CERT-FR Warns of Squid Proxy Flaws
Multiple vulnerabilities in Squid before version 7.7 allow remote denial of service, data integrity compromise, and security policy bypass.
CERT-FR has issued an advisory covering multiple vulnerabilities affecting Squid proxy versions prior to 7.7. The flaws, tracked under CVE-2026-61642 and detailed in three separate Squid GitHub security advisories published September 12, 2026, could allow an attacker to trigger a remote denial of service, compromise data integrity, or bypass configured security policies within Squid deployments.
No evidence of active exploitation in the wild is mentioned in the advisory. Organizations running Squid as a caching proxy or forward/reverse proxy should consult the referenced vendor security bulletins and upgrade to version 7.7 or later to remediate these issues. As Squid is commonly deployed at network perimeters for web traffic filtering and caching, unpatched instances could expose organizations to service disruption or policy circumvention affecting downstream security controls.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1168
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free