Affected Vendors This Week
- Cisco: 11 CVEs (3 critical, 5 high)
- SonicWall: 3 CVEs (3 critical)
- TP-Link: 2 CVEs
- ASUS: 2 CVEs
- OpenWrt / DD-WRT: 1 CVE
- Netgear: 1 CVE
Critical Vulnerabilities Requiring Immediate Action
This week brings a significant security update dominated by Cisco and SonicWall critical vulnerabilities. Cisco IOS XR Software accounts for the bulk of high-severity issues, with three critical vulnerabilities at CVSS 9.8: CVE-2026-20279, CVE-2026-20274, and CVE-2026-20212. The latter affects Cisco Nexus 9000 Series Switches with Silicon One integration, allowing unauthenticated remote code execution with root privileges—a particularly dangerous attack vector in data center environments.
Cisco IOS XR also has five additional high-severity issues (CVE-2026-20278, CVE-2026-20280, CVE-2026-20275, CVE-2026-20276, CVE-2026-20277) ranging from CVSS 8.2 to 8.8. Customers running these platforms should prioritize firmware updates immediately.
SonicWall NSM On-Prem Critical Flaws
SonicWall Network Security Manager (NSM) On-Prem deployments face three critical vulnerabilities, all CVSS 9.1. CVE-2026-81939 is a Zip Slip vulnerability in file upload and archive processing that could allow attackers to extract files outside intended directories. CVE-2026-78327 exposes an OS Command Injection flaw in the management interface, while CVE-2026-78328 allows privilege escalation from Admin to SuperAdmin. Organizations with on-premises NSM installations should apply patches and review access controls immediately.
Consumer and SMB Router Issues
TP-Link Archer AX55 v4 users should be aware of two vulnerabilities: CVE-2026-18167 (stack-based buffer overflow in EasyMesh when Mesh mode is enabled) and CVE-2026-18330 (hard-coded cryptographic key). ASUS Control Center has a critical issue (CVE-2026-75754) combining missing authentication, SSRF, and hard-coded credentials.
Action items: Check Cisco and SonicWall patch portals for firmware updates this week. Verify your router inventory for affected models and prioritize testing in lab environments before production deployment.