Affects the Linux kernel netfilter/ip6tables used broadly across servers, cloud instances, routers and appliances; enables firewall bypass and could expose orgs to large-scale network compromise.
CVE-2026-72348
Linux netfilter IPv6 extension header parsing flaw allows ip6tables bypass
Is CVE-2026-72348 being exploited?
Not confirmed. CVE-2026-72348 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.63% probability of exploitation in the next 30 days.
How severe is CVE-2026-72348?
CVE-2026-72348 is rated Critical with a CVSS score of 9.1. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72348?
Yes. A fix has been recorded for CVE-2026-72348. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72348 affect?
CVE-2026-72348 affects Linux kernel (netfilter/ip6tables), Linux servers and workstations, Cloud VMs running Linux, Embedded Linux routers/firewalls, and 1 further product or version. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72348?
Install vendor kernel/security updates immediately; if needed, restrict or disable IPv6 and tighten firewall rules.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Malformed IPv6 extension headers can be hot-dropped avoided and thus bypass ip6tables drop rules, allowing unauthorized IPv6 traffic and potential exploitation.
Immediate action required
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < f16d856b6af5fd0e7cb0b0212f70825b599ef72e
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < fc416870100cf16d5b9495199355a679c3a02d48
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < f775fcf384b06f35b612f78fa5601fee99eb6513
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 2fd89a50a9783eed8ed23866b11c8b3d8779a7a8
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 3578b6d92a5b1e603ae6e8c8f5538a709f03aba4
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 3d441be2b1c5e98167302fa1c7b61960a067b112
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < d5e39e5eb6b30bc4a3bb7aba54c293cf36a806c7
- affected>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and < 43ccc20b5a733226417832cf16ef45322e594990
- affected2.6.12
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.