CVE-2026-84776
Deferred Deferred - Pending Action

Unauthenticated Denial of Service in MalCare Security

Vulnerability report for CVE-2026-84776, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: Patchstack

Description

Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
malcare security to 6.69 (inc)
malcare security 6.72

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated denial of service attack affecting MalCare Security versions 6.69 and below. It allows remote attackers to disrupt service without any authentication or user interaction.

Detection Guidance

To detect this vulnerability, check if your WordPress site is running MalCare Security Plugin version 6.69 or below. You can use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly for version details. Monitor for unusual website crashes or hangs without authentication attempts.

Impact Analysis

The vulnerability could cause your MalCare Security service to become unavailable, potentially leaving your systems unprotected. It may lead to downtime and loss of security monitoring capabilities.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by causing service disruptions. A DoS attack may lead to unauthorized downtime, affecting data availability requirements under these regulations. However, the provided context does not explicitly detail compliance impacts.

Mitigation Strategies

Update MalCare Security to the latest version beyond 6.69 to address the unauthenticated Denial of Service vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84776. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart