CVE-2026-16876

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.

  • Published Sep 7, 2026
  • CVSS 9.3 critical
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-16876 at the National Vulnerability Database