CVE-2026-71954 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
CVE-2026-71954 is a vulnerability tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed August 9, 2026; most recent activity August 9, 2026.
A critical command injection vulnerability, CVE-2026-71954, has been identified in D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108. This vulnerability allows…
CVE-2026-71954 is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
The most recent intelligence report mentioning CVE-2026-71954 on ThreatCluster is dated August 9, 2026.
Across ThreatCluster reporting, CVE-2026-71954 most frequently co-occurs with Command Injection, CWE-78 - OS Command Injection, T1059 - Command and Scripting Interpreter, D-Link Dwr-m961, OS Command Injection.
The most significant recent cluster is “Critical Command Injection Vulnerability in D-Link DWR-M961 Devices” (2 articles · Updated August 9, 2026). CVE-2026-71954 appears across 1 threat cluster in total, listed above with sources.
CVE-2026-71954 appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.