PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19538 NLnet Labs CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T09:16:46.057Z and has not been modified since then. This vulnerability, CVE-2026-19538, involves BLOCKED access control list items on the proxy protocol port that can be bypassed when connecting over TCP or TLS and sending the query twice on a kept-open connection. The vulnerability has a high CVSS score of 8.2 and is classified as HIGH severity. Affected product deployments may be vulnerable to access control bypass, potentially allowing unauthorized access or malicious activity. Security teams and administrators responsible for proxy protocol port configurations and access control management should be aware of this vulnerability and take necessary defensive actions. Further verification is needed due to limited evidence, and defenders should verify configurations, monitor connection attempts, and prioritize patching or mitigation efforts for affected systems.

Vendor
NLnet Labs
Product
NSD
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-01
Advisory published
2026-08-26
Advisory updated
2026-09-01

Who should care

Security teams and administrators responsible for proxy protocol port configurations and access control management should be aware of this vulnerability and take necessary defensive actions. Operators of affected systems, vulnerability management teams, and security personnel should prioritize patching or mitigation efforts and review compensating controls to minimize potential impact. Platform administrators and security teams may need to coordinate with vendors for patching or mitigation guidance specific to their environments.

Technical summary

The BLOCKED access control list items that are evaluated to deny access on the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on a connection that is kept open. This vulnerability has a high CVSS score of 8.2 and is classified as HIGH severity. Affected product deployments may be vulnerable to access control bypass, potentially allowing unauthorized access or malicious activity.

Defensive priority

High-priority defensive review recommended due to high CVSS score of 8.2 and potential for access control bypass.

Recommended defensive actions

  • Review and verify access control configurations for proxy protocol port
  • Implement compensating controls to monitor and restrict suspicious connection attempts
  • Inventory affected systems and prioritize patching or mitigation efforts

Evidence notes

Evidence is limited; primary official records indicate access control list items can be bypassed when connecting over TCP or TLS and sending the query twice on a kept-open connection. Further verification needed. Limited evidence suggests that defenders should verify configurations, monitor connection attempts, and prioritize patching or mitigation efforts for affected systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19538 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19538

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19538 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19538

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.