D-Link has warned customers about a maximum-severity zero-day vulnerability affecting its legacy DIR-822A dual-band Wi-Fi routers. The flaw, tracked as CVE-2026-86296, already has public proof-of-concept exploit code, and no patch is currently available.
The advisory places the issue at the highest severity level, though it does not describe the attack vector in detail. Because the DIR-822A is a legacy product, D-Link may not issue a fix, leaving affected users with limited options.
Users who still run the DIR-822A should treat the device as at risk and consider replacing it with a supported model. The presence of public exploit code raises the likelihood of active attacks, so the warning should not be ignored.