CVE-2026-9216
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network acc
CVSS
3.5
Low
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-121
Not enough EPSS history yet.
An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality or integrity impact. A crash of the router's management UI does not impact the availability of the router's core services like WiFi network.
- www.netgear.comhttps://www.netgear.com/support/product/rax30
- www.netgear.comhttps://www.netgear.com/support/product/rax35
- www.netgear.comhttps://www.netgear.com/support/product/rax38
- www.netgear.comhttps://www.netgear.com/support/product/rax40
- www.netgear.comhttps://www.netgear.com/support/product/raxe300
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-839907.8 HIG—
———Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.3hCVE-2026-819537.8 HIG—
———Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.3hCVE-2026-813967.8 HIG—
———Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.3hCVE-2026-813887.8 HIG—
———Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.3hCVE-2026-785048.8 HIG—
———Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.3hCVE-2026-730068.8 HIG—
———Stack-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.3h