CVE-2026-44066: Netatalk

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to obtain sensitive information or cause a minor service disruption.

Affected products

  • Netatalk Netatalk: from 3.1.0, up to and including 4.4.2

Published 2026-05-21. Last modified 2026-07-23.