Yasuhiro Morishita[verified]@OrangeMorishitaDisclosure
CVE-2026-16876 is an authentication bypass in a WebGUI that permits unauthenticated, arbitrary command execution, with a CVSS score of 9.3 (v4.0) and 9.4 (v3.0).
CyberSignal | Cybersecurity & AI News[verified]@XQOPTRXPatch
CVE-2026-16876 is a critical authentication‑bypass vulnerability on NEC Univerge routers that allows arbitrary CLI commands; no evidence of active exploitation is reported, and NEC advises updating or disabling the WebGUI to mitigate the risk.
kotaro@サイバーセキュリティ情報発信[verified]@ngsk_cisoPatch
NEC and JVN publicly disclosed an authentication bypass vulnerability (CVE-2026-16876) affecting UNIVERGE IX-R/IX-V WebGUI, and released a patch and official workaround.
ねこさん⚡(ΦωΦ)@catnap707Disclosure
NEC's Univerge IX-R/IX-V router series is affected by CVE‑2026‑16876, a critical vulnerability allowing unauthenticated arbitrary command execution via a crafted WebGUI message. Patched firmware is now available.