By vendor
Zeek vulnerabilities
Known CVEs affecting Zeek products, prioritized by severity, with SEC.co remediation and detection guidance.
2 published vulnerabilities
- CVE-2026-60108HIGH 7.5
Zeek, a popular open-source network security monitoring platform, contains a denial-of-service vulnerability in its FTP analyzer component. An unauthenticated attacker on the network can trigger excessive memory consumption by sending a specially crafted FTP command sequence that forces Zeek to allocate memory without limit, eventually crashing the sensor. This affects Zeek versions before 8.0.9 and requires no credentials or user interaction to exploit.
- CVE-2026-60109HIGH 7.5
Zeek, an open-source network security monitoring platform, contains a crash vulnerability in its Kerberos protocol analyzer. An attacker can send a specially crafted Kerberos error message to port 88 without authentication, causing the Zeek sensor to crash and stop monitoring network traffic. This is a denial-of-service attack that requires only a single packet and no credentials.