A critical vulnerability has been identified in Tenda AC9 firmware version 15.03.05.14, specifically affecting the R7WebsSecurityHandler function within the Web Management component. The flaw results in improper authentication, allowing attackers to bypass authentication mechanisms remotely. The vulnerability can be exploited without local access, significantly increasing its risk profile. A public exploit has already been published, raising the likelihood of active exploitation in the wild. The affected product is a widely used consumer and small business router manufactured by Tenda. The vulnerability has been assigned CVE-2026-86300 and is tracked on NVD and VulDB. Multiple proof-of-concept references have been published on GitHub detailing unauthorized password setting and product information disclosure. Organizations and individuals using the Tenda AC9 router are advised to apply patches or mitigations immediately.