SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86510

CRITICAL · CVSS 9.9 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The D-Link DIR-822A A_101 is vulnerable due to an out-of-bounds write in the tunnel_set_params function of the L2TP Control Message Parser, which can be exploited remotely. This critical vulnerability, with a CVSS score of 9.9, could allow attackers to execute arbitrary code, potentially compromising the device and the network it connects to. Organizations using this router should prioritize immediate patching or mitigation measures to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86510
Severity
CRITICAL
CVSS
9.9
EPSS
0.46%

Original NVD Description

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.