π΅οΈ RESEARCH & DEEP DIVES
- Command Injection Flaw in TP-Link Archer AXE75 OpenVPN Module
CVE-2026-9044
TP-Link Archer AXE75 V1 routers have an OS command injection vulnerability in their OpenVPN module.- Applies to TP-Link Archer AXE75 V1 routers with OpenVPN VPN module
- Vulnerability allows adjacent, authenticated attackers to execute arbitrary OS commands
- Exploited by importing a specially crafted VPN client configuration file
- Improper filtering of special characters leads to command injection
- Affected versions are all before firmware 1.5.6 Build 20260623
π Coverage: cve.threatint.com Β· π Original: cve.threatint.com Β· π via CVE ThreatInt
π CVEs & KEV
- CVE-2026-34641 β CVSS 7.8 β Premiere Pro | Out-of-bounds Write (CWE-787)Premiere Pro is affected by an ou...
- CVE-2026-45377 β CVSS 6.5 β Decidim: Private exports can be downloaded through reusable linksDecidim is a...
- CVE-2026-54785 β CVSS 6.2 β gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with...
- CVE-2026-45376 β CVSS 5.5 β Decidim: Admin user search allows SQL injection through similarity-based sort...
- CVE-2026-54909 β CVSS 5.3 β Pion STUN vulnerable to remote denial of service via panic while parsing a ma...
- CVE-2026-45330 β CVSS 4.9 β Decidim: Veriο¬cation admins can access supplied IDs from other organisationsD...
- CVE-2026-54787 β CVSS 3.1 β sigstore-go fails to check signature timestamps against a signing key's valid...
- CVE-2026-54768 β CVSS β β WPGraphQL has deprecated
userfield on SendPasswordResetEmailPayload that l... - CVE-2026-53573 β CVSS β β core-geonetwork has an Open Redirect BypassGeoNetwork is a catalog applicatio...