CVE-2026-49494: Xcitium Client Security / Comodo Internet Security Remote Denial of Service

Published Jun 7, 2026
·
Updated

Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected by 2026 Q3) contain an integer underflow vulnerability in the firewall driver Inspect.sys that allows remote unauthenticated attackers to crash the system by sending a crafted IPv6 packet with a declared payload length smaller than the sum of its extension-header lengths. The unsigned 64-bit payload-length value underflows to a near-maximal integer, triggering an out-of-bounds read and oversized memcpy in the Windows kernel at DISPATCHLEVEL, resulting in a blue screen of death even on hosts with all ports blocked.

Affected Software

2 affected components
Xcitium Xcitium Client Security<13.8.2.10019
Comodo Comodo Internet Security<=12.3.4.8162

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Xcitium Client Security (XCS) to a version that resolves this vulnerability.

    Fixed in 13.8.2.10019
  2. Configuration

    Disable IPv6 on affected Windows hosts to prevent processing of crafted IPv6 packets that exploit the Inspect.sys integer underflow vulnerability.

    Windows (IPv6 network stack) IPv6 = disabled
  3. Compensating control

    Block or filter IPv6 traffic at the network perimeter (firewalls/edge routers) to prevent delivery of crafted IPv6 packets with malicious extension headers that can trigger the Inspect.sys vulnerability.

Event History

Jun 7, 2026
CVE Published
via MITRE·12:08 PM
Data Sourced
via MITRE·12:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Aug 18, 58402
Event
via NVD·03:09 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-49494?

The severity of CVE-2026-49494 is rated high with a score of 7.5.

2

What type of vulnerability is associated with CVE-2026-49494?

CVE-2026-49494 is identified as an integer underflow vulnerability in the Comodo Internet Security's firewall driver.

3

How does CVE-2026-49494 affect Comodo Internet Security?

CVE-2026-49494 allows an attacker to exploit the integer underflow in Inspect.sys to perform a remote denial of service.

4

Is there a known fix for CVE-2026-49494?

Currently, the recommended action is to update to the latest version of Comodo Internet Security where the integer underflow vulnerability has been addressed.

5

Could CVE-2026-49494 lead to data loss?

While CVE-2026-49494 primarily results in a denial of service, it does not directly lead to data loss as it impacts availability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203