• Home
  • Article
  • Beware of Memcached UDP Reflection DDoS Attacks

Beware of Memcached UDP Reflection DDoS Attacks

Cloudmatika / March 24, 2026
Beware of Memcached UDP Reflection DDoS Attacks

Last February, we became aware of a new type of DDoS reflection attack targeting several Memcached servers via UDP traffic. Cloudmatika identified this new vector when we detected an external DDoS attack targeting UDP port 11211 on Memcached servers. By default, Memcached listens on localhost via TCP and UDP port 11211 in most Linux versions; however, in some distributions, it is pre-configured to listen on this port across all interfaces.

Fundamentally, Memcached is not supposed to have outbound interconnections to external networks and should only communicate within the local network. Cloudmatika immediately notified our customers to fix this bug on their Memcached servers listening on UDP port 11211 and advised them to restrict access strictly to the local network wherever possible.

As cited in the Akamai Blog—a prominent resource on website vulnerabilities and security—there are currently more than 50,000 known vulnerable systems running on these Memcached servers. When a system receives Memcached requests, it crafts a response by gathering the requested values from memory and transmitting them via an uninterrupted stream.

Similar to most previous DDoS Reflection and Amplification attacks, the primary resolution for this Memcached attack is to disconnect it from the internet, meaning Memcached communications and requests should only be permitted locally. Blocking port 11211 is the baseline defense and will prevent systems within your network from being exploited as reflectors. Configuring mitigation controls, such as port blocking, will allow this traffic to be handled quickly and efficiently.

Whatsapp Chat Chat with us here
Scroll to Top