CVE-2026-32136Disclosure(adguard / adguardhome)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch adguard adguardhome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTTP/1.1 request that requests an upgrade to HTTP/2 cleartext (h2c). Once the upgrade is accepted, the resulting HTTP/2 connection is handled by the inner mux, which has no authentication middleware attached. All subsequent HTTP/2 requests on that connection are processed as fully authenticated, regardless of whether any credentials were provided. This vulnerability is fixed in 0.107.73.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • adguardhome

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 8 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-11); latest day: 1
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
adguardhome

Deep dive

Activity timeline10 mentions / 5d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-13: 3Mentions · 2026-03-16: 1Mentions · 2026-03-17: 2Mentions · 2026-03-23: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-13: 3Technical Details · 2026-03-16: 1Technical Details · 2026-03-23: 103-1103-1303-1603-1703-23
Signal classification2 categories
Disclosure
880.0%
Patch
220.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure2Patch1
2026-03-133
Disclosure2Patch1
2026-03-161
Disclosure1
2026-03-172
Disclosure2
2026-03-231
Disclosure1
Full discourse10 posts
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    🛑 Votre AdGuard Home est vulnérable à une compromission totale : CVE-2026-32136 🔗 Toutes les infos dans mon article : https://www.it-connect.fr/votre-adguard-home-est-vulnerable-a-une-compromission-totale-cve-2026-32136/ #cybersecurite #adguard #infosec #veilleIT https://t.co/hKQSUfssVs

    Post summary

    The tweet announces that AdGuard Home is vulnerable to a total compromise under CVE‑2026‑32136 and points readers to an external article for more information.

    0801952.2K
    11.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.8 CVSS vulnerability (CVE-2026-32136) in AdGuard Home lets unauthenticated attackers hijack network DNS settings. Update to v0.107.73 now. #CVE #CyberSecurity #NetworkSecurity #InfoSec #DNSHijacking #Vulnerability https://securityonline.info/network-hijack-critical-9-8-cvss-flaw-in-adguard-home-grants-hackers-full-dns-control/ https://t.co/WfUJinw6lw

    Post summary

    The tweet announces a critical vulnerability in AdGuard Home (CVE-2026-32136) that allows DNS hijacking, urges users to upgrade to v0.107.73, but does not provide PoC, exploit code, or evidence of active exploitation.

    040111777
    10.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『allow users to bypass authentication and gain full access to AdGuard Home without valid credentials.』 CVE-2026-32136 Release AdGuard Home v0.107.73 · AdguardTeam/AdGuardHome · GitHub https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73

    Post summary

    CVE‑2026‑32136 enables an authentication bypass in AdGuard Home, granting full access without credentials. No PoC, exploit, or patch is referenced, and no active exploitation is reported.

    00010496
    6.7K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical authentication bypass (CVE-2026-32136) affects `AdGuard Home` via HTTP/2 cleartext (h2c) upgrades. This allows unauthorized admin access. Secure network exposure. #AdGuardHome #AuthBypass #InfoSec https://www.pulsepatch.io/posts/cve-2026-32136-adguard-home-h2c-auth-bypass

    Post summary

    AdGuard Home is exposed to a critical authentication bypass (CVE‑2026‑32136) that allows unauthorized admin access via HTTP/2 cleartext upgrades, but no patch, PoC, or exploit details are provided.

    0000040
    2 followersView on X
  • thibault@akril
    Disclosure

    [IT-Connect] - Votre AdGuard Home est vulnérable à une compromission totale : CVE-2026-32136 - https://www.it-connect.fr/votre-adguard-home-est-vulnerable-a-une-compromission-totale-cve-2026-32136/ 👌😁

    Post summary

    A French blog post announces that AdGuard Home is vulnerable (CVE‑2026‑32136) but provides no further technical details, exploit code, or mitigation advice.

    0000061
    681 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical AdGuard Home Auth Bypass Lets Attackers Seize Full Admin Control CyberInsider reports that CVE-2026-32136 is a critical authentication bypass in AdGuard Home’s h2c handling that allows unauthenticated attackers to access the administrative API, view DNS logs and device inventories, and change core settings. This matters because attackers could redirect all network DNS traffic, disable protections, or lock out admins, turning a home or small-office DNS filter into a network-wide interception point. 🎯 Target: Global/Home & Small Office Networks #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://cyberinsider.com/adguard-home-vulnerable-to-critical-auth-bypass-allowing-admin-control/

    Post summary

    CVE-2026-32136 is a critical authentication bypass in AdGuard Home’s H2C handling that gives attackers full admin control, with no PoC, exploit code, or patch discussion provided.

    0000093
    286 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32136 - Critical AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardHome by sending an HTT... https://www.thehackerwire.com/vulnerability/CVE-2026-32136/ https://t.co/7MHGfhm6h7

    Post summary

    The post announces a critical authentication bypass vulnerability in AdGuard Home, providing basic technical details but no evidence of exploitation, patches, or PoC.

    0000044
    134 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32136 AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.73, an unauthenticated remote attacker can bypass all authentication in AdGuardH… https://www.cve.org/CVERecord?id=CVE-2026-32136

    Post summary

    The excerpt announces that prior to AdGuard Home version 0.107.73, an unauthenticated remote attacker can bypass all authentication, but it provides no PoC, exploit, active exploitation evidence, or patch information.

    00000134
    56.7K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32136: CRITICAL] AdGuard Home vulnerability fixed! Before version 0.107.73, unauthenticated attackers could bypass all authentication by exploiting HTTP/2 cleartext upgrade flaw. Update now.#cve,CVE-2026-32136,#cybersecurity https://cvefind.com/CVE-2026-32136

    Post summary

    AdGuard Home users are advised to update to version 0.107.73 or later to patch a critical authentication bypass vulnerability involving an HTTP/2 cleartext upgrade.

    0000047
    600 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32136: AdGuard Home: HTTP/2 Cleartext (... HTTP/2 cleartext upgrade completely bypasses AdGuard Home auth - inner mux lacks middleware, turning h2c requests into ... https://zerodaysignal.com/vulnerability/CVE-2026-32136 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    AdGuard Home’s HTTP/2 cleartext upgrade bypasses authentication because the inner mux lacks middleware, enabling h2c requests to access the service without credentials.

    0000079
    142 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appadguardadguardhome---

Explore more