#HollowByte
2/ FortiSandbox cmd-injection flaws (CVE-2026-39808 + CVE-2026-25089) hit CISA KEV Jul 16 — actively exploited, patch/pull offline by Jul 19. Plus OpenSSL 'HollowByte' pre-auth DoS (11-byte payload). Patch now. Src: CISA / Okta
September 14, 2026 at 9:00 PM
2/ FortiSandbox cmd-injection flaws (CVE-2026-39808 + CVE-2026-25089) hit CISA KEV Jul 16 — actively exploited, patch/pull offline by Jul 19. Plus OpenSSL 'HollowByte' pre-auth DoS (11-byte payload). Patch now. Src: CISA / Okta
September 12, 2026 at 9:00 PM
2/ FortiSandbox cmd-injection flaws (CVE-2026-39808 + CVE-2026-25089) hit CISA KEV Jul 16 — actively exploited, patch/pull offline by Jul 19. Plus OpenSSL 'HollowByte' pre-auth DoS (11-byte payload). Patch now. Src: CISA / Okta
September 7, 2026 at 9:00 PM
2/ FortiSandbox cmd-injection flaws (CVE-2026-39808 + CVE-2026-25089) hit CISA KEV Jul 16 — actively exploited, patch/pull offline by Jul 19. Plus OpenSSL 'HollowByte' pre-auth DoS (11-byte payload). Patch now. Src: CISA / Okta
September 6, 2026 at 9:00 PM
2/ FortiSandbox cmd-injection flaws (CVE-2026-39808 + CVE-2026-25089) hit CISA KEV Jul 16 — actively exploited, patch/pull offline by Jul 19. Plus OpenSSL 'HollowByte' pre-auth DoS (11-byte payload). Patch now. Src: CISA / Okta
September 5, 2026 at 9:00 PM
2/ FortiSandbox cmd-injection flaws (CVE-2026-39808 + CVE-2026-25089) hit CISA KEV Jul 16 — actively exploited, patch/pull offline by Jul 19. Plus OpenSSL 'HollowByte' pre-auth DoS (11-byte payload). Patch now. Src: CISA / Okta
August 31, 2026 at 9:00 PM
2/ FortiSandbox cmd-injection flaws (CVE-2026-39808 + CVE-2026-25089) hit CISA KEV Jul 16 — actively exploited, patch/pull offline by Jul 19. Plus OpenSSL 'HollowByte' pre-auth DoS (11-byte payload). Patch now. Src: CISA / Okta
July 25, 2026 at 12:17 AM
🟢 HollowByte attack payload size is only 11 bytes

🗨️ Specialists at Okta have disclosed details about the HollowByte DoS vulnerability discovered in OpenSSL. An unauthentica…

#news
HollowByte attack payload size is only 11 bytes
Read more
hackmag.com
July 23, 2026 at 9:00 PM
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes.
www.bleepingcomputer.com
July 23, 2026 at 1:12 PM
OpenSSL Fixes HollowByte Memory Exhaustion Bug
OpenSSL Fixes HollowByte Memory Exhaustion Bug
Okta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks.
securityaffairs.com
July 23, 2026 at 3:42 AM
HollowByte: an 11-byte payload freezes OpenSSL server memory. No CVE, just a silent fix. If your patch pipeline keys off advisories, this one never hit your radar. #ThreatIntel #CyberSecurity #ICS https://threat-intelligence.redeyesecurity.com/blog/openssl-hollowbyte-silent-fix-2026
July 22, 2026 at 6:07 PM
New OpenSSL flaw lets attackers crash servers with just 11 bytes. HollowByte DoS vulnerability poses immediate risk to critical…

https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-byte-payload/

#cybersecurity #infosec
July 22, 2026 at 6:30 AM
„HollowByte“: Denial-of-Service-Lücke in OpenSSL | heise online

heise.de/-11370866
„HollowByte“: Denial-of-Service-Lücke in OpenSSL
Die OpenSSL-Maintainer haben stillschweigend eine Denial-of-Service-Lücke geschlossen. Okta nennt sie „HollowByte“.
heise.de
July 21, 2026 at 6:45 PM
11 octets suffisent pour faire tomber un serveur… 😬

Cette faille porte un nom : #HollowByte mais le problème, c'est qu'elle a été corrigée en silence, sans le moindre #CVE pour la signaler.

👉 www.it-connect.fr/openssl-holl...

#Cybersécurité #OpenSSL
11 octets suffisent pour saturer un serveur : voici la faille OpenSSL HollowByte
La faille HollowByte sature la mémoire d'un serveur OpenSSL avec un paquet de 11 octets. Corrigée en silence depuis la version 4.0.1, et sans aucun CVE.
www.it-connect.fr
July 21, 2026 at 1:57 PM
OpenSSL's HollowByte DoS flaw lets attackers freeze server memory with just 11 bytes—and the patch shipped quietly without a CVE. Security teams need to audit their OpenSSL…

https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html

#cybersecurity #infosec
July 21, 2026 at 10:00 AM
[[TLP:CLEAR] OpenSSL opravuje zraniteľnosť HollowByte]

OpenSSL opravuje zraniteľnosť HollowByte umožňujúcu neautentizovanému vzdialenému útočníkovi opakovaným zasielaním špeciálne upravených hlavičiek o veľkosti 11 B v úvodnej fáze TLS požiadavky vykonať útok DoS na cieľovú službu. Na systémoch […]
Original post on mastodonczech.cz
mastodonczech.cz
July 21, 2026 at 8:39 AM
✨ HollowByte: come 11 byte possono esaurire la memoria dei server OpenSSL
Leggi il blog: spcnet.it/hollowbyte-c...
July 21, 2026 at 7:31 AM
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability bit.ly/4vGyARw

#infoSec #hollowbyte #openssl
OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory.
bit.ly
July 21, 2026 at 6:16 AM