CVE-2026-6328General

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet processing module, STREAM frame handler modules) allows Protocol Manipulation.This issue affects XQUIC: through 1.8.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-24: 1Mentions · 2026-06-08: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-04-15: 1Technical Details · 2026-06-08: 104-1504-2406-08
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-151
General1
2026-04-241
General1
2026-06-081
Patch1
Full discourse3 posts
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Critical RCE in Windows DNS Client (CVE-2026-41096) & XQUIC protocol manipulation (CVE-2026-6328) threaten data privacy & integrity in transit. DNS cache poisoning also reported in dnsmasq. Patch now! #Cybersecurity #Vulnerabilities #DNS

    Post summary

    The post announces critical RCE and protocol manipulation vulnerabilities in Windows DNS Client and XQUIC (CVE‑2026‑41096 & CVE‑2026‑6328) and urges immediate patching, noting associated DNS cache poisoning in dnsmasq.

    0000069
    14 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-6328: XQUIC Protocol Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04dl6pR0

    Post summary

    The tweet merely announces CVE‑2026‑6328, linking to an external article about business impacts and response, but does not supply technical, exploit, or mitigation details.

    0000029
    29 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-6328 Improper input validation, Improper verification of cryptographic signature vulnerability in XQUIC Project XQUIC xquic on Linux (QUIC protocol implementation, packet pr… https://www.cve.org/CVERecord?id=CVE-2026-6328

    Post summary

    The statement announces CVE‑2026‑6328 as an improper input validation and cryptographic signature verification flaw in the XQUIC project, with no PoC, exploit, active use evidence, or patch details included.

    0000050
    57.2K followersView on X

Explore more