Massive security flaws affect entire Tor network: critical patches released
An AI “firehose” is flooding the major anonymity network with bug reports.

- Tor issued emergency fixes for high-severity flaws affecting relays, clients, and onion services.
- The release lists 10 tracked vulnerabilities, but full technical details are delayed to limit attacker use.
- Some bugs could undermine anonymity by linking browsing activity across sessions or separate onion-site visits.
- Tor Browser users may need the next release because version 15.0.23 likely lacks all fixes.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
High-severity vulnerabilities are affecting Tor across the entire network: relays, clients, and onion services. The Tor Project urges upgrades ASAP, as it holds back full technical details from potential attackers.
Tor developers say that “LLM report firehose” once again delivered an avalanche of vulnerabilities.
The project released emergency “high-severity fixes” affecting “all entities” on September 23rd, 2026. The latest release of the Tor network's core software is Tor 0.4.9.13.
“The fixes affect all Tor components: relays, clients, and onion services. We strongly recommend upgrading as soon as possible,” the Tor Project said in a security announcement, relayed to the oss-security mailing list.
The project shared only brief release notes in the security release document and said that detailed technical write-ups, filed as public GitLab tickets, would be released roughly a week later.
Still, the release notes list a total of 16 categories with various bug fixes, including 10 tracked vulnerabilities with assigned TROVE IDs, Tor’s in-house vulnerability numbering system (Tor Registry Of Vulnerabilities and Exposures).
Major security bug fixes hint at a possible memory corruption issue in relays that could, in theory, allow attackers to crash or take control of the devices.
One of the bugs could let a malicious .onion site link together browsing activity that's supposed to stay separate, undermining anonymity.
Another vulnerability in stream isolation could let a malicious .onion site or HSDir relays undermine anonymity by linking browsing activity across multiple sessions.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The Onion service vulnerability also allows attackers to flood services with runaway connection attempts, potentially knocking .onion sites offline.
And a "use-after-free" bug affects Tor connection handling, which could potentially be exploited to crash connections, or worse.
Memory corruption vulnerabilities can sometimes lead to remote code execution. However, the Tor Project hasn't said if that's the case here.
The latest stable Tor Browser version 15.0.23 was released on September 15th, 2026, and likely doesn’t yet incorporate all the fixes. Tor Browser users should look for the next release to get the patch.