CVE-2026-75501Disclosure

HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.

7.5/ 10 priority

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 5 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • Peaked 2d ago at 6 mentions (2026-08-24); latest day: 2
  • 14 total mentions across 5 days

Deep dive

Activity timeline14 mentions / 5d
02356Mentions · 2026-08-21: 1Mentions · 2026-08-22: 1Mentions · 2026-08-24: 6Mentions · 2026-08-25: 4Mentions · 2026-08-26: 2PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-08-22: 1PoC Mentioned / Linked · 2026-08-24: 1Exploit Tool / Code · 2026-08-21: 1Exploit Tool / Code · 2026-08-22: 1Active Exploitation · 2026-08-24: 1Active Exploitation · 2026-08-25: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-25: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-24: 5Technical Details · 2026-08-25: 408-2108-2208-2408-2508-26
Signal classification5 categories
Disclosure
750.0%
PoC
214.3%
Active Exploitation
214.3%
General
214.3%
Patch
17.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-08-211
PoC1
2026-08-221
PoC1
2026-08-246
Active Exploitation1Disclosure5
2026-08-254
Active Exploitation1Disclosure2General1
2026-08-262
General1Patch1
Full discourse14 posts
  • yousukezan@yousukezan
    Disclosure

    米国の複数の通信事業者が採用するCalix GS7 XGS(GS5239XG)ルーターに、認証なしで外部からポート転送設定を作成できる未修正の脆弱性「CVE-2026-75501」が見つかった。CERT/CCが公開した。 影響するのはEXOS/6.6.47搭載機で、MiniUPnPdの制御エンドポイントがWAN側TCP 5000番ポートで認証なしに公開されている。攻撃者はSOAPリクエストでポート転送ルールを作成・削除・列挙し、外部IPアドレスを取得できる。 これによりNATやファイアウォールを迂回し、監視カメラ、NAS、管理画面、IoT機器をインターネットへ公開できる。発見者Brian Khan Quintanaは、自宅外から内部アドレスへの転送設定を作成し、有効期限なしのルールが再起動後も残ることを確認した。 Quintanaは6月7日にCalixへ報告を試みたが応答がなく、Carnegie Mellon CERT/CCへ届け出た。記事執筆時点で未修正で、UPnPを管理画面から無効化する回避策が推奨されている。設定を変更できない場合はISPへ無効化を依頼する必要があるという。 https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/

    Post summary

    The post announces an unpatched CVE-2026-75501 affecting Calix GS7 XGS routers, details the unauthenticated UPnP control flaw, and recommends disabling UPnP as a workaround, with no evidence of current exploitation.

    020501.6K
    15.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    CVE-2026-75501 exposes an unauthenticated UPnP service on Calix routers. Public PoC code shows how attackers bypass NAT and firewall protections. #CVE202675501 #Calix #UPnP #RouterSecurity #NAT #IoTSecurity http://securityonline.info/cve-2026-75501-calix-upnp-nat-bypass/

    Post summary

    The post announces CVE‑2026‑75501, highlighting publicly available PoC code that demonstrates how unauthenticated Calix UPnP services can be exploited to bypass NAT and firewall protections.

    01051593
    13.0K followersView on X
  • JENI Systems@JeniSystems
    General

    A Calix router flaw could expose devices inside your home network through unauthenticated port forwarding, and a reboot may not undo it. https://jenisystems.com/news/calix-router-vulnerability-cve-2026-75501-upnp/ #Cybersecurity #NetworkSecurity #RouterSecurity https://t.co/waK425IAJW

    Post summary

    The post announces a Calix router vulnerability (CVE‑2026‑75501) that may expose internal devices via unauthenticated port forwarding, but provides no technical details, PoC, exploit tools, or patch information.

    0101024
    12 followersView on X
  • Marcell Ujlaki@UjlakiMarci
    Disclosure

    CVE-2026-75501: allows remote attackers to bypass network address translation (NAT) and expose internal network devices directly to the public internet. “No password. No prompt. Nothing on screen. The rule survives a reboot.” https://t.co/RE2mli8Qjt

    Post summary

    The statement indicates that CVE‑2026‑75501 permits remote attackers to bypass NAT and expose internal devices, but no PoC, exploit, patch, or evidence of active exploitation is mentioned.

    10010238
    359 followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    4. Unpatched Calix routers let attackers bypass NAT A missing-authentication flaw (CVE-2026-75501) in Calix GS7 XGS residential routers used by multiple U.S. broadband providers allows remote attackers to create port-forwarding rules and expose internal devices. No vendor patch is available yet—disable UPnP where possible. 5. Critical Keycloak password-reset flaw enables full account takeover CVE-2026-18963 (CVSS 9.1) in Keycloak lets unauthenticated attackers force password resets and take over any account without email verification. Fixed versions are available; disable the “Forgot Password” feature as a temporary mitigation if you cannot update right away. #Cybersecurity #CISA #NIST

    Post summary

    The post highlights real‑world exploitation of two critical CVEs, noting the absence of patches for one and the availability of fixes for the other, while also recommending mitigations.

    1000071
    76 followersView on X
  • CVETodo@CveTodo
    Patch

    A high-severity vulnerability in Calix's GS7 XGS residential router has no patch and no vendor response, leaving home networks served by major U. broadband providers exposed to a trivially simple... https://cvetodo.com/news/unpatched-cve-2026-75501-in-calix-gs7-xgs-router-lets-attackers-punch-holes-through-nat-firewall #Calix #GS7XGSGS5239XG #CVE #InfoSec #Cybersecurity https://t.co/2xghD4iGEn

    Post summary

    An unpatched high‑severity CVE‑2026‑75501 has been identified in Calix GS7 XGS routers, with no vendor patch or response yet, and no evidence of an active exploit disclosed.

    0000040
    19 followersView on X
  • connect24h@connect24h
    Disclosure

    その穴、ルーター自身が開けるのはえげつない。 米国の複数ISPが採用するCalix GS7 XGS(GS5239XG)のEXOS/6.6.47で、WAN側TCP 5000のMiniUPnPdへ認証なしでSOAPリクエストを送り、port forwardingを作成できる可能性が報告された。CVE-2026-75501。期限なしの設定は再起動後も残ったという。 実悪用や全環境での再現、Calix公式の修正状況は未確認。ただ、これは家庭用だからと監視対象から外した機器も他人事じゃない。CSIRTの初動観点なら、機種・EXOS version・WAN側TCP 5000・UPnP設定を棚卸し軸にしたい。検証の詳しい経緯は元記事にある。NATは境界であって、認証ではない。 ソース: https://www.bleepingcomputer.com/news/security/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/

    Post summary

    CVE-2026-75501 targets Calix GS7 XGS routers, enabling unauthenticated SOAP requests on TCP 5000 to create persistent port forwards that bypass NAT, potentially exposing internal devices; no active exploitation or mitigation information is confirmed.

    00000278
    6.3K followersView on X
  • Autumn Good@autumn_good_35
    General

    『By default, the UPnP service is exposed on the device’s WAN interface and does not require authentication.』😱 CVE-2026-75501 VU#756733 - Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability https://kb.cert.org/vuls/id/756733

    Post summary

    The post reports that the Calix GS7 router’s UPnP service is exposed without authentication (CVE‑2026‑75501) but offers no PoC, exploit code, or patch information.

    00000445
    7.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers are exploiting CVE-2026-75501 in Calix routers to bypass NAT protections with unauthenticated SOAP requests, exposing internal cameras, IoT devices, and NAS systems directly to the internet. This incident highlights why zero-trust architecture can't rely on perimeter defenses alone. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/calix-cve-2026-75501-upnp-nat-bypass-vulnerability

    Post summary

    The post confirms that CVE-2026-75501 is being actively exploited in the wild, enabling unauthenticated SOAP requests to bypass NAT protections and expose internal devices to the internet.

    0000077
    1.9K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    Unpatched Calix GS7 XGS routers with CVE-2026-75501 let remote attackers bypass NAT, add port forwards, and expose internal devices via WAN port 5000 without login. #Calix #CVE-2026-75501 #UPnP https://www.hendryadrian.com/unpatched-calix-flaw-lets-hackers-bypass-nat-to-expose-internal-devices/

    Post summary

    The tweet discloses that unpatched Calix GS7 XGS routers with CVE‑2026‑75501 allow remote attackers to bypass NAT, add port forwards, and expose internal devices via WAN port 5000 without authentication.

    00000210
    4.6K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Unpatched Calix Router Flaw (#CVE-2026-75501): Remote UPnP Exploitation Bypasses NAT and Firewall Protections + Video -Prediction: 📈 4 Positive | 📉 6 Negative https://undercodetesting.com/unpatched-calix-router-flaw-cve-2026-75501-remote-upnp-exploitation-bypasses-nat-and-firewall-protections-video/ Educational Purposes!

    Post summary

    The post announces CVE‑2026‑75501 in unpatched Calix routers, detailing a UPnP-based remote exploitation that bypasses NAT and firewalls, with no confirmed patch, PoC, or active exploitation reported.

    0000045
    708 followersView on X
  • Zubiqo@zubiqo
    Disclosure

    Unpatched Calix $CALX flaw allows attackers to expose internal devices to the public internet. Hackers can send unauthenticated SOAP requests to permanently expose internal cameras, NAS drives, and IoT appliances. The vulnerability, tracked as CVE-2026-75501, affects Calix GS5239XG residential gateways running EXOS/6.6.47 firmware. The router exposes its UPnP service to the public WAN interface on TCP port 5000 without access controls. Calix supplies these devices to major US broadband providers including Cox Communications, Brightspeed, and CityFibre. "One unauthenticated request from anywhere in the world is enough to open a permanent hole through the router's firewall to any device inside the house. No password. No prompt. Nothing on screen. The rule survives a reboot." — Brian Khan Quintana Leaving unauthenticated WAN endpoints exposed on premium ISP hardware is a catastrophic engineering failure that leaves consumer networks entirely defenseless.

    Post summary

    The text announces a newly disclosed CVE-2026-75501 affecting Calix gateways, describing how unauthenticated SOAP requests can permanently expose internal devices to the internet, but provides no evidence of active use, exploit code, or patch availability.

    00000116
    173 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Unpatched Calix Router Flaw (#CVE-2026-75501) – NAT Bypass Exposes Internal Devices to the Public Internet + Video -Prediction: 📈 2 Positive | 📉 6 Negative https://undercodetesting.com/unpatched-calix-router-flaw-cve-2026-75501-nat-bypass-exposes-internal-devices-to-the-public-internet-video/ Educational Purposes!

    Post summary

    The content announces a new CVE-2026-75501 flaw in Calix routers that allows a NAT bypass, potentially exposing internal devices to the public internet, and links to a video for demonstration.

    0000040
    708 followersView on X
  • moton@moton
    PoC

    CVE-2026-75501: Public PoC for Calix Router Flaw That Bypasses NAT and Firewall Protections - https://securityonline.info/cve-2026-75501-calix-upnp-nat-bypass/

    Post summary

    The post announces a publicly available proof‑of‑concept for a Calix router flaw that bypasses NAT and firewall protections, but it does not describe active exploitation, patches, or detailed technical specifics.

    0000071
    753 followersView on X

Explore more