Affected Vendors This Week
- GL.iNet: 7 CVEs (3 high, 4 medium)
- Cisco: 4 CVEs (2 high, 2 medium)
- TP-Link: 2 CVEs (1 medium, 1 unrated)
- Zyxel: 2 CVEs (2 medium)
- Teltonika: 1 CVE (unrated)
Critical Vulnerabilities
This week brings 16 new CVEs with a notable concentration in GL.iNet devices and Cisco communications platforms. Two vulnerabilities stand out as particularly concerning.
CVE-2026-20230 (CVSS 8.6) affects Cisco Unified Communications Manager and Unified CM SME, allowing unauthenticated remote attackers to compromise systems. This is the highest-severity flaw of the week and should be prioritized for patching. CVE-2026-20245 (CVSS 7.8) impacts Cisco Catalyst SD-WAN Manager, enabling authenticated local attackers to execute arbitrary commands as root via crafted CLI files.
GL.iNet GL-MT3000 Cluster
GL.iNet accounts for nearly half this week's CVEs, with seven issues identified in the GL-MT3000 router (firmware 4.4.5 and earlier). Three high-severity vulnerabilities require immediate attention:
- CVE-2026-11451 and CVE-2026-11452 involve buffer overflow conditions in the FTP Protocol Handler and SET_USER_PWD Handler respectively (both CVSS 7.3)
- CVE-2026-11450 (CVSS 7.3) exploits unsafe path normalization in the HTTP daemon's RPC interface
Four additional medium-severity flaws include RPC interface issues, MTK backend vulnerabilities, and OpenVPN configuration problems. Check for firmware updates immediately if you operate GL-MT3000 devices in your environment.
Buffer Overflows in UPnP Services
Zyxel VMG4005-B50B users should update firmware beyond version 5.13(ABRL.5.4)C0. CVE-2026-3870 and CVE-2026-3871 (both CVSS 6.5) present buffer overflow risks in UPnP AddPortMapping() and DeletePortMapping() commands, allowing adjacent attackers to trigger denial-of-service conditions.
Additional Medium-Risk Issues
CVE-2026-1871 affects TP-Link Tapo C200 v5 cameras with a stack-based buffer overflow in RTSP authentication. Cisco's CVE-2026-20233 and CVE-2026-20175 involve cross-site scripting and arbitrary file loading vulnerabilities in Webex Meetings and Finesse respectively.
Action items: Prioritize Cisco updates for CVSS 8.6 and 7.8 flaws; patch GL.iNet devices to latest firmware; update Zyxel VMG4005-B50B; verify TP-Link Tapo device firmware versions in your deployments.
```