DIR-822A L2TP control message parser out-of-bounds write memory corruption flaw (CVE-2026-86510)
Vulnerability
Summary
Hide ▲
Show ▼
D-Link is investigating CVE-2026-86510, a critical out-of-bounds write in the L2TP control message parser of DIR-822A routers that can let attackers with basic privileges trigger arbitrary memory corruption on devices using L2TP or L2TPv6 WAN connectivity. A public PoC exploit raises the risk of faster weaponization against exposed routers. D-Link says it is still investigating the flaw and working on security patches.
Related Happenings
D-Link DIR-822A DHCP stack-based buffer overflow remote code execution flaw (CVE-2026-86296)
Vulnerability
H score31
First: 22.09.2026 15:48
Last: 22.09.2026 15:48
Sources 1
How related:
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
About this happening:
The D-Link DIR-822A vulnerability CVE-2026-86296 exposes legacy dual-band routers to unauthenticated attacks that can crash the DHCP daemon or enable remote code...
D-Link DIR-822A DHCP stack-based buffer overflow remote code execution flaw (CVE-2026-86296)
VulnerabilityHow related: D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
About this happening: The D-Link DIR-822A vulnerability CVE-2026-86296 exposes legacy dual-band routers to unauthenticated attacks that can crash the DHCP daemon or enable remote code...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector Action
H score46
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
About this happening:
CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector ActionAbout this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA adds CVE-2026-20262 to KEV and orders federal fixes
Public Sector Action
H score32
First: 16.06.2026 09:05
Last: 16.06.2026 09:05
Sources 1
About this happening:
CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixe...
CISA adds CVE-2026-20262 to KEV and orders federal fixes
Public Sector ActionAbout this happening: CISA added CVE-2026-20262 to its Known Exploited Vulnerabilities (KEV) catalog and required Federal Civilian Executive Branch (FCEB) agencies to apply Cisco's fixe...
Timeline
-
22.09.2026 15:48 2 articles · 0h ago
D-Link warns of CVE-2026-86510 in DIR-822A routers
Initial DisclosureD-Link warned that CVE-2026-86510 is a critical out-of-bounds write in the L2TP control message parser on DIR-822A dual-band Wi-Fi routers. The flaw can be triggered by manipulating input data on devices configured for L2TP or L2TPv6 WAN connectivity, and D-Link said public proof-of-concept exploit code is available. The company is still investigating the issue and advised customers to keep DIR-822A routers off the internet, restrict remote management access, and limit administrative access through firewall or network-access controls.
Show sources
- D-Link warns of max severity zero-day bug in DIR-822A routers — www.bleepingcomputer.com — 22.09.2026 15:48
- D-Link warns of max severity zero-day bug in DIR-822A routers — www.bleepingcomputer.com — 22.09.2026 15:48