:

D-LINK WARNS OF CRITICAL ZERO-DAY IN DIR-822A ROUTERS

SECURITY DESK1 MIN READ
TUE, SEP 22, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

D-Link has alerted users of a maximum-severity zero-day vulnerability (CVE-2026-86296) affecting DIR-822A dual-band Wi-Fi routers. The flaw has no available patch and public exploit code is already circulating.

The vulnerability poses immediate risk to users of the legacy DIR-822A router model. With proof-of-concept exploit code publicly available and no security patch released, the threat level is elevated. D-Link has not disclosed specific technical details about the flaw's nature or attack vector. The company has not provided a timeline for when a fix will be available. Users of DIR-822A routers should monitor D-Link's security advisories for patch availability. As a temporary mitigation, restricting network access and disabling unnecessary features may reduce exposure. D-Link has not announced whether other router models are affected by this vulnerability. The DIR-822A is an older device, and the presence of public exploits suggests threat actors may begin targeting installations soon.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Researchers have identified stolen credentials as a critical vulnerability threatening America's water infrastructure. The exposed passwords create direct pathways for attackers to access essential systems.

JUST NOWSecurity Desk

Microsoft's Digital Crimes Unit has shut down EvilTokens, a phishing-as-a-service platform that compromised over 12,000 Microsoft accounts across 10,000+ organizations.

JUST NOWIndustry Desk

A webinar tomorrow examines critical early response decisions in Google Workspace breaches. Real-world incident analysis shows which actions limit damage and which escalate the impact.

1H AGOSecurity Desk

A cross-site request forgery (CSRF) vulnerability in WordPress Core, dubbed 'Click2Shell,' enables attackers to execute PHP code on vulnerable servers. Technical details and working exploits are now public.

11H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.