
16 CVEs in FastNetMon Community Edition. All found, reported, and fixed. Our team ran a full source code audit of FastNetMon CE and surfaced 16 distinct vulnerabilities, now tracked as CVE-2026-48682 through CVE-2026-48697. First, credit where it is due. Huge thanks to Pavel Odintsov and the FastNetMon team. We sent the report and they moved immediately, confirmed the issues, staged fixes, and shipped patches in days. That is exactly how responsible disclosure is supposed to go, and a maintainer who turns it around that fast makes the whole ecosystem safer. The part I am most excited about: we did not find these by hand alone. Much of this audit ran on the same analysis engine we are building into Lory, our autonomous offensive security agent. The pattern that caught most of the worst bugs is simple to describe and brutal in practice, a length value read straight off the wire flowing into a memcpy with no bounds check. Teaching an agent to trace untrusted input from the network boundary to the dangerous sink is exactly what Lory is built to do at scale. FastNetMon was a real-world proving ground, and it delivered. The throughline on the critical ones: wire-controlled length, no validation, into a binary built with zero hardening flags. No stack canary, no FORTIFY, no PIE, no RELRO. That is what turns a parser bug into code execution as root on the box watching your network. If you run FastNetMon CE in production, update now. If you package it yourself, add hardening flags to your build. → All 16, with full technical writeups: Memory corruption CVE-2026-48682 · IPv4 parser OOB read https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48682-ipv4-parser-oob CVE-2026-48683 · NetFlow v9 data flowset OOB https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48683-netflow-v9-data-oob CVE-2026-48684 · NetFlow v9 options template OOB https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48684-netflow-v9-options-oob CVE-2026-48685 · BGP extended length misread https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48685-bgp-extended-length CVE-2026-48686 · BGP NLRI stack overflow (CVSS 9.8, RCE) https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48686-bgp-nlri-stack-overflow CVE-2026-48688 · BGP MP_REACH_NLRI IPv6 https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48688-bgp-mp-reach-nlri-ipv6 CVE-2026-48689 · Dynamic buffer off-by-one https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48689-dynamic-buffer-off-by-one CVE-2026-48690 · Packet storage integer overflow https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48690-packet-storage-integer-overflow CVE-2026-48691 · BGP AS_PATH overflow https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48691-bgp-as-path-overflow Injection CVE-2026-48687 · Juniper plugin command injection https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48687-juniper-cmd-injection CVE-2026-48694 · Juniper NETCONF injection https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48694-juniper-netconf-injection CVE-2026-48695 · MikroTik command injection https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48695-mikrotik-cmd-injection CVE-2026-48696 · ExaBGP sprintf overflow https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48696-exabgp-sprintf-overflow Auth & transport CVE-2026-48692 · Unauthenticated gRPC interface https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48692-grpc-no-auth CVE-2026-48693 · Symlink issue in temp handling https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48693-symlink-tmp CVE-2026-48697 · Missing TLS validation https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48697-missing-tls-validation → Read the C, find the line, prove the impact, disclose it right. #cybersecurity #infosec #vulnerabilityresearch #CVE #networksecurity #BGP #responsibledisclosure #AISecurity
Post summary
The text announces 16 newly discovered CVEs in FastNetMon CE, links to detailed technical writeups, and urges users to apply vendor patches and hardening measures.

