you affected by CVE-2026-60109?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
