● Daily security briefing
Sunday, August 9, 2026
August 9 saw moderate advisory activity with 90 CVEs published and 2 CERT/PSIRT advisories issued, though no KEV additions or critical vendor guidance was released. The day was dominated by a cluster of critical vulnerabilities affecting consumer networking equipment: seven command injection flaws (CVE-2026-71987 through CVE-2026-71993, all CVSS 9.8) were discovered in MSI Radix AXE6600 router firmware version v781521 across multiple interfaces, alongside a critical flaw (CVE-2026-19348, CVSS 9.8) in Shenzhen Aitemi M300 Wi-Fi Repeater firmware. Organizations using these consumer-grade devices in enterprise or critical environments should prioritize assessment and patching efforts given the high severity and widespread impact potential of these command injection vulnerabilities.
11 critical1 highacross the day’s notable advisories and CVEs
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalCVE-2026-19348CVSS 9.8A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&func
- criticalCVE-2026-71993CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on t
- criticalCVE-2026-71992CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on
- criticalCVE-2026-71991CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to
- criticalCVE-2026-71990CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to ex
- criticalCVE-2026-71989CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands o
- criticalCVE-2026-71988CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on th
- criticalCVE-2026-71987CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the a
- criticalCVE-2026-71986CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the a
- criticalCVE-2026-71985CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary command
- criticalCVE-2026-71984CVSS 9.8MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on
- highCVE-2026-19346CVSS 8.8A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument N
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 2 above.