Critical Authentication Bypass Vulnerability in Acer Wave 7 Mesh Routers
Independent security researcher Gergo Pap has identified a maximum-severity zero-day vulnerability, designated CVE-2026-49200, affecting Acer Wave 7 mesh routers. The flaw is a broken access control vulnerability within the router management interface that allows unauthenticated remote attackers to access and retrieve router log archive files. These archives contain sensitive administrative credentials in plaintext format, facilitating complete system compromise. By exploiting this vector, an attacker can bypass standard authentication protocols, gain unauthorized access to the device, and execute lateral movement within the protected network. Acer is currently developing and deploying firmware updates to mitigate this critical information disclosure and access control risk.
Critical Arbitrary Code Execution Vulnerabilities in Notepad++
Notepad++ versions up to 8.9.6 are susceptible to high-severity arbitrary code execution (ACE) via CVE-2026-48800 and CVE-2026-48778 (CVSS 7.8). The vulnerabilities stem from a design flaw where the application implicitly trusts unvalidated XML configuration files stored in the user's %AppData% directory. Attackers can achieve ACE by injecting malicious commands into shortcuts.xml to manipulate the 'Run' menu or by hijacking the command-line interpreter path within config.xml. This vector enables reboot-surviving persistence that bypasses endpoint detection and response (EDR) tools focusing on the installation directory. Immediate remediation requires upgrading to version 8.9.6.1 or later.