diff --git a/meta-networking/recipes-daemons/squid/files/CVE-2026-33526.patch b/meta-networking/recipes-daemons/squid/files/CVE-2026-33526.patch
new file mode 100644
index 0000000000..beeb07c339
--- /dev/null
+++ b/meta-networking/recipes-daemons/squid/files/CVE-2026-33526.patch
@@ -0,0 +1,35 @@
+From 8a7d42f9d44befb8fcbbb619505587c8de6a1e91 Mon Sep 17 00:00:00 2001
+From: Joshua Rogers <megamansec@gmail.com>
+Date: Tue, 10 Feb 2026 19:58:49 +0000
+Subject: [PATCH] Do not escape malformed URI twice when sending ICP errors
+ (#2374)
+
+In this context, escaping escaped URI always produces incorrect URI
+because `%` character in the escaped URI gets escaped again. Feeding the
+result of the first rfc1738_escape() call to the second call is also
+dangerously wrong because the result of the first call gets invalidated
+during the second call.
+
+No other cases of such "chained" rfc1738_escape() calls were found.
+
+Broken since 2002 commit e6ccf245.
+
+CVE: CVE-2026-33526
+Upstream-Status: Backport [https://github.com/squid-cache/squid/commit/8a7d42f9d44befb8fcbbb619505587c8de6a1e91]
+Signed-off-by: Peter Marko <peter.marko@siemens.com>
+---
+ src/icp_v2.cc | 1 -
+ 1 file changed, 1 deletion(-)
+
+diff --git a/src/icp_v2.cc b/src/icp_v2.cc
+index 2a4ced3bf..25f7b71d2 100644
+--- a/src/icp_v2.cc
++++ b/src/icp_v2.cc
+@@ -457,7 +457,6 @@ HttpRequest *
+ icpGetRequest(char *url, int reqnum, int fd, Ip::Address &from)
+ {
+     if (strpbrk(url, w_space)) {
+-        url = rfc1738_escape(url);
+         icpCreateAndSend(ICP_ERR, 0, rfc1738_escape(url), reqnum, 0, fd, from, nullptr);
+         return nullptr;
+     }
diff --git a/meta-networking/recipes-daemons/squid/squid_6.14.bb b/meta-networking/recipes-daemons/squid/squid_6.14.bb
index fc5b827da2..965704920b 100644
--- a/meta-networking/recipes-daemons/squid/squid_6.14.bb
+++ b/meta-networking/recipes-daemons/squid/squid_6.14.bb
@@ -22,6 +22,7 @@ SRC_URI = "https://github.com/squid-cache/${BPN}/releases/download/SQUID_${PV_U}
            file://squid.nm \
            file://CVE-2025-59362.patch \
            file://CVE-2025-62168.patch \
+           file://CVE-2026-33526.patch \
            "
 
 SRC_URI[sha256sum] = "9eafe06f58a199b918e79d33d8aa03afb9ae0c11d18974dca0b44c2669cab6dd"
