THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-16445 (HIGH 7.5) — A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. T

[NVD] CVE-2026-16445 (HIGH 7.5) — A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. T

lownvdPublished 2026-07-21

CVE-2026-16445 CVSS: 7.5 HIGH Published: 2026-07-21T13:17:16.730

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's NetworkManager-based initrd network module. These options are improperly handled and written into a

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16445