CVE-2026-86296
CVSS 10 CRITICAL: a vulnerability was determined in D-Link DIR-822A A_101. EPSS 1% (70th percentile).
Vulnerabilities · 4h ago
CSIRT-ITA warned that a public proof of concept exists for CVE-2026-95675 in the D-Link DAP-1360 web management interface, a remote code execution flaw rated CVSS 9.3. D-Link says the device is end-of-life, so there is no vendor patch or workaround to apply.
The bug is an input-validation failure: a remote, unauthenticated attacker can send crafted HTTP requests to the admin page and get commands executed as root. That can fully compromise the device, let an attacker alter its configuration persistently, and turn it into an access point for further activity on the local network.
For any team still running these units, the exposure sits at the management plane, not just on the box itself. If the interface is reachable from the WAN, a public PoC makes the device an immediately exploitable foothold, and remediation burden stays with the asset owner because the vendor will not ship a fix.
CVSS 10 CRITICAL: a vulnerability was determined in D-Link DIR-822A A_101. EPSS 1% (70th percentile).
CVSS 8.8 HIGH: a security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402.
CVSS 4.3 MEDIUM: a vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402.
2 sources covering this story
D-Link: PoC pubblico per lo sfruttamento della CVE-2026-95675
Disponibile Proof of Concept (PoC) per lo sfruttamento di una vulnerabilità presente nei dispositivi D-Link DAP-1360 non più supportati.
D-Link warns of max severity zero-day bug in DIR-822A routers
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
Part of the PlainSec briefing for 2026-09-23