NVD disclosure day

Published threat advisories for August 8, 2026

CVE advisoryCRITICAL

CVE-2026-71983

MSI Radix AXE6600 Command Injection via WPS Interface

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in MSI Radix AXE6600 router firmware, allowing remote attackers to execute arbitrary commands and gain root privileges. This is a concern because routers are often internet-facing and this vulnerability could lead to full device compromise. Confirmation of affected devices and t

CVE advisoryCRITICAL

CVE-2026-71958

D-Link DWR-M961 Command Execution via Buffer Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A buffer overflow vulnerability in the quicksetup.cgi interface of D-Link DWR-M961 devices could permit a remote attacker to execute arbitrary commands or crash the device. This is a concern for network-accessible devices that might be exposed to the internet.

CVE advisoryCRITICAL

CVE-2026-71957

D-Link DWR-M961 Command Execution via Buffer Overflow

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

D-Link DWR-M961 devices are affected by a buffer overflow vulnerability in the `app.cgi` interface. A remote attacker could exploit this by sending a crafted, overly long string to a specific field, potentially leading to arbitrary command execution or a device crash. This is a concern because these devices are network

CVE advisoryCRITICAL

CVE-2026-71956

D-Link DWR-M961 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in D-Link DWR-M961 devices via the app.cgi interface, allowing remote attackers to execute arbitrary commands with root privileges. Because these are network edge devices, this vulnerability is very likely to be reachable from the internet. This issue impacts the device's config

CVE advisoryCRITICAL

CVE-2026-71953

D-Link DWR-M961 Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

D-Link LTE routers are affected by a command injection vulnerability in their web management interface. This flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges if the interface is reachable. This could compromise router configuration and operational integrity, necessitating

CVE advisoryCRITICAL

CVE-2026-71952

D-Link DWR-M961 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

D-Link routers contain a command injection vulnerability in a specific interface that allows remote attackers to execute arbitrary commands with root privileges. This could affect the device's functionality and security if the interface is reachable. The relevance and exposure of affected devices need to be confirmed t

CVE advisoryCRITICAL

CVE-2026-71950

D-Link DWR-M961 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in D-Link routers that could allow remote attackers to execute arbitrary commands with root privileges. This impacts devices managing internet access and data, making it crucial to confirm if your organization uses these routers and assess potential exposure to maintain network

CVE advisoryCRITICAL

CVE-2026-71949

D-Link Router Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

D-Link DWR-M961 routers have a command injection vulnerability in the /boafrm/formUSSDSetup interface. Remote attackers can inject commands to execute with root privileges, potentially compromising the device and network. This is a concern because routers are often internet-facing and this vulnerability requires no aut

CVE advisoryCRITICAL

CVE-2026-71948

D-Link DWR-M961 Command Injection Vulnerability Allows Root Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability in D-Link DWR-M961 devices allows unauthenticated remote attackers to execute arbitrary commands with root privileges through a diagnostic interface. This could lead to unauthorized control over the affected devices, potentially impacting network traffic or enabling further malicious a

CVE advisoryCRITICAL

CVE-2026-71947

D-Link DWR-M961 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability in D-Link routers allows remote attackers to execute arbitrary commands with root privileges through a diagnostic interface. If reachable, this could impact device integrity and data processing. Verifying the presence and exposure of affected devices is crucial.A command injection vuln

CVE advisoryCRITICAL

CVE-2026-71946

D-Link DWR-M961 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

D-Link routers contain a command injection vulnerability in a diagnostic interface that allows unauthenticated remote attackers to execute arbitrary commands with root privileges. This could impact device availability and potentially lead to further network compromise if the interface is reachable.

CVE advisoryCRITICAL

CVE-2026-71945

D-Link DWR-M961 Command Injection Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in the upgrade interface of certain D-Link routers, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges by manipulating a specific URL field. This could lead to full device compromise, making it crucial to confirm if internet-facing route

CVE advisoryCRITICAL

CVE-2026-71944

D-Link DWR-M961 Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability exists in D-Link DWR-M961 devices, allowing remote attackers to execute arbitrary commands with root privileges via the `/boafrm/formLtefotaUpgradeQuectel` interface. This issue could lead to unauthorized system control if the devices are reachable from the network.

CVE advisoryCRITICAL

CVE-2026-14526

AI Copilot WordPress Plugin Authorization Bypass Allows Site Takeover.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The AI Copilot – Content Generator plugin for WordPress has an authorization bypass vulnerability that allows unauthenticated attackers to create new administrator accounts, potentially leading to full site takeover. This issue arises because the plugin does not properly verify user authorization for certain actions. T