What you need to know today.
Microsoft vulnerabilities dominate the threat landscape, with critical RCE flaws in Outlook and Exchange actively exploited, alongside numerous Windows issues.

Microsoft's Outlook and Exchange Server are in the crosshairs with multiple critical vulnerabilities, including CVE-2024-21413 for Outlook Remote Code Execution and CVE-2022-41080 for Exchange Server Elevation of Privilege. These flaws, some with high exploit prediction scores, are part of a broader wave of Microsoft vulnerabilities being actively exploited, underscoring the need for immediate patching. The KEV listing for these and other Microsoft products like Windows Kernel (CVE-2024-21338) and Windows Search (CVE-2023-36884) highlights their critical nature and active exploitation.
Beyond Microsoft, several critical vulnerabilities have been disclosed in other software. Joomla's Fabrik extension (CVE-2026-66915) suffers from remote code execution via its ajax_calc feature. ProxySQL (CVE-2026-48772) has a critical vulnerability in its MySQL frontend that could allow attackers to bypass security controls. Additionally, Dulldusk's phpfm (CVE-2026-72593, CVE-2026-72592) contains missing authentication and unrestricted file upload flaws, enabling RCE. These, along with command injection vulnerabilities in Alseambusher's crontab-ui (CVE-2026-72589, CVE-2026-72590) and Duhow's xiaoai-patch (CVE-2026-72580), present significant risks for affected systems.
A critical remote code execution vulnerability in Microsoft's Windows TCP/IP stack (CVE-2021-26424) and Windows Kernel (CVE-2021-34458) remain significant threats, despite their earlier discovery. These flaws, with high CVSS scores and active exploitation potential, allow attackers to execute arbitrary code on vulnerable systems. Microsoft's Windows Services for NFS (CVE-2021-26432) also presents a critical RCE risk. The continued presence and exploitation of these vulnerabilities emphasize the ongoing need for diligent patch management across Microsoft environments.
NASA's fprime-gds (CVE-2026-72577) is affected by critical vulnerabilities allowing arbitrary code execution on ground station hosts and command injection to spacecraft. This highlights the security risks in critical infrastructure software. The vulnerability stems from the Flask application's security misconfigurations, enabling unauthenticated remote attackers to compromise the system. Immediate attention is required for any systems utilizing fprime-gds to prevent potential mission-critical impacts.
A critical vulnerability in the JWT authentication mechanism (CVE-2026-5430) allows attackers to bypass security controls by crafting tokens signed with unsupported algorithms. This flaw could lead to unauthorized access and potential compromise of systems relying on JWT for authentication. The lack of explicit algorithm validation makes this a significant risk for applications using this standard.