CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-18753

criticalCVSS 9.1covered by 1 sourcefirst seen 2026-08-04
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.

⚡ Watch CVE-2026-18753

Get an email if CVE-2026-18753 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-18753

CVE.org record

Embed the live status

CVE-2026-18753 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-18753 status](https://www.csirts.com/badge/CVE-2026-18753)](https://www.csirts.com/cve/CVE-2026-18753)