● Daily security briefing
Saturday, August 8, 2026
Friday saw 98 CVEs published with no new KEV entries, though eight critical vulnerabilities demand immediate attention. D-Link DWR-M961 routers are the primary concern, with seven critical flaws (CVE-2026-71958, CVE-2026-71957, CVE-2026-71956, CVE-2026-71955, CVE-2026-71954, CVE-2026-71953, CVE-2026-71952) all scoring 9.8 CVSS affecting hardware version C1 on multiple firmware versions. Additionally, MSI Radix AXE6600 routers contain a critical command injection vulnerability (CVE-2026-71983, CVSS 9.8) in WPS functionality on firmware v781521. Organizations running these consumer and prosumer router models should prioritize firmware updates immediately.
12 criticalacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-71983CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by
- criticalCVE-2026-71958CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attack
- criticalCVE-2026-71957CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can
- criticalCVE-2026-71956CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker ca
- criticalCVE-2026-71955CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote att
- criticalCVE-2026-71954CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup in
- criticalCVE-2026-71953CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A rem
- criticalCVE-2026-71952CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup inter
- criticalCVE-2026-71951CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface.
- criticalCVE-2026-71950CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface.
- criticalCVE-2026-71949CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface.
- criticalCVE-2026-71948CVSS 9.8D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun i
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 5 above.