
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in

Cisco patched two dozen flaws including critical Catalyst SD-WAN and IOS XE command-injection bugs plus an FMC authentication bypass in

CISA added actively exploited Langflow and Apache Tomcat vulnerabilities to the KEV catalog, linking the Tomcat flaw to an AI-enabled

cPanel patched CVE-2026-58048, a CVSS 9.4 privilege-escalation flaw letting an authenticated hosting customer execute SQL in the database root context.

Forescout disclosed 15 TP-Link Omada zero-touch provisioning vulnerabilities that chain with earlier RCE flaws into full fleet-wide network compromise.

Thermo Fisher patched CVE-2026-17583 in Applied Biosystems DNA-testing software, allowing forensic evidence file alterations to pass with little detection.

FaceHugger flaws in Hugging Face Diffusers bypass trust_remote_code and let malicious model repositories execute arbitrary code when models are loaded.

N-able warns attackers exploited CVE-2026-18577 to take over N-central servers and reach managed endpoints, planting Cloudflare tunnels for persistent access.

CISA added the Cisco FMC zero-day CVE-2026-20316 to the KEV after active exploitation began. Cisco is also patching a critical

The Rails framework patched CVE-2026-66066, a critical Active Storage flaw letting unauthenticated attackers read server files via crafted image uploads.

Disclosed CVE-2026-59726 is a CVSS 10.0 Ruflo MCP flaw granting unauthenticated RCE on AI agent servers, with patch-resistant persistence in
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.