CVE-2026-3606Disclosure(ettercap-project / ettercap)

LOWCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for ettercap-project ettercap systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

3.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-119CWE-125CWE-787

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ettercap

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Products
ettercap

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-06: 3Active Exploitation · 2026-03-06: 1Technical Details · 2026-03-06: 203-06
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3606 A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef… https://www.cve.org/CVERecord?id=CVE-2026-3606 ----- Traducción: CVE-2026-3606 Se … http://infoflow.cloud`

    Post summary

    A new CVE (CVE-2026-3606) impacting Ettercap's add_data_segment function has been identified and referenced in the CVE database, but no PoC, exploit, or patch details are provided.

    0000032
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3606 A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef… https://www.cve.org/CVERecord?id=CVE-2026-3606

    Post summary

    The text announces a newly discovered vulnerability in Ettercap 0.8.4, identifying the affected function but provides no PoC, exploit, or patch details.

    00000189
    56.6K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Attention, elevated activities detected targeting Ettercap (CVE-2026-3606) https://vuldb.com/?ctiid.349218

    Post summary

    The post reports detected activity around CVE‑2026‑3606 in Ettercap, but no PoC, exploit code, or patch details are shared.

    0000069
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appettercap-projectettercap0.8.4--

Explore more