CVE-2026-94050: DIR-X1860Z
- Severity
- 5.3 (MEDIUM)
- Vendor
- D-LINK
- Affected versions
- 1.0.2.220120.165402
- Fixed version
- 1.0.7.260821.161908
- Patch status
- Patched
- Published
- 2026-09-20T21:16:55.380
- Modified
- 2026-09-20T21:16:55.380
Why it matters
Vulnerability requiring standard triage and vendor validation.
Recommended admin actions
- Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
- Treat internet-facing systems as higher priority.
Technical summary
A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_get/routerd.get_rand_key of the component ubus JSON-RPC interface. Such manipulation leads to information disclosure. The attack must be carried out from within the local network. Upgrading to version 1.0.7.260821.161908 is able to address this issue. It is suggested to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.
View the official NVD record for CVE-2026-94050
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-90817 |
REDCap PATCH
Reporter: CONTACT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-88856 |
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-88857 |
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-94003 |
CF-N1-S
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-88854 |
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-94089 |
DIR-868L
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-94097 |
NBR200V2
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-94107 |
nivocart
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-86553 |
Product identification pending
Reporter: PSIRT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-94104 |
Product identification pending
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-94106 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-94109 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-88855 |
OrdaSoft Joomla Gallery free extension for Joomla
Reporter: SECURITY
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94095 |
NBR200V2
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94096 |
NBR200V2
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94099 |
NBR200V2
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94100 |
NBR200V2
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-94101 |
NBR200V2
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-87067 |
Forminator Forms PATCH
Reporter: CONTACT
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-94098 |
NBR200V2
Reporter: CNA
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-94128 |
VIVID LED DJ
Reporter: CNA
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-94129 |
VALKYRIE AURORA
Reporter: CNA
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-94108 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-82842 |
SAML Single Sign On PATCH
Reporter: CONTACT
|
8.1
HIGH
|
VIEW RECORD |
| CVE-2026-94112 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-85017 |
Unlimited Elements For Elementor PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-87839 |
Tripzzy PATCH
Reporter: CONTACT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-94036 |
DIR-X1860
Reporter: CNA
|
7.4
HIGH
|
VIEW RECORD |
| CVE-2026-81650 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-92540 |
Import and export users and customers PATCH
Reporter: CONTACT
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-92541 |
Import and export users and customers PATCH
Reporter: CONTACT
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-94113 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-93961 |
UJCMS
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93969 |
SxDevOps
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93970 |
SxDevOps
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93971 |
SxDevOps
Reporter: CNA
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-94105 |
Product identification pending
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-94111 |
Product identification pending
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-92254 |
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-14844 |
Master Slider
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-84223 |
Kirki PATCH
Reporter: CONTACT
|
6.8
MEDIUM
|
VIEW RECORD |
| CVE-2026-94185 |
Product identification pending PATCH
Reporter: 7FFCEE3D-2C14-4C3E-B844-86C6A321A158
|
6.7
MEDIUM
|
VIEW RECORD |
| CVE-2026-87068 |
Forminator Forms PATCH
Reporter: CONTACT
|
6.6
MEDIUM
|
VIEW RECORD |
| CVE-2026-92422 |
Meow Gallery PATCH
Reporter: CONTACT
|
6.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-86555 |
Product identification pending
Reporter: PSIRT
|
6.2
MEDIUM
|
VIEW RECORD |
| CVE-2026-92252 |
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-93962 |
Kamailio PATCH
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93964 |
nginx-proxy-manager
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93972 |
Online Reviewer Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93973 |
Online Reviewer Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93974 |
Online Reviewer Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93978 |
Internship Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93979 |
Internship Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93980 |
Internship Management System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-93997 |
Drug Recommendation System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94004 |
DedeCMS
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94015 |
Drug Recommendation System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94038 |
dim-sum-app
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94039 |
TaxHacker
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94040 |
TaxHacker
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94043 |
Free5GC
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94044 |
MCP
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-94110 |
QCMS
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-86552 |
Product identification pending
Reporter: PSIRT
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-87840 |
Tripzzy PATCH
Reporter: CONTACT
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-94050 |
DIR-X1860Z PATCH
Reporter: CNA
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-94090 |
Manalyze
Reporter: CNA
|
5.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-92253 |
Anti-Virus
Reporter: 34EDF4F2-2577-40AB-82CE-39F45972C129
|
5.2
MEDIUM
|
VIEW RECORD |
| CVE-2026-93965 |
SxDevOps
Reporter: CNA
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93966 |
SxDevOps
Reporter: CNA
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93967 |
SxDevOps
Reporter: CNA
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-93968 |
SxDevOps
Reporter: CNA
|
5.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92410 |
Sign-up Sheets PATCH
Reporter: CONTACT
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-86554 |
Product identification pending
Reporter: PSIRT
|
4.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-81653 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
4.2
MEDIUM
|
VIEW RECORD |
| CVE-2026-16542 |
Import and export users and customers PATCH
Reporter: CONTACT
|
4.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-92965 |
TikTok PATCH
Reporter: CONTACT
|
3.7
LOW
|
VIEW RECORD |
| CVE-2026-81651 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
3.1
LOW
|
VIEW RECORD |
| CVE-2026-81654 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
3.1
LOW
|
VIEW RECORD |
| CVE-2026-81652 |
Photo Gallery, Sliders, Proofing and Themes PATCH
Reporter: CONTACT
|
2.7
LOW
|
VIEW RECORD |
| CVE-2026-92423 |
Product identification pending PATCH
Reporter: CONTACT
|
2.7
LOW
|
VIEW RECORD |
| CVE-2026-93960 |
Pixelfed PATCH
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-93963 |
Leave Management System
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94028 |
Product identification pending
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94031 |
Product identification pending
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94032 |
Leave Management System
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94035 |
Drug Recommendation System
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94037 |
mcp-file-analyzer
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94041 |
Restaurant-Management-System
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94042 |
Restaurant Management System
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94046 |
Product identification pending
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94047 |
Product identification pending
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94049 |
Product identification pending
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94051 |
Product identification pending
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94093 |
Product identification pending
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94094 |
Product identification pending
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-94102 |
WuzhiCMS
Reporter: CNA
|
2.1
LOW
|
VIEW RECORD |
| CVE-2026-93977 |
Assessment Management
Reporter: CNA
|
2
LOW
|
VIEW RECORD |
| CVE-2026-94033 |
Product identification pending
Reporter: CNA
|
2
LOW
|
VIEW RECORD |
| CVE-2026-94034 |
Product identification pending
Reporter: CNA
|
2
LOW
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.