A high-severity vulnerability, CVE-2026-56766, was disclosed in Hydra through version 9.7, where the tool’s NTLM authentication handler can trigger a stack buffer overflow when processing a malicious NTLM Type-2 challenge from a server. The flaw affects the SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules, and occurs when an excessively long domain string causes base64-encoded response data to overflow a 500-byte stack buffer by roughly 18 to 330 bytes.
The bug can lead to remote code execution on systems that do not have stack protection enabled. The issue was fixed in commit 9cc84c2, and defenders are advised to update Hydra to a version containing that fix, apply relevant security patches, enable stack protection, and review environments where Hydra performs NTLM authentication against untrusted or potentially malicious servers.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-56766 was published on 2026-06-25 for a high-severity stack buffer overflow in Hydra through version 9.7 affecting NTLM authentication handling across several modules. The advisory states the issue can be triggered by an excessively long domain string in an NTLM Type-2 challenge.
A stack buffer overflow in Hydra's NTLM authentication handling affecting multiple protocol modules was fixed in commit 9cc84c2. The flaw could allow remote code execution on systems without stack protection when processing a crafted NTLM Type-2 challenge from a malicious server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.