CVE-2026-43634Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can exploit this to circumvent fail2ban brute-force protection, bypass per-user IP allowlists, and poison authentication audit logs by spoofing trusted IP addresses on each request.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-348

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-19); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-19: 2Mentions · 2026-05-30: 1Patch / Workaround · 2026-05-30: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-30: 105-1905-30
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-192
Disclosure2
2026-05-301
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-43634 (CVSS 7.5) HestiaCP v1.2.0-1.9.4 IP spoofing flaw allows unauthenticated attackers to bypass authentication via CF-Connecting-IP header manipulation. Circumvents fail2ban & IP allowlists. Patch immediately. #CVE #PatchNow https://t.co/GHkPGCuHBU

    Post summary

    The tweet announces CVE-2026-43634, describes its impact, and urges immediate patching.

    0000038
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43634 HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by … https://www.cve.org/CVERecord?id=CVE-2026-43634

    Post summary

    The text publicly identifies CVE-2026-43634 as an IP spoofing vulnerability in HestiaCP, enabling unauthenticated remote authentication bypass. It provides minimal technical detail and a link to the official CVE record.

    00000142
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43634 IP Spoofing Authentication Bypass in HestiaCP Versions 1.2.0 Thro... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43634 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-43634, noting an IP spoofing authentication bypass in HestiaCP 1.2.0 and links to a vulnerability details page.

    0000067
    4.0K followersView on X

Explore more