OpenWrt security patch release for CVE-2026-53921
Security Patch Release
Summary
Hide ▲
Show ▼
OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The update also bundles fixes for other remotely triggerable flaws in uhttpd, cgi-io, and LuCI. The critical bug is tracked as CVE-2026-53921 and can be reached by an unauthenticated attacker sending a crafted DHCPv6 REQUEST. Administrators on the 24.10 and 25.12 branches should move to the listed patched releases.
Related Happenings
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch Release
H score32
First: 28.07.2026 11:04
Last: 28.07.2026 11:04
Sources 1
About this happening:
Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch ReleaseAbout this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch Release
H score32
First: 27.07.2026 17:40
Last: 27.07.2026 17:40
Sources 1
About this happening:
vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
VBulletin 6.2.2 security patch release for template-engine flaw
Security Patch ReleaseAbout this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...
Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch Release
H score34
First: 22.07.2026 13:50
Last: 22.07.2026 13:50
Sources 1
About this happening:
Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...
Ubuntu snap-confine patch release (CVE-2026-8933)
Security Patch ReleaseAbout this happening: Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...
SimpleHelp security update for CVE-2026-48558
Security Patch Release
H score65
First: 15.06.2026 23:06
Last: 15.06.2026 23:06
Sources 1
About this happening:
SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...
SimpleHelp security update for CVE-2026-48558
Security Patch ReleaseAbout this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch Release
H score42
First: 15.06.2026 19:39
Last: 15.06.2026 19:39
Sources 1
About this happening:
BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
Timeline
-
28.07.2026 15:56 1 articles · 2h ago
Hauke Mehrtens publishes LuCI pull request #8878
Technical Analysis UpdateOpenWrt maintainer Hauke Mehrtens published LuCI pull request #8878 and credited Matthew Hickey and Hacker House for the findings tied to the LuCI codebase.
Show sources
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root — thehackernews.com — 28.07.2026 15:56
-
28.07.2026 15:56 2 articles · 2h ago
OpenWrt ships 24.10.8 to close CVE-2026-53921
Mitigation Patch UpdateOpenWrt shipped version 24.10.8 to close CVE-2026-53921, a critical DHCPv6 stack overflow in odhcpd that an unauthenticated attacker could trigger with a crafted DHCPv6 REQUEST, while also addressing additional default-service flaws in uhttpd, cgi-io and LuCI.
Show sources
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root — thehackernews.com — 28.07.2026 15:56
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root — thehackernews.com — 28.07.2026 15:56