THREAT OPS › Threat News › [NVD] CVE-2026-16445 (HIGH 7.5) — A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. T
[NVD] CVE-2026-16445 (HIGH 7.5) — A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. T
CVE-2026-16445 CVSS: 7.5 HIGH Published: 2026-07-21T13:17:16.730
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a
Indicators of compromise
- CVE-2026-16445cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16445