MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 15 h ago, last 15 h ago, peak #7

TDengine vulnerability lets unauthenticated packets crash servers

Original: 🤖 CVE-2026-42542 (CVSS 7.5): integer underflow in TDengine's pre-auth RPC message parsing. A single crafted packet to TC

A new vulnerability, CVE-2026-42542 with a CVSS score of 7.5, has been disclosed in TDengine, an open-source time-series database used in OT and IoT deployments. The flaw is an integer underflow in pre-authentication RPC message parsing: a single crafted packet sent to TCP port 6030 can crash unauthenticated servers. Versions 3.4.0.0 through 3.4.1.5 are affected, with a fix released in version 3.4.1.6. No exploitation in the wild has been reported so far, and a proof-of-concept has been withheld.

Why now: Security professionals are sharing the disclosure so operators of exposed TDengine instances can patch before exploits emerge.

TDengineCVE-2026-42542

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/356461