Router Flaws and WordPress Risks Dominate Briefing
Critical flaws in Tenda and Acer routers, a WordPress supply-chain attack, and multiple WordPress vulnerabilities are highlighted today.

Critical vulnerabilities have been disclosed in Tenda routers, including CVE-2026-11499, which allows for stack-based buffer overflows through manipulation of the blkDomain argument in the formDOMAINBLK function. This could lead to remote code execution on affected Tenda HG7HG9 and HG10 devices. As Vypr Intelligence reported, these flaws present a significant risk to network infrastructure, particularly for small to medium businesses relying on these devices.
Acer is addressing critical vulnerabilities in its Wave 7 routers, including CVE-2026-49200 and CVE-2026-49201. CVE-2026-49200 allows unauthenticated access to cleartext credentials stored in the acer_cgi.log file, while CVE-2026-49201 enables attackers to decrypt and re-encrypt system backups by exploiting a hardcoded AES key in the upload.cgi binary. BleepingComputer notes that these issues could facilitate persistent backdoor injection and unauthorized system access, posing a severe threat to users.
A supply-chain attack has been identified targeting the guardrails-ai Python package on PyPI. Version 0.10.1, published on May 11, 2026, contains malicious code that executes upon installation, as detailed by CVE-2026-45758. This incident highlights the ongoing risks associated with software dependencies and the potential for widespread compromise when malicious packages are distributed through trusted repositories.
Several WordPress themes and plugins are affected by critical vulnerabilities, including arbitrary file uploads and remote code execution. CVE-2024-58349 in the Travelscape theme, CVE-2024-58348 in the Background Image Cropper plugin, and CVE-2023-54352 in the Seotheme all allow unauthenticated attackers to upload malicious files and execute arbitrary code. These flaws underscore the importance of keeping WordPress sites and their components updated to prevent exploitation.
ZKTeco products are facing scrutiny due to multiple critical vulnerabilities. CVE-2016-20030 in ZKBioSecurity 3.0 allows for user enumeration, while CVE-2016-20026 in the same product reveals hardcoded credentials for the bundled Apache Tomcat server, enabling unauthorized access to the manager application. Additionally, CVE-2016-20024 in ZKTime.Net 3.0.1.6 presents an insecure file permissions vulnerability that could lead to privilege escalation. These issues collectively expose ZKTeco systems to significant security risks.
Google Chrome on Android is impacted by several critical vulnerabilities, including sandbox escapes and use-after-free issues. CVE-2026-11167, CVE-2026-11163, and CVE-2026-11152, all patched in Chrome version 149.0.7827.53, allow remote attackers to potentially escape the sandbox or execute arbitrary code via crafted HTML pages. These vulnerabilities demonstrate the persistent challenges in securing web browser environments.