Critical Vulnerabilities Disclosed: CVE-2026-16327 and CVE-2026-65687

Critical Vulnerabilities Disclosed: CVE-2026-16327 and CVE-2026-65687

First seen 24 Jul 2026, 01:15 UTC EchelongraphIsmalicious 71% similarity 71.0

Article Content

Browse articles
ThreatCluster

Two significant vulnerabilities have been reported: CVE-2026-16327 in D-Link DNS-320 and CVE-2026-65687 in Bold Reports Standalone Report Designer. CVE-2026-16327, with a CVSS score of 7.3, allows remote attackers to exploit unrestricted file uploads, while CVE-2026-65687, rated at 9.8, enables unauthenticated access to sensitive files through path traversal. The D-Link vulnerability has no vendor fix yet, and users are advised to implement workarounds. In contrast, the Bold Reports vulnerability has not confirmed active exploitation, but it poses a severe risk due to potential unauthorized access to sensitive data. Both vulnerabilities have been publicly disclosed, increasing the urgency for organizations to assess their exposure and apply necessary mitigations.

Key Points: • CVE-2026-16327 allows remote file upload vulnerabilities in D-Link DNS-320. • CVE-2026-65687 enables unauthorized file access in Bold Reports Standalone Report Designer. • Immediate action is required for CVE-2026-16327 as no vendor fix is available yet.

ThreatCluster AI

Timeline

2026-07-20
CVE-2026-16327 published
D-Link DNS-320 vulnerability disclosed, allowing remote file uploads.
Echelongraph
2026-07-23
CVE-2026-65687 published
Bold Reports vulnerability allows unauthenticated file access through path traversal.
Ismalicious

Community

Browse all →