Curl Fixes a 25-Year-Old Bug in Its Largest CVE Release Yet
2026-06-25T20:51:45Z•af1c608698b778d7d1bde0614a33c86536625baf59defd7a0a9fa2cadf16c106
amadeycisaciscocredential-stuffingctemcurlcve-2026-20230cve-2026-20245europolfortibleedfortinetfrontier-ailantronixlibcurlmisticransomwarestealcubiquitivulnerabilityzero-day
What happened
Multiple high-impact security events: curl released a single update fixing 18 vulnerabilities (including a 25-year-old bug) across libcurl (auth bypass, memory safety, host validation). Google-owned Mandiant reported exploitation of Cisco Catalyst SD‑WAN vulnerability CVE-2026-20245 as a zero-day months before disclosure (privileged command execution). Cisco Unified Communications Manager vulnerability CVE-2026-20230 (CVSS 8.6) is being actively exploited to trigger SSRF, write files and gain root. CISA added Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerab
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- af1c608698b778d7d1bde0614a33c86536625baf59defd7a0a9fa2cadf16c106
- Enrichment time
- 2026-06-25T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.