CVE-2026-76591
Low · CVSS 2.1Published 2026-08-19
CVSS
2.1
Low
EPSS
—
exploit probability
Active Exploit
No
not yet listed
Low — routine — Low severity. Handle in normal patch cycle.
What is CVE-2026-76591?
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
CVSS Score Explained
CVSS 2.1 is Low severity. Impact is limited and exploitation is difficult. Patch when convenient.
EPSS Exploitation Probability
No EPSS score yet — model needs more data on this CVE.
References & Patches
- PoChttps://github.com/meishigana/CVE/blob/main/team15_20260702/14_755ap-ssi-cmdi/poc/poc-ssi-injection.py
- ›https://github.com/meishigana/CVE/tree/main/team15_20260702/14_755ap-ssi-cmdi
- ›https://vuldb.com/cve/CVE-2026-76591
- ›https://vuldb.com/submit/877853
- ›https://vuldb.com/vuln/393088
- ›https://vuldb.com/vuln/393088/cti
Track vulnerabilities for your stack
Tell us what tech you run — Node.js, Python, Java, nginx, whatever — and get a weekly email when new CVEs affect it.
Recent CVEs
- CVE-2026-76923Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service5.5
- CVE-2026-76924Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service5.5
- CVE-2026-76926BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service3.1
- CVE-2026-76927H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service4.7
- CVE-2026-76928X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service7.5
- CVE-2026-76929Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service4.7