PatchDay Alert

CVE

CVE-2026-7248

0field notes · 1digest CVSS 9.8


Daily digests

An attacker can remotely trigger a buffer overflow on D-Link DI-8100 routers (firmware 16.07.26A1) through the tgfile.htm CGI endpoint by sending a crafted 'fn' parameter. No authentication is needed, and a working exploit is already public. CVSS 9.8, so this is about as bad as it gets for a network device.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.