Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-86296

D-Link DIR-822A Maximum Severity Zero-Day Vulnerability

CVSS 10.0 vulnerability in D-Link DIR-822A legacy routers with public PoC and no patch. Device is end-of-life; D-Link recommends replacement.

cat cve-2026-86296.json
Vendor
D-Link
Product
DIR-822A
CVSS
10.0
EPSS (exploit probability)
1.3%
Status
unpatched
Published

CVE-2026-86296 affects the D-Link DIR-822A dual-band Wi-Fi router. D-Link has disclosed the flaw directly to customers and confirmed that no patch will be issued: the DIR-822A is past end of life.

Severity: CVSS 10.0 (Critical) per NVD.

Exploitation status: Public proof-of-concept exploit code is in circulation as of September 2026. No patch is available or planned. D-Link recommends replacing the device.

Recommended action: Treat this as a hardware replacement priority. If immediate replacement is not possible, do not expose the router directly to the internet. Place it behind a firewall and restrict external access until a replacement is in place.

For full coverage see D-Link Warns CVSS 10.0 DIR-822A Flaw Has No Fix.