Router CVE Weekly Digest — Sep 7–13, 2026

Published September 14, 2026 · Covering Sep 7–13, 2026 · RouterCVE Weekly Digest

35 CVEs 3 Critical3 High6 Medium3 Low

Affected Vendors This Week

  • Fortinet – 10 CVEs (2 critical, 2 high, 4 medium, 2 other)
  • ASUS – 11 CVEs (all low/none severity)
  • Palo Alto Networks – 9 CVEs (all low/none severity)
  • Linksys – 1 CVE (critical)
  • NETGEAR – 2 CVEs (1 medium, 1 low)
  • Cisco – 1 CVE (high)
  • Semtech/Sierra Wireless – 1 CVE (medium)

Critical Vulnerabilities

This week brought three critical vulnerabilities demanding immediate attention. CVE-2026-86299 affects Linksys RE7000 range extenders (version 2.0.15) and exposes a dangerous flaw in the PingTest handler at /cgi-bin/json.cgi?PingTest. This improper access control issue carries a CVSS score of 9.9 and could allow unauthenticated remote attackers to execute arbitrary commands. If you manage Linksys RE7000 devices, check for firmware updates immediately.

Fortinet users face two critical issues. CVE-2026-26084 (CVSS 9.9) affects FortiSandbox versions 4.4.0–4.4.8 and 5.0.0–5.0.5, plus FortiSandbox Cloud and PaaS variants, via improper access control. This is a sandbox escape risk that could compromise your security analytics infrastructure. CVE-2026-84390 (CVSS 9.8) targets FortiMonitorOnSight 7.2.0–7.2.7, exposing sensitive information embedded in source code—potentially leaking credentials or API keys to attackers. Both require urgent patching; check Fortinet's latest advisories for version-specific updates.

High-Severity Threats

Three high-severity CVEs round out the critical tier. CVE-2026-84393 (CVSS 8.1) affects FortiOS 7.6.1–7.6.6 and FortiProxy 7.6.2–7.6.6, introducing certificate validation bypasses that could enable man-in-the-middle attacks. CVE-2026-84387 (CVSS 7.2) is a command injection flaw in FortiSandbox 4.4.0–4.4.8 and 5.0.0–5.0.6. Meanwhile, CVE-2026-20293 (CVSS 7.1) affects Cisco UCS Servers and UCS-based appliances via UEFI Shell, allowing authenticated attackers with valid credentials to escalate privileges—relevant for organizations running Cisco-based security appliances.

Medium-Severity Issues & NETGEAR CSRF Risk

CVE-2026-9215 (CVSS 6.7) is a cross-site request forgery (CSRF) vulnerability in multiple NETGEAR router models. An attacker using social engineering can trick an administrator into visiting a malicious site that tampers with router configuration. While this requires user interaction, it's dangerous in managed environments. Network administrators should educate users about phishing risks and consider restricting admin access to trusted networks only.

Fortinet's medium-severity issues include CVE-2026-84391 (uninitialized variable DoS in FortiAnalyzer 7.6.3–7.6.6) and CVE-2026-84385 (access control bypass in FortiSOAR PaaS). Additionally, CVE-2026-15461 (CVSS 5.3) affects Sierra Wireless HL78xx modems' GNSS driver with a struct embedding issue—relevant for organizations using embedded cellular routers.

ASUS & Palo Alto Low-Severity Bulk

ASUS reported 11 CVEs this week, primarily targeting Armoury Crate driver security—mostly local privilege escalation and information disclosure issues with CVSS scores under 6.0. While these affect desktops and laptops rather than routers directly, they're worth tracking if your organization manages ASUS-based endpoints. Palo Alto Networks' 9 CVEs are similarly low-severity, affecting various products (PAN-OS, GlobalProtect, Prisma Access) but not routers specifically.

Actionable Next Steps

  • Linksys users: Prioritize firmware updates for RE7000 devices immediately.
  • Fortinet customers: Review and apply patches for FortiSandbox, FortiMonitorOnSight, FortiOS, and FortiProxy versions listed above.
  • Cisco UCS operators: Check UEFI Shell access logs and restrict UEFI access to trusted administrators.
  • NETGEAR admins: Educate users on phishing and consider restricting router admin panels to internal networks only.
  • All organizations: Review your router inventory against this list and prioritize updates by CVSS score and your network's exposure.