Find notable cyber news and cases, enriched with sources, timelines, and signals.

OpenWrt security patch release for CVE-2026-53921

Security Patch Release
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The update also bundles fixes for other remotely triggerable flaws in uhttpd, cgi-io, and LuCI. The critical bug is tracked as CVE-2026-53921 and can be reached by an unauthenticated attacker sending a crafted DHCPv6 REQUEST. Administrators on the 24.10 and 25.12 branches should move to the listed patched releases.

Related Happenings

Django Software Foundation security patch release for CVE-2026-15307

Security Patch Release
H score39 First: 05.08.2026 17:27 Last: 05.08.2026 17:27 Sources 1

About this happening: Django Software Foundation shipped Django 6.0.8 and 5.2.17 on August 4 to fix four CVEs, including CVE-2026-15307 in GeoDjango. The release closes a pa...

TeamCity security patch release for CVE-2026-63077

Security Patch Release
H score53 First: 28.07.2026 11:11 Last: 28.07.2026 11:11 Sources 1

About this happening: JetBrains released TeamCity On-Premises fixes for CVE-2026-63077, a critical unauthenticated remote code execution issue, through 2025.11.7, 2026.1.3, and...

Linux kernel upstream security patch release for CVE-2026-53264

Security Patch Release
H score32 First: 28.07.2026 11:04 Last: 28.07.2026 11:04 Sources 1

About this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...

VBulletin 6.2.2 security patch release for template-engine flaw

Security Patch Release
H score32 First: 27.07.2026 17:40 Last: 27.07.2026 17:40 Sources 1

About this happening: vBulletin released security patches for 6.2.1, 6.2.0, and 6.1.6 and shipped 6.2.2 as the fixed build, closing a template-engine remote code execution flaw on s...

Ubuntu snap-confine patch release (CVE-2026-8933)

Security Patch Release
H score34 First: 22.07.2026 13:50 Last: 22.07.2026 13:50 Sources 1

About this happening: Canonical released snapd updates through the Ubuntu Security Team to fix CVE-2026-8933, a local privilege escalation in snap-confine that can let an unpriv...

Timeline

  1. 28.07.2026 15:56 2 articles · 10d ago

    OpenWrt ships 24.10.8 to close CVE-2026-53921

    Mitigation Patch Update

    OpenWrt shipped version 24.10.8 to close CVE-2026-53921, a critical DHCPv6 stack overflow in odhcpd that an unauthenticated attacker could trigger with a crafted DHCPv6 REQUEST, while also addressing additional default-service flaws in uhttpd, cgi-io and LuCI.

    Show sources