Netcore has 32 CVEs on record. Disclosure cadence is accelerating: 32 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 32. The median CVSS is 6.8 (medium), with 7 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (6) and CWE-522 (5). Most affected products: NR255-V (23), NBR200V2 (7), NR268 (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 32 prev 0
Worst active — by depth score
CVE-2026-94101Critical· 9.9A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.07124667CVE-2026-94096Critical· 9.9A vulnerability was found in Netcore NBR200V2 1.3.241127.07124667CVE-2026-94098Critical· 9.1A vulnerability was identified in Netcore NBR200V2 1.3.241127.07124663CVE-2026-94100Critical· 9.9A weakness has been identified in Netcore NBR200V2 1.3.241127.07124655CVE-2026-94099Critical· 9.9A security flaw has been discovered in Netcore NBR200V2 1.3.241127.07124655
Netcore vulnerabilities
CVEs affecting Netcore, newest first. Open any entry for full detail, references, and exploit status.
32 CVEsRSS
CVE-2026-76853High· 8.1Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation
Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check in put_parame_file_cgi.c to bypass restr…
CVE-2026-76852High· 8.8Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks
Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature valid…