Ismalicious Critical Vulnerabilities Disclosed: CVE-2026-16327 and CVE-2026-65687
Article Content
- •CVE-2026-16327 allows remote file upload vulnerabilities in D-Link DNS-320.
- •CVE-2026-65687 enables unauthorized file access in Bold Reports Standalone Report Designer.
- •Immediate action is required for CVE-2026-16327 as no vendor fix is available yet.
Two significant vulnerabilities have been reported: CVE-2026-16327 in D-Link DNS-320 and CVE-2026-65687 in Bold Reports Standalone Report Designer. CVE-2026-16327, with a CVSS score of 7.3, allows remote attackers to exploit unrestricted file uploads, while CVE-2026-65687, rated at 9.8, enables unauthenticated access to sensitive files through path traversal. The D-Link vulnerability has no vendor fix yet, and users are advised to implement workarounds. In contrast, the Bold Reports vulnerability has not confirmed active exploitation, but it poses a severe risk due to potential unauthorized access to sensitive data. Both vulnerabilities have been publicly disclosed, increasing the urgency for organizations to assess their exposure and apply necessary mitigations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-16327 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…