D-Link is investigating two critical flaws reported in DIR-822A routers running firmware A_101. CVE-2026-86296 is an unauthenticated, network-reachable stack-based buffer overflow in the udhcpcd component, rated CVSS 10.0, that could enable denial of service or remote code execution. A public proof-of-concept exploit has reportedly been released.
The second issue, CVE-2026-86510, is an out-of-bounds write in the L2TP Control Message Parser, rated 9.9 under CVSS v3.1 and requiring low privileges but no user interaction; public exploit code has also reportedly been released. D-Link has not confirmed the complete affected hardware-revision or regional scope, nor whether remediation is available. Organizations should verify deployed router models and firmware, disable unnecessary remote management, restrict administrative access, and monitor regional D-Link support channels for updates.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Public proof-of-concept exploits were reportedly released for CVE-2026-86296 and CVE-2026-86510. CVE-2026-86296 may enable unauthenticated remote disruption or code execution, while CVE-2026-86510 can trigger memory corruption through crafted L2TP control messages.
D-Link Systems disclosed it is investigating CVE-2026-86296, an unauthenticated network-reachable stack buffer overflow in udhcpcd affecting reported DIR-822A firmware A_101, and CVE-2026-86510, an L2TP control-message parser out-of-bounds write in the same reported firmware. The flaws are scored CVSS 10.0 and 9.9 (v3.1), respectively; D-Link had not confirmed the complete affected hardware, regional scope, or remediation status.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.