Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

D-Link finds no fix for critical DIR-822A router flaw with public exploit code

D-Link disclosed a maximum-severity vulnerability, CVE-2026-86296, affecting its legacy DIR-822A dual-band routers, caused by a stack-based buffer overflow in the DHCP server component. The bug requires no authentication and can be triggered by sending crafted DHCP packets over the local network, potentially crashing the device or enabling remote code execution. A proof-of-concept exploit is already public, and D-Link has not yet released a patch. The company is also probing a second flaw, CVE-2026-86510, an out-of-bounds write in the L2TP parser reported by the same researcher.

Check Point patches critical root RCE bug in Security Management Server, Log Server

Check Point has issued security updates for CVE-2026-91843, a stack-based buffer overflow in the login process of its Security Management Server and Log Server products. The flaw allows unauthenticated attackers to remotely execute code with root privileges in low-complexity attacks requiring no user interaction. Check Point says it isn't aware of active exploitation but has provided detection guidance and interim mitigations for customers who can't immediately apply the fix.

32-Year-Old Buffer Overflow Found in GNU Inetutils Telnetd (CVE-2026-32746)

Researchers from the DREAM Security Research Team disclosed a pre-authentication buffer overflow in the LINEMODE SLC negotiation handler of GNU inetutils' Telnet server, a flaw dating back to 1994. Because many vendors' Telnetd implementations, including those in major Linux distributions, derive from the same codebase, the bug's reach extends well beyond a single project.

SAP patches maximum-severity OVERPASS kernel flaw affecting 10,000+ systems

SAP's September 2026 security update fixes 20 vulnerabilities, headlined by CVE-2026-44756, a critical buffer overflow in the SAP Kernel's Extended Passport Protocol library dubbed OVERPASS by Onapsis researchers. The bug allows unprivileged attackers to remotely execute commands with admin rights via SAP's Internet Communication Manager, and Onapsis estimates over 10,000 internet-facing SAP systems are exposed. SAP also patched CVE-2026-58240, dubbed S4GET, a missing authentication issue in the NetWeaver Message Server that lets unauthenticated attackers compromise an entire SAP cluster.

HPE fixes critical unauthenticated RCE flaw in ArubaOS-CX switches

HPE has released patches for CVE-2026-73749, a critical buffer overflow in ArubaOS-CX that lets unauthenticated attackers send malformed packets to a daemon to gain elevated code execution. The bulletin also lists 23 other vulnerabilities, several rated high severity, affecting management and web modules across multiple AOS-CX release branches. One vulnerable version has already reached end of maintenance but still received a fix due to the severity of the flaw.

Today's top topics: openai anthropic apple android authority beats 360 meta muse sam altman ai safety dario amodei xbox
View all today's topics →