chiprook
← Security
SecurityOctober 8, 2026, 09:40

CVE-2026-75937: unauthenticated root RCE in Digi routers scored 9.4

A critical flaw in the Digi Accelerated Linux (DAL OS) web administration service lets a crafted HTTP POST execute OS commands as root without authentication. Affected firmware spans 21.8.24.139 to 26.7.90.14; fixes ship in 26.2.148.166 LTS, 26.7.90.15 and 26.9.10.28.

CVE-2026-75937: unauthenticated root RCE in Digi routers scored 9.4
#Digi#DALOS
Read next
Security

CVE-2026-95675: Unauthenticated root RCE in D-Link DAP-1360

Security

CVE-2026-84411 in MikroTik RouterOS: unauthenticated HTTP request reaches root

Security

CISA: Monta EV charging platform has four flaws, worst rated CVSS 9.4

Hardware

9.4GW SMR-powered data center campus proposed in Utah