TP-Link has released security updates for two vulnerabilities affecting the Archer AX55 V4 wireless router: CVE-2026-18167 and CVE-2026-18330. Published on September 3, 2026, the advisory recommends updating to firmware 1.2.1 Build 20260527. CVE-2026-18167 is a high-severity stack-based buffer overflow in the EasyMesh component that can be exploited by an unauthenticated attacker on the local network when Mesh mode is enabled, potentially causing the EasyMesh daemon to crash or allowing remote code execution. CVE-2026-18330 is a medium-severity vulnerability involving a hardcoded shared RSA-1024 private key in the web login module. A local network attacker who captures an HTTP login session could potentially decrypt administrator password data. A weakened AES session key further reduces authentication security, potentially exposing router administrator credentials and enabling unauthorized configuration changes. TP-Link has addressed both vulnerabilities in the updated firmware. Users of Archer AX55 V4 are advised to install the latest firmware and secure router administration by disabling unnecessary HTTP-based management, using HTTPS where available, restricting administrative access to trusted devices, and monitoring connected clients for suspicious activity.
A recently released proof-of-concept called FalconFlank claims to expose a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor for Windows. Published on GitHu...
A malicious campaign is abusing rogue ConnectWise ScreenConnect clients to spread malware across Windows systems connected to compromised remote-access environments. According to H...
CERN, the European Organization for Nuclear Research and operator of the Large Hadron Collider, plans to migrate more than 2,200 industrial computers and embedded devices used for ...