Vendor
Linksys vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in Linksys: 0 in the last 7 days and 1 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86299, was published on 7 September 2026. 14 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 1
- Critical, all time
- 2
- Exploited in the wild
- 0
About Linksys
Linksys is a manufacturer of networking hardware, including routers, switches, and access points.
Linksys technologies
Latest Linksys vulnerabilities
- CVE-2026-86299: Linksys RE7000 OS command injection in PingTest handlercriticalCVSS 9.9EPSS 3.7%
- CVE-2025-14136: A security flaw has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000…highCVSS 8.8EPSS 1.1%
- CVE-2025-14135: A vulnerability was identified in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000…highCVSS 8.8EPSS 0.9%
- CVE-2025-14133: A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000…highCVSS 8.8EPSS 0.9%
- CVE-2025-60693: Linksys E1200 v2 stack buffer overflow in httpd get_merge_macmediumCVSS 6.5EPSS 0.8%
- CVE-2025-60696: Linksys RE7000 stack overflow in makeRequest.cgi arplookuphighCVSS 8.4EPSS 0.2%
- CVE-2025-60695: Linksys E7350 stack buffer overflow in mtk_dut binarymediumCVSS 5.9EPSS 0.2%
- CVE-2025-60694: Linksys E1200 v2 stack overflow in validate_static_routehighCVSS 7.5EPSS 1.3%
- CVE-2025-60692: Cisco Linksys E1200 stack overflow in libshared.sohighCVSS 8.4EPSS 0.2%
- CVE-2025-60691: Linksys E1200 v2 stack buffer overflow in httpd apply_cgihighCVSS 8.8EPSS 0.7%
- CVE-2025-60690: Linksys E1200 v2 stack overflow in httpd get_merge_ipaddrhighCVSS 8.8EPSS 4.4%
- CVE-2025-44654: Linksys E2500 improper access control in vsftpd configurationcriticalCVSS 9.8EPSS 1.1%
- CVE-2025-44657: Linksys EA6350 improper access control in vsftpd configurationlowCVSS 3.9EPSS 0.3%
Most severe Linksys vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-86299: Linksys RE7000 OS command injection in PingTest handlercriticalCVSS 9.9EPSS 3.7%
- CVE-2025-44654: Linksys E2500 improper access control in vsftpd configurationcriticalCVSS 9.8EPSS 1.1%
- CVE-2025-60690: Linksys E1200 v2 stack overflow in httpd get_merge_ipaddrhighCVSS 8.8EPSS 4.4%
- CVE-2025-14136: A security flaw has been discovered in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000…highCVSS 8.8EPSS 1.1%
- CVE-2025-14135: A vulnerability was identified in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000…highCVSS 8.8EPSS 0.9%
- CVE-2025-14133: A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000…highCVSS 8.8EPSS 0.9%
- CVE-2025-60691: Linksys E1200 v2 stack buffer overflow in httpd apply_cgihighCVSS 8.8EPSS 0.7%
- CVE-2025-60696: Linksys RE7000 stack overflow in makeRequest.cgi arplookuphighCVSS 8.4EPSS 0.2%
- CVE-2025-60692: Cisco Linksys E1200 stack overflow in libshared.sohighCVSS 8.4EPSS 0.2%
- CVE-2025-60694: Linksys E1200 v2 stack overflow in validate_static_routehighCVSS 7.5EPSS 1.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 1 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/linksys.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Linksys vulnerabilities", https://junglewise.ai/threats/vendors/linksys, 26 September 2026.