NVD disclosure day

Published threat advisories for August 9, 2026

CVE advisoryCRITICAL

CVE-2026-71992

MSI Radix AXE6600 Command Injection via macfilter

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

An MSI Radix AXE6600 router firmware vulnerability allows remote attackers to execute arbitrary commands and gain root privileges by exploiting the macfilter function. This command injection flaw could lead to a complete system compromise if the affected device is accessible.

CVE advisoryCRITICAL

CVE-2026-71991

MSI Radix AXE6600 Command Injection via Telnet Configuration

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability in MSI Radix AXE6600 router firmware allows remote attackers to execute arbitrary commands and gain root privileges. If the Telnet configuration interface is reachable, attackers can compromise the device, impacting network security and control.

CVE advisoryCRITICAL

CVE-2026-71990

MSI Radix AXE6600 Command Injection via TelnetSSH Function

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability in the MSI Radix AXE6600 router's TelnetSSH function allows remote attackers to execute arbitrary commands and gain root privileges. This issue could potentially compromise the affected devices if their management interfaces are accessible, impacting network device security and managem

CVE advisoryCRITICAL

CVE-2026-71989

MSI Radix AXE6600 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in MSI Radix AXE6600 router firmware that allows remote attackers to execute arbitrary commands. If reachable, this could enable attackers to obtain root privileges on the affected device. This issue is relevant due to the router's role as an internet edge device.

CVE advisoryCRITICAL

CVE-2026-71988

MSI Radix AXE6600 Router Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

MSI Radix AXE6600 router firmware contains a command injection vulnerability. Remote attackers can exploit this flaw to execute arbitrary commands and potentially gain root privileges on the device without authentication or user interaction. This poses a risk to device integrity and security.

CVE advisoryCRITICAL

CVE-2026-71987

MSI Radix AXE6600 Router Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in MSI Radix AXE6600 router firmware, allowing remote attackers to execute arbitrary commands and potentially gain root privileges. This is a concern because the vulnerability is reachable via the network, and successful exploitation could lead to full device control.

CVE advisoryCRITICAL

CVE-2026-71986

MSI Radix AXE6600 Command Injection via DMZ Function

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

MSI Radix AXE6600 router firmware has a critical command injection vulnerability in its DMZ function, allowing unauthenticated remote attackers to execute arbitrary commands and gain root privileges. This issue, reachable via the network, impacts device control and overall network security. Organizations should identif

CVE advisoryCRITICAL

CVE-2026-71984

MSI Radix AXE6600 Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in MSI Radix AXE6600 router firmware. This flaw allows remote attackers to execute arbitrary commands and potentially gain root privileges. As this affects a network edge device, it warrants careful consideration of potential exposure.