CVE-2026-15579

An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the username field length during Web login processing. This may allow a remote attacker to submit a specially crafted overly long input, triggering a buffer overflow that can cause the authentication process to crash and result in a Denial of Service (DoS) attack.

  • Published Sep 18, 2026
  • CVSS 8.8 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-15579 at the National Vulnerability Database