CVE-2026-16876Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-08-21); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-08-21: 1Mentions · 2026-08-22: 1Mentions · 2026-08-26: 1Mentions · 2026-09-07: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-09-07: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-22: 1Technical Details · 2026-08-26: 1Technical Details · 2026-09-07: 108-2108-2208-2609-07
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-211
Disclosure1
2026-08-221
Disclosure1
2026-08-261
Patch1
2026-09-071
Patch1
Full discourse4 posts
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    "脆弱性は、重要な機能に対する認証の欠如(CVE-2026-16876)。攻撃者によって対象製品のWebGUIに細工したメッセージを送信された場合、認証なしで任意のコマンドを実行される可能性がある。CVSS v4.0のスコアは9.3、CVSS v3.0のスコアは9.4。"

    Post summary

    CVE-2026-16876 is an authentication bypass in a WebGUI that permits unauthenticated, arbitrary command execution, with a CVSS score of 9.3 (v4.0) and 9.4 (v3.0).

    040701.2K
    4.6K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    NECのルーター「UNIVERGE IX-R/IX-V」シリーズに深刻な脆弱性、対策済みソフトウェアに更新を - INTERNET Watch https://internet.watch.impress.co.jp/docs/news/2134644.html "CVE-2026-16876…攻撃者によって対象製品のWebGUIに細工したメッセージを送信された場合、認証なしで任意のコマンドを実行される可能性がある"

    Post summary

    NEC's Univerge IX-R/IX-V router series is affected by CVE‑2026‑16876, a critical vulnerability allowing unauthenticated arbitrary command execution via a crafted WebGUI message. Patched firmware is now available.

    13142808
    3.5K followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX
    Patch

    🚨 [CRITICAL VULNERABILITY / NETWORK EDGE] — A NEWLY PUBLISHED CVE LETS UNAUTHENTICATED ATTACKERS BYPASS THE WEBGUI AND EXECUTE ARBITRARY CLI COMMANDS ON NEC UNIVERGE ROUTERS No credentials. No user interaction. Network-accessible attack path. CyberSignal Priority: 🔴 VERY HIGH CVE-2026-16876 CVSS v4.0: 9.3 CRITICAL CWE-306: Missing Authentication for Critical Function Product: NEC UNIVERGE IX-R / IX-V The CVE record for a critical authentication-bypass vulnerability affecting NEC's UNIVERGE IX-R/IX-V network devices was publicly published on September 7. An attacker can tamper with messages sent to the WebGUI, bypass authentication and execute arbitrary CLI commands on the device. ### 🔎 What happened The vulnerability exists inside the WebGUI authentication path. According to NEC, a remote attacker can: craft or modify WebGUI messages ↓ send them to the vulnerable device ↓ bypass authentication ↓ reach CLI-command execution The CVSS characteristics are significant: Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Attack Requirements: NONE Confidentiality impact: HIGH. Integrity impact: HIGH. ### ⚔️ Attack chain Internet/network access to WebGUI ↓ Crafted WebGUI messages ↓ Authentication bypass ↓ Arbitrary CLI command execution ↓ Device configuration manipulation ↓ Potential control of network-edge behavior ### 🎯 What is affected NEC lists the following vulnerable UNIVERGE IX-R/IX-V releases: Ver1.1 → Ver1.3 Ver1.4.21 → Ver1.4.28 Ver1.5.23 These are network infrastructure devices, meaning successful exploitation could give an attacker command-level influence over infrastructure sitting directly in the traffic path. ### 🧠 Why this matters A vulnerability in a normal application can expose one application. A vulnerability in a router or network gateway can expose the layer THROUGH WHICH OTHER SYSTEMS COMMUNICATE. Arbitrary CLI execution could potentially allow malicious configuration changes affecting: routing network access interfaces management settings traffic handling security controls. That makes authentication bypass on network infrastructure materially more dangerous than its WebGUI label may initially suggest. ### ⚠️ Important caveat There is an important date distinction. The NEC security advisory was originally issued on: AUGUST 21, 2026. What is new today, SEPTEMBER 7, is the formal public CVE publication. Also: CISA KEV: NO EPSS: Not yet available There is currently no verified evidence in the cited sources that CVE-2026-16876 is being actively exploited in the wild. So this should NOT be labelled: “ACTIVE EXPLOITATION.” ### 🛡️ Defender action NEC recommends: UPDATE TO THE LATEST VERSION. If upgrading cannot be performed immediately: DISABLE THE WEBGUI. NEC provides the following command: no http-server ip enable Organizations should additionally: restrict management interfaces from the public internet allow administration only from trusted management networks review configuration changes inspect authentication and administrative logs verify no unexpected CLI-level changes have occurred. CyberSignal Insight: WHEN THE MANAGEMENT UI CAN REACH THE CLI WITHOUT AUTHENTICATION — THE WEB INTERFACE IS EFFECTIVELY A PATH TO THE NETWORK CONTROL PLANE. Sources: NEC PSIRT · http://CVE.org · NVD

    Post summary

    CVE-2026-16876 is a critical authentication‑bypass vulnerability on NEC Univerge routers that allows arbitrary CLI commands; no evidence of active exploitation is reported, and NEC advises updating or disabling the WebGUI to mitigate the risk.

    12040190
    234 followersView on X
  • kotaro@サイバーセキュリティ情報発信@ngsk_ciso
    Patch

    NEC UNIVERGE IX-R/IX-V、WebGUIの認証欠如(CVE-2026-16876) 8/21にJVNとNECが公表。対処版と公式回避策が出ている。 https://jvn.jp/jp/JVN81414813/

    Post summary

    NEC and JVN publicly disclosed an authentication bypass vulnerability (CVE-2026-16876) affecting UNIVERGE IX-R/IX-V WebGUI, and released a patch and official workaround.

    1000066
    27 followersView on X

Explore more