Security News

Cybersecurity news aggregator

CRITICAL Updates SC Media

OpenWrt releases security updates for critical DHCPv6 flaw and other vulnerabilities

OpenWrt has patched a critical DHCPv6 stack buffer overflow (CVE-2026-53921, CVSS 9.8) in its odhcpd service, allowing unauthenticated remote code execution via a crafted DHCPv6 REQUEST packet. The security update also addresses other pre-authentication flaws in odhcpd and uhttpd, as well as multiple vulnerabilities in optional LuCI components. The critical fixes are included in OpenWrt versions 24.10.8 and 25.12.5, to which users should upgrade.
Read Full Article →

Vulnerability Management , Patch/Configuration Management , Threat Intelligence OpenWrt releases security updates for critical DHCPv6 flaw and other vulnerabilities July 29, 2026 Share By SC Staff (Adobe Stock) As noted by The Hacker News, OpenWrt released version 24.10.8 to address a critical DHCPv6 stack overflow vulnerability (CVE-2026-53921) and a range of other remotely triggerable flaws in its network services. The critical DHCPv6 vulnerability, rated 9.8 on CVSS 3.1, allows an unauthenticated attacker to overwrite a stack buffer in the odhcpd service by sending a crafted DHCPv6 REQUEST. This could lead to code execution on devices lacking security features like stack canaries and ASLR. The update also fixes other pre-authentication weaknesses in odhcpd, including an out-of-bounds write and memory disclosure, as well as HTTP request smuggling bugs in uhttpd and a DHCPv6 hostname injection flaw leading to stored XSS. Separately, an AI-assisted audit by Hacker House identified command-injection, path-traversal, and cross-site scripting (XSS) weaknesses in optional LuCI components, along with a stored XSS issue and missing CSRF protection. While the critical DHCPv6 fix is included in OpenWrt 24.10.8 and 25.12.5, the LuCI-related patches were still under review as of July 28. No exploitation in the wild had been reported for these vulnerabilities at the time of the advisory. OpenWrt recommends users update to the latest versions and consider migrating to the 25.12 series. Source: The Hacker News SC Staff Related Vulnerability Management JetBrains patches critical TeamCity flaw enabling unauthenticated code execution SC Staff July 29, 2026 JetBrains released security updates for TeamCity On-Premises to address a critical vulnerability, CVE-2026-63077, which carries a CVSS score of 9.8. Threat Intelligence vBulletin forum software vulnerable to remote code execution SC Staff July 29, 2026 A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering, posing a significant risk to online communities and discussion boards. Vulnerability Management Proof-of-concept exploit released for Certighost Windows AD CS vulnerability SC Staff July 28, 2026 Reported by Bleeping Computer. A proof-of-concept exploit was released for a vulnerability in Windows Active Directory Certificate Services (AD CS) known as Certighost, potentially allowing authenticated attackers to compromise an entire Windows domain. Related Events Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Backdoor Brute Force DNS Spoofing Deauthentication Attack Deepfake Defacement Denial of Service Dictionary Attack Disruption DumpSec You can skip this ad in 5 seconds

Share this article