Find notable cyber news and cases, enriched with sources, timelines, and signals.

DIR-822A L2TP control message parser out-of-bounds write memory corruption flaw (CVE-2026-86510)

Vulnerability
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

D-Link is investigating CVE-2026-86510, a critical out-of-bounds write in the L2TP control message parser of DIR-822A routers that can let attackers with basic privileges trigger arbitrary memory corruption on devices using L2TP or L2TPv6 WAN connectivity. A public PoC exploit raises the risk of faster weaponization against exposed routers. D-Link says it is still investigating the flaw and working on security patches.

Related Happenings

D-Link DIR-822A DHCP stack-based buffer overflow remote code execution flaw (CVE-2026-86296)

Vulnerability
H score31 First: 22.09.2026 15:48 Last: 22.09.2026 15:48 Sources 1

How related: D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.

About this happening: The D-Link DIR-822A vulnerability CVE-2026-86296 exposes legacy dual-band routers to unauthenticated attacks that can crash the DHCP daemon or enable remote code...

CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM

Public Sector Action
H score46 First: 26.06.2026 15:31 Last: 26.06.2026 15:31 Sources 1

About this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...

CISA adds CVE-2026-20262 to KEV and orders federal fixes

Public Sector Action
H score32 First: 16.06.2026 09:05 Last: 16.06.2026 09:05 Sources 1

About this happening: CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixe...

Timeline

  1. 22.09.2026 15:48 2 articles · 0h ago

    D-Link warns of CVE-2026-86510 in DIR-822A routers

    Initial Disclosure

    D-Link warned that CVE-2026-86510 is a critical out-of-bounds write in the L2TP control message parser on DIR-822A dual-band Wi-Fi routers. The flaw can be triggered by manipulating input data on devices configured for L2TP or L2TPv6 WAN connectivity, and D-Link said public proof-of-concept exploit code is available. The company is still investigating the issue and advised customers to keep DIR-822A routers off the internet, restrict remote management access, and limit administrative access through firewall or network-access controls.

    Show sources