[CVE-2026-102255] SonicWall SMA1000 SSRF Vulnerability Could Allow Unauthorized Access to Internal Functionality
Published on October 7, 2026
Severity Critical Detail SonicWall has released hotfixes to address a critical Server-Side Request Forgery (SSRF) vulnerability affecting SMA1000 Series secure access appliances. The vulnerability, tracked as CVE-2026-102255, affects the Appliance WorkPlace interface of SMA1000 appliances. The vulnerability stems from an unintended alternate access path that could allow a remote, unauthenticated attacker to abuse the appliance […]
Learn more » Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User
Published on October 6, 2026
Severity Critical Detail Dell has released security updates addressing five vulnerabilities affecting Dell System Update (DSU), including a critical vulnerability that could allow attackers to execute arbitrary code with root privileges. The vulnerabilities affect Dell System Update versions prior to 2.3.0.0, and customers are advised to upgrade as soon as possible. The most severe vulnerability, […]
Learn more » Apache Struts Vulnerabilities Enable Remote Code Execution, DoS and Data Disclosure
Published on October 6, 2026
Severity High Detail Apache has disclosed four security vulnerabilities affecting Apache Struts applications. The vulnerabilities could allow remote code execution (RCE), denial-of-service (DoS), and cross-user data disclosure, depending on application configuration and feature usage. The recommended fixes are Apache Struts 7.4.0 or later or 6.12.0 or later for organizations remaining on the 6.x maintenance branch. […]
Learn more » Microsoft Releases Exchange Server V2 Security Update Adding CVE-2026-96940 Fix
Published on October 5, 2026
Severity High Detail Microsoft has released a revised September 2026 V2 Security Update for on-premises Exchange Server, adding a fix for CVE-2026-96940. The V2 release supplements the original September 2026 Exchange Server Security Update and applies to supported on-premises Exchange Server deployments. Microsoft stated that the vulnerability was identified internally and that it is not […]
Learn more » [CVE-2026-104286] Critical Fortinet FortiMail Zero-Day Vulnerability Actively Exploited in Attacks
Published on October 2, 2026
Severity Critical Detail Fortinet has disclosed a critical zero-day vulnerability affecting FortiMail that is being actively exploited in the wild. Tracked as CVE-2026-104286, the vulnerability could allow an unauthenticated attacker to write arbitrary files to the underlying operating system through specially crafted HTTP or HTTPS requests. The vulnerability results from a combination of Path Traversal […]
Learn more » [CVE-2026-76504] Cisco Catalyst SD-WAN Manager Authentication Bypass Vulnerability Actively Exploited in the Wild
Published on October 1, 2026
Severity Critical Detail Cisco has disclosed a critical authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. Tracked as CVE-2026-76504, the vulnerability is being actively exploited in the wild and could allow an unauthenticated remote attacker to gain administrator-level access to vulnerable systems. The vulnerability exists in the API session-based authentication management component of Cisco Catalyst […]
Learn more » Apple CoreGraphics Zero-Day Vulnerability Actively Exploited in Attacks
Published on September 30, 2026
Severity High Detail Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address a critical zero-day vulnerability affecting the CoreGraphics framework. Tracked as CVE-2026-86950, the vulnerability may have been exploited in an extremely sophisticated attack targeting specific individuals. The vulnerability resides in CoreGraphics, a core Apple framework responsible for rendering graphics, images, and documents across […]
Learn more » CISA Warns of Citrix NetScaler 0-Day RCE Vulnerabilities Exploited in Attacks
Published on September 28, 2026
Severity Critical Detail The U.S. Cybersecurity and Infrastructure Security Agency (CISA) have added two Citrix NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The vulnerabilities affect Citrix NetScaler ADC and NetScaler Gateway appliances and could allow unauthenticated attackers to compromise affected systems remotely. The […]
Learn more » ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data
Published on September 25, 2026
Severity Critical Detail ServiceNow has disclosed five vulnerabilities affecting its AI Platform, including two critical issues that could allow unauthenticated attackers to execute arbitrary SQL commands, access sensitive instance data, modify records, and potentially escalate privileges. The vulnerabilities were disclosed in September 2026 under security advisory KB3159623. ServiceNow reported that there is currently no evidence […]
Learn more » Red Hat OpenShift Flaw Lets Attackers Bypass Signature Checks and Inject Malicious Release Images
Published on September 22, 2026
Severity High Detail Red Hat has disclosed a security vulnerability affecting the oc-mirror utility used by OpenShift environments. Tracked as CVE-2026-75939, the vulnerability could allow attackers to bypass release-image signature verification and inject malicious payloads into disconnected registries. The vulnerability stems from improper verification of PGP-signed OpenShift release images. The oc-mirror utility checks for signature […]
Learn more » SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Published on September 19, 2026
SeverityHigh Detail SolarWinds has released security updates to address a high-severity vulnerability in Access Rights Manager (ARM) that could allow an unauthenticated remote attacker to achieve remote code execution (RCE). Tracked as CVE-2026-28326, the vulnerability carries a CVSS score of 8.8 (High) and affects SolarWinds Access Rights Manager 2026.2 and earlier versions. The vulnerability stems […]
Learn more » CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
Published on September 19, 2026
Severity High Detail The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities affecting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence that the vulnerabilities are being actively exploited in the wild. The three vulnerabilities affect different Linux kernel subsystems and can allow local attackers to cause memory disclosure, […]
Learn more » [CVE-2026-76460] Critical Cisco ISE Authentication Bypass Vulnerability Exploited in the Wild
Published on September 17, 2026
SeverityCritical Detail Cisco has released security updates to address a critical vulnerability, tracked as CVE-2026-76460, affecting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The vulnerability has a CVSS score of 10.0 (Critical) and is being actively exploited in the wild. The vulnerability is caused by insufficient authentication control on an […]
Learn more » Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
Published on September 10, 2026
Severity Critical Detail Palo Alto Networks has disclosed a high-severity buffer overflow vulnerability in PAN-OS that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. The vulnerability is tracked as CVE-2026-0310 and is caused by improper processing of XML data within PAN-OS. The issue affects both […]
Learn more » [CVE-2026-59346, CVE-2026-59347] Critical VMware Workstation and Fusion Vulnerabilities Allow Code Execution on the Host
Published on September 3, 2026
Severity Critical Detail Broadcom has issued a security advisory, VMSA-2026-0007, addressing two vulnerabilities affecting VMware Workstation and VMware Fusion. The vulnerabilities could allow attackers to escape a guest virtual machine and execute code on the underlying host system, potentially compromising the security boundary provided by virtualization. The most severe vulnerability, CVE-2026-59346, is an integer overflow […]
Learn more » [CVE-2026-83548, CVE-2026-83549] SonicWall SMA1000 Vulnerabilities Allow Unauthorized Access and Remote Code Execution
Published on September 2, 2026
Severity Critical Detail SonicWall has disclosed two security vulnerabilities affecting SMA1000 Series secure mobile access appliances under advisory SNWLID-2026-0016. SonicWall confirmed that its Product Security Incident Response Team investigated a case indicating that both vulnerabilities are being actively exploited in the wild. The most severe vulnerability, CVE-2026-83548, is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability […]
Learn more » [CVE-2026-19632] Critical WordPress TranslatePress Bug Enables Complete Site Takeover
Published on August 27, 2026
Severity Critical Detail A critical vulnerability in the TranslatePress WordPress plugin, which is installed on more than 400,000 websites, could allow unauthenticated attackers to take over administrator accounts and gain full control of affected websites. Tracked as CVE-2026-19632, the vulnerability has a CVSS score of 9.8 (Critical) and affects TranslatePress versions 3.3.1 and earlier. The […]
Learn more » [CVE-2026-66152, CVE-2026-66153] SonicWall NetExtender Vulnerabilities Allow an Attacker to Write Arbitrary Files as Root
Published on August 26, 2026
Severity High Detail SonicWall has disclosed two security vulnerabilities affecting the NetExtender Linux Client under advisory SNWLID-2026-0013. The most severe vulnerability, CVE-2026-66152 is a path traversal flaw in the handling of OPSWAT tarball files that could allow an attacker to write arbitrary files with root privileges on affected Linux systems. Successful exploitation could allow unauthorized […]
Learn more » [CVE-2026-69836] Critical Microsoft Entra ID Vulnerability Exploited in the Wild
Published on August 21, 2026
SeverityCritical Detail Microsoft has addressed a critical remote code execution vulnerability, tracked as CVE-2026-69836, affecting Microsoft Entra ID, its cloud identity service formerly known as Azure Active Directory. The vulnerability has a CVSS score of 10.0 (Critical) and was reportedly exploited in the wild. The vulnerability is caused by deserialization of untrusted data in Microsoft […]
Learn more » Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
Published on August 19, 2026
SeverityCritical Detail The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities affecting Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE Service Extensions to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation. The vulnerabilities are tracked as CVE-2026-65400, CVE-2026-55040, CVE-2026-59310, and CVE-2026-33824, with CVSS scores ranging from 9.1 to […]
Learn more » [CVE-2026-71362] Critical Adobe Commerce Flaw Allows Unauthenticated Privilege Escalation
Published on August 13, 2026
SeverityCritical Detail Adobe has released security updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to address multiple critical, important, and moderate vulnerabilities. Successful exploitation of the vulnerabilities could result in security feature bypass, arbitrary code execution, and privilege escalation. Adobe stated that it is not aware of any exploits in the wild […]
Learn more » [CVE-2026-20349] Cisco Releases Security Updates for Actively Exploited Secure Firewall Remote Access SSL VPN DoS Vulnerability
Published on August 13, 2026
SeverityHigh Detail Cisco has released security updates to address a high-severity vulnerability, tracked as CVE-2026-20349, affecting the Remote Access SSL VPN service in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The vulnerability has a CVSS score of 8.6 (High Severity) and can allow an unauthenticated, remote […]
Learn more » Microsoft Outlook RCE Vulnerability Lets Attackers Execute Code Remotely
Published on August 12, 2026
Severity High Detail Microsoft disclosed a new remote code execution (RCE) vulnerability in Microsoft Outlook, tracked as CVE-2026-70329, on August 11, 2026. The vulnerability is rated Important with a maximum CVSS 3.1 score of 8.8. The flaw is classified as CWE-190 (Integer Overflow or Wraparound), where an application incorrectly handles numerical values outside their expected […]
Learn more » 18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host
Published on August 9, 2026
Severity Critical Detail A critical Linux kernel vulnerability, tracked as CVE-2026-64564 and dubbed SCTPhantom, allows an unprivileged local attacker to escalate privileges to full root and, under specific conditions, escape a container and compromise the underlying host. The vulnerability is a use-after-free (UAF) flaw in the Linux kernel’s SCTP Dynamic Address Reconfiguration (ASCONF) functionality. The […]
Learn more » New WordPress Pre-Auth XSS Could Lead to PHP Code Execution
Published on August 8, 2026
Severity High Detail WordPress has disclosed a high-severity pre-authentication reflected cross-site scripting (XSS) vulnerability affecting the WordPress login screen. Tracked as CVE-2026-64638, the vulnerability requires no authentication or attacker privileges and can allow malicious JavaScript to execute in a victim’s browser through a specially crafted username. Researchers at pwn.ai demonstrated that the vulnerability can be […]
Learn more » Critical SonicWall SMA1000 Zero-Day Vulnerabilities Enable Root-Level Compromise
Published on August 3, 2026
Severity Critical Detail SonicWall has disclosed two actively exploited zero-day vulnerabilities affecting SonicWall SMA 1000 appliances. Tracked as CVE-2026-15409 and CVE-2026-15410, the vulnerabilities can be chained to allow unauthenticated attackers to gain root-level access to affected internet-facing VPN gateways. The attack begins by exploiting CVE-2026-15409, a critical pre-authentication vulnerability in the SMA WorkPlace WebSocket proxy […]
Learn more » Broadcom Releases Emergency Security Updates for Critical VMware Authentication Bypass and VM Escape Vulnerabilities
Published on July 31, 2026
Severity Critical Detail Broadcom has released emergency security updates to address five vulnerabilities affecting VMware products, including three critical flaws that could allow attackers to bypass authentication, execute arbitrary code, or escape from a guest virtual machine (VM) to the underlying ESX host. The most severe vulnerabilities affect VMware vCenter Server and VMware ESX. The […]
Learn more » Attackers Can Exploit SolarWinds Web Help Desk Flaw to Trigger Memory-Based DoS
Published on July 31, 2026
Severity Critical Detail SolarWinds has released Web Help Desk (WHD) version 2026.2.1 to address multiple security vulnerabilities including a critical authentication bypass flaw and a high-severity denial-of-service (DoS) vulnerability that could impact the availability and security of affected systems. The most critical issue, CVE-2026-28323, is a SAML authentication bypass vulnerability affecting deployments configured to use […]
Learn more » Cisco Warns of FMC Static Credential Flaw Exploited in Zero-Day Attacks
Published on July 30, 2026
Severity Critical Detail Security researchers and Cisco have disclosed a high-severity vulnerability affecting Cisco Secure Firewall Management Center (FMC) Software, tracked as CVE-2026-20316, which has been actively exploited in zero-day attacks. The vulnerability is caused by the presence of static credentials associated with a low-privilege account built into Cisco Secure FMC Software. An unauthenticated remote […]
Learn more » libssh2 Vulnerabilities Allow Malicious SSH Servers to Corrupt Client Memory
Published on July 28, 2026
Severity High Detail Security researchers have disclosed four high-severity vulnerabilities affecting libssh2, a widely used open-source C library that provides SSH2 protocol support for applications such as remote administration tools, SFTP clients, automated deployment platforms, backup solutions, and file transfer applications. The vulnerabilities affect libssh2 version 1.11.1 and earlier and could allow a malicious SSH […]
Learn more » Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Published on July 23, 2026
Severity Critical Detail Check Point has disclosed a critical authentication bypass vulnerability, tracked as CVE-2026-16232, affecting Check Point Security Management and Multi-Domain Security Management servers. The flaw allows an unauthenticated remote attacker to obtain a valid application login token, authenticate through SmartConsole, and gain full administrator privileges over the management server. According to Check Point, […]
Learn more » Critical ASUS Router Flaw Lets Remote MITM Attackers Execute Arbitrary Commands
Published on July 22, 2026
Severity Critical Detail ASUS has disclosed a critical security vulnerability, tracked as CVE-2026-13385, affecting multiple ASUS router firmware versions. The flaw stems from improper validation of network communications and could allow a remote attacker to execute arbitrary commands through a man-in-the-middle (MITM) attack. According to ASUS, the vulnerability affects firmware branches 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102. […]
Learn more » Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Published on July 21, 2026
Severity Critical Detail Microsoft has disclosed that CVE-2026-50522, a critical remote code execution (RCE) vulnerability affecting Microsoft SharePoint Server, is being actively exploited in the wild. The flaw, caused by insecure deserialization of untrusted data, allows attackers to execute arbitrary code remotely on vulnerable on-premises SharePoint servers. According to Microsoft’s advisory, the vulnerability can be […]
Learn more » Critical WordPress Core Flaw Could Allow Unauthenticated Attackers to Execute Remote Code
Published on July 18, 2026
Severity Critical Detail WordPress has released versions 6.9.5 and 7.0.2 to address a critical pre-authentication remote code execution (RCE) vulnerability, known as wp2shell, affecting WordPress Core. The vulnerability allows an anonymous attacker to execute arbitrary code on a vulnerable WordPress installation without authentication, user interaction, or the presence of third-party plugins. According to the published […]
Learn more » Dell BIOS Flaw Lets Attackers Recover Passwords From SPI Flash
Published on July 11, 2026
Severity Medium Detail Dell has disclosed a security vulnerability, tracked as CVE-2026-40639 (DSA-2026-197) affecting multiple Dell client platforms. This flaw allows attackers with physical access to recover BIOS administrator and user passwords from the device’s SPI flash memory due to the use of an insecure XOR-based password storage mechanism. The vulnerability exists in the SystemPwSmm […]
Learn more » Palo Alto PAN-OS Vulnerability Allows Arbitrary Code Execution Through Malicious Network Traffic
Published on July 10, 2026
Severity High Detail Palo Alto Networks has released security updates to address a high-severity vulnerability in PAN-OS that could allow unauthenticated attackers to execute arbitrary code or cause a denial-of-service (DoS) condition by sending specially crafted network traffic. The vulnerability tracked as CVE-2026-0288 affects the User-ID Terminal Server Agent (TSA) component in PAN-OS and is […]
Learn more » Microsoft patches RoguePlanet Defender zero-day vulnerability
Published on July 9, 2026
Severity High Detail Microsoft has released a security update to address a zero-day vulnerability in Microsoft Defender, RoguePlanet which was publicly disclosed after the June 2026 Patch Tuesday. The vulnerability tracked as CVE-2026-50656 affects fully patched Windows 10 and Windows 11 systems and could allow attackers to gain SYSTEM-level privileges through a race condition in […]
Learn more » Critical BeyondTrust Authentication Vulnerabilities Affect Remote Support (RS) and Privileged Remote Access (PRA) Appliances
Published on July 7, 2026
Severity Critical Detail BeyondTrust has disclosed multiple vulnerabilities affecting its Remote Support (RS) and Privileged Remote Access (PRA) appliances. The vulnerabilities, tracked under advisory BT26-03, include critical and high-severity flaws that could lead to authentication bypass, denial-of-service (DoS), and unauthorized access to sensitive data. The most critical vulnerabilities affect the authentication mechanism and have a […]
Learn more » Winrar Flaw Could Allow Attackers to Take Control of Your Computer
Published on July 4, 2026
Severity High Detail RARLAB has released WinRAR 7.23 to address a high-severity vulnerability tracked as CVE-2026-14191. The flaw affects the way WinRAR and UnRAR process RAR5 recovery-volume (.rev) files and could allow a remote attacker to execute arbitrary code on a victim’s system by convincing a user to open a specially crafted archive. The vulnerability […]
Learn more » Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
Published on June 30, 2026
Severity Critical Detail Progress Software has released security updates to address a critical vulnerability affecting Progress Kemp LoadMaster. The vulnerability, tracked as CVE-2026-8037 that allows an unauthenticated remote attacker to execute arbitrary commands as the root user on affected appliances when the API is enabled. The vulnerability exists in the escape_quotes() function, which is responsible […]
Learn more » Critical Linux Kernel Flaw Allows Unprivileged Users to Gain Full Root Access
Published on June 27, 2026
Severity High Detail A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46331 and nicknamed “Pedit COW,” allows an unprivileged local user to escalate privileges and obtain full root access on affected Linux systems. The vulnerability affects the Linux kernel’s traffic-control subsystem, specifically the tcf_pedit_act() function within the act_pedit module. It impacts Linux kernel versions 5.18 […]
Learn more » [CVE-2026-20262] Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Published on June 16, 2026
Severity Medium Detail Cisco has released security updates to address an actively exploited vulnerability affecting Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage). The vulnerability, tracked as CVE-2026-20262, has a CVSS score of 6.5 (Medium Severity) and may allow an authenticated remote attacker to create or overwrite files on the underlying operating system of an affected […]
Learn more » Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code
Published on June 12, 2026
Severity High Detail Microsoft has released security updates addressing three critical remote code execution (RCE) vulnerabilities affecting Microsoft Outlook and Microsoft Word. The vulnerabilities, tracked as CVE-2026-45456, CVE-2026-45458, and CVE-2026-47635, could allow attackers to execute arbitrary code on affected systems by delivering specially crafted emails or Office documents, originating from memory corruption flaws within the […]
Learn more » Ivanti Endpoint Manager Mobile Vulnerability Enables Remote Code Execution Attacks
Published on June 11, 2026
SeverityHigh Detail Ivanti has disclosed and patched a high-severity vulnerability in Endpoint Manager Mobile (EPMM), tracked as CVE-2026-6973. The vulnerability could allow an authenticated attacker with sufficient privileges to achieve remote code execution by injecting malicious Apache configuration directives into affected systems. The vulnerability is classified under CWE-15 Improper Neutralization of Special Elements in Configuration […]
Learn more » Windows BitLocker 0-Day Vulnerability Allows Attackers to Bypass Security Feature
Published on June 10, 2026
SeverityMedium Detail Microsoft has disclosed and patched Windows BitLocker Security Feature Bypass vulnerability, tracked as CVE-2026-50507, as part of its June 2026 Patch Tuesday security updates. The vulnerability stems from a protection mechanism failure within BitLocker Device Encryption that could allow an unauthorized attacker with physical access to bypass encryption protections and gain access to […]
Learn more » SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver Patched
Published on June 9, 2026
SeverityCritical Detail SAP has released 15 new security notes as part of its June 2026 Security Patch Day, addressing multiple vulnerabilities across core SAP products. Among the updates are four critical-severity vulnerabilities affecting SAP NetWeaver, SAP Commerce Cloud, SAP Data Hub, and related enterprise platforms. The most severe vulnerability, CVE-2026-44748, is an XML Signature Wrapping […]
Learn more » Multiple VMware Stored XSS Vulnerabilities Allow Attackers to Inject Malicious Scripts
Published on June 8, 2026
Severity High Detail Broadcom has disclosed three stored cross-site scripting (XSS) vulnerabilities affecting VMware Cloud Foundation Operations and several related products. Tracked as CVE-2026-41722, CVE-2026-41723, and CVE-2026-41724, the flaws were addressed in security advisory VMSA-2026-0004. No workarounds are currently available, making patching the only viable remediation path. The vulnerabilities stem from stored cross-site scripting flaws […]
Learn more » [CVE-2026-20245] Cisco SD-WAN 0-day exploited, no patch available
Published on June 5, 2026
Severity High Detail Cisco has disclosed an actively exploited privilege escalation vulnerability, tracked as CVE-2026-20245, affecting Cisco Catalyst SD-WAN Manager. At the time of disclosure, no security patch or workaround is available. The vulnerability affects the command-line interface (CLI) of Cisco Catalyst SD-WAN Manager and is caused by insufficient validation of user-supplied input. An authenticated […]
Learn more » Ivanti ITSM Vulnerability Allows Attacker to Gain Admin Privileges
Published on June 3, 2026
Severity High Detail A high-severity vulnerability has been identified in Ivanti Neurons for ITSM, affecting both cloud and on-premises deployments. The flaw, tracked as CVE-2026-9614 is an improper access control vulnerability that allows an authenticated remote attacker with low-level privileges to escalate privileges and gain administrator-level access to affected environments. According to Ivanti, this flaw […]
Learn more » TP-Link Router Vulnerability Allows Attackers to Execute Arbitrary System Commands
Published on June 2, 2026
Severity High Detail A high-severity vulnerability has been identified in TP-Link Archer routers, specifically affecting the Archer BE450 v1 and Archer BE7200 v1 models. Tracked as CVE-2026-5509, the flaw is a command injection vulnerability located within the router’s web management interface. It arises due to insufficient input sanitization in backend system commands, allowing an authenticated […]
Learn more »