CVE-2026-18616PoC

LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

3.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-03); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-03: 1Mentions · 2026-08-04: 1Mentions · 2026-08-06: 1PoC Mentioned / Linked · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-04: 1PoC Mentioned / Linked · 2026-08-06: 1Exploit Tool / Code · 2026-08-03: 1Exploit Tool / Code · 2026-08-04: 1Technical Details · 2026-08-04: 1Technical Details · 2026-08-06: 108-0308-0408-06
Signal classification2 categories
PoC
266.7%
Disclosure
133.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-031
PoC1
2026-08-041
PoC1
2026-08-061
Disclosure1
Full discourse3 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    🔌 GL-iNet GL-MT3000 routers up to 4.4.5 are vulnerable to command injection via the server.set_peer function in http://wg-server.so. No auth needed over the network. CVE-2026-18616 | CVSS 8.9 #cybersecurity #vulnerabilities #ciso https://secalerts.co/vulnerability/CVE-2026-18616?utm_campaign=x https://t.co/3uNGyPYbYK

    Post summary

    GL‑iNet GL‑MT3000 routers (firmware up to 4.4.5) are vulnerable to unauthenticated command injection (CVE‑2026‑18616) via server.set_peer, with a PoC reference at wg‑server.so; no patch or active exploitation has been reported yet.

    01021282
    888 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: #GL-iNet: PoC pubblici per lo sfruttamento delle CVE-2026-18601, CVE-2026-18602, CVE-2026-18612, CVE-2026-18616 Rischio: 🔴 Tipologia: 🔸Remote Code Execution 🔗https://www.acn.gov.it/portale/en/w/gl-inet-poc-pubblici-per-lo-sfruttamento-delle-cve-2026-18601-cve-2026-18602-cve-2026-18612-cve-2026-18616 🔄 Aggiornamenti disponibili 🔄 https://t.co/hyI0AfGXoC

    Post summary

    The post announces publicly available PoCs for four GL‑iNet CVE‑2026‑186xx vulnerabilities, confirming remote code execution potential, with no active exploitation or patch information provided.

    0101168
    629 followersView on X
  • MalwareObserver@MalwareObserver
    PoC

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-18616](https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/wg_set_peer_... https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/wg_set_peer_rce/CVE.md #ZeroDay #PatchManagement #Vulnerability

    Post summary

    The tweet shares a GitHub link to the CVE-2026-18616 PoC, indicating a zero‑day vulnerability has been identified, but no exploitation or patch details are mentioned.

    0000045
    18 followersView on X

Explore more