What is CVE-2026-18726?
A vulnerability was found in open-iscsi (CVE-2026-18726) that allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. The attack is performed by sending a specially crafted ICMPv6 Router Advertisement containing a zero-length option. Users should mitigate this by updating open-iscsi to the latest patched version.
Azərbaycanca: open-iscsi-də aşkar edilmiş bu boşluq (CVE-2026-18726) eyni lokal şəbəkə seqmentindəki uzaqdan hücumçuya xüsusi hazırlanmış ICMPv6 Router Advertisement paketi göndərərək iscsiuio demonunda xidmət rəddinə (DoS) səbəb olmağa imkan verir. Zərərçəkən sistemlər şəbəkə üzərindən iSCSI xidmətini dayandıra bilər. Təhlükəsizliyi təmin etmək üçün open-iscsi paketini ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Where does an attacker need to be located to exploit CVE-2026-18726?
The attacker must be on the same local network segment.
How is the attack via CVE-2026-18726 carried out?
The attack is performed by sending a specially crafted ICMPv6 Router Advertisement containing a zero-length option.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.