CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-71920

mediumCVSS 4.9covered by 2 sourcesfirst seen 2026-08-24
A remote, authenticated attacker can exploit multiple vulnerabilities in DrayTek Vigor Switches to execute arbitrary code.

CSIRTS triage

What
Multiple vulnerabilities enable remote authenticated attackers to execute arbitrary code.
Who is affected
DrayTek Vigor Switch deployments with remote management or API access enabled.
Urgency
Medium severity requiring authentication; patch promptly to prevent code execution on network infrastructure.
Action
Update DrayTek Vigor Switches to firmware versions addressing CVE-2026-71915 through CVE-2026-71922.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-71920

Get an email if CVE-2026-71920 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-71920

CVE.org record

Embed the live status

CVE-2026-71920 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71920 status](https://www.csirts.com/badge/CVE-2026-71920)](https://www.csirts.com/cve/CVE-2026-71920)