CVE-2026-47784Disclosure(memcached / memcached)

MEDIUMCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch memcached memcached systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • memcached

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-26); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
memcached

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-21: 1Mentions · 2026-05-26: 2Mentions · 2026-05-27: 1Mentions · 2026-05-30: 1Active Exploitation · 2026-05-21: 1Patch / Workaround · 2026-05-30: 1Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 1Technical Details · 2026-05-30: 105-2105-2605-2705-30
Signal classification3 categories
Disclosure
360.0%
Active Exploitation
120.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-211
Active Exploitation1
2026-05-262
Disclosure2
2026-05-271
Disclosure1
2026-05-301
Patch1
Full discourse5 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-47783 & CVE-2026-47784: Two SASL vulnerabilities in Memcached, 8.1 rating 🔥 Two new vulnerabilities Memcached allow an attacker to enumerate valid usernames on the system and guess their passwords because password and username data for SASL password database authentication has a timing side channel. 👉 https://nt.ls/zZBd0

    Post summary

    Two newly disclosed Memcached SASL timing side‑channel vulnerabilities (CVE‑2026‑47783/84) enable attackers to enumerate valid usernames and guess passwords, rated 8.1 CVSS.

    1501061.1K
    7.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Memcached before 1.6.42 got 2 CVEs https://www.openwall.com/lists/oss-security/2026/05/24/7 CVE-2026-47783 / CVE-2026-47784 for timing side channels in processing of username / password data for SASL password database authentication

    Post summary

    The post announces two new CVEs (CVE‑2026‑47783 and CVE‑2026‑47784) affecting Memcached versions before 1.6.42, describing timing side‑channel vulnerabilities during SASL authentication.

    00010216
    4.6K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH Severity: CVE-2026-47784 (CVSS 8.1) memcached <1[.]6[.]42 has timing side channel in SASL auth via memcmp. Allows password extraction over network. Upgrade to 1[.]6[.]42+ immediately. #CVE #Vulnerability #PatchNow https://t.co/mPOf0GSZYN

    Post summary

    The tweet reports a timing side‑channel flaw in memcached SASL authentication, highlights its CVSS 8.1 severity, and urges upgrading to version 1.6.42 or newer.

    0000047
    32 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    Memcached is leaking your usernames. And then your passwords. CVE-2026-47783 & CVE-2026-47784 - two SASL vulns (CVSS 8.1) that let attackers enumerate valid usernames then brute-force credentials from the exposed SASL password database. 8,539 vulnerable instances confirmed globally. US leads with 1,532. http://vulntracker.io

    Post summary

    The post announces two Memcached SASL vulnerabilities (CVE‑2026‑47783 and CVE‑2026‑47784), providing CVSS scores, attack vectors, and noting over 8,500 confirmed vulnerable instances globally.

    0000097
    655 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting memcached (CVE-2026-47784) https://vuldb.com/vuln/364829/cti

    Post summary

    The post reports increased malicious activity targeting the memcached CVE-2026-47784, implying that this vulnerability is being actively exploited in the wild.

    0000057
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmemcachedmemcached---

Explore more