What you need to know today.
Critical RCEs and KEV additions dominate today's brief, with flaws in Haiwell, WordPress, IBM Db2, Linux kernel, and Microsoft SQL Server posing significant threats.

A critical OS command injection vulnerability in Haiwell IoT Cloud HMI Gateway, CVE-2026-19188, allows unauthenticated attackers to execute arbitrary commands via the Net Check feature. This flaw, detailed in a CISA ICS Advisory, could enable widespread compromise of industrial control systems. The vendor has not yet released a patch or mitigation.
Multiple critical vulnerabilities have been disclosed in WordPress plugins, including CVE-2026-61962 and CVE-2026-27544, which permit unauthenticated arbitrary code execution and remote code execution, respectively. Additionally, CVE-2026-15341 (User Session Synchronizer) and CVE-2026-15303 (6Storage Rentals) suffer from authentication bypass flaws, potentially leading to account takeover. These issues expose a significant number of WordPress sites to compromise.
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected by several critical vulnerabilities. CVE-2026-17186 allows remote attackers to execute arbitrary CL commands, CVE-2026-17184 enables arbitrary code execution due to external control of file names or paths, and CVE-2026-17182 permits authentication bypass. These flaws could allow attackers to gain significant control over affected IBM systems.
A critical vulnerability, CVE-2023-52440, has been identified in the Linux kernel's ksmbd component. This flaw, a slub overflow in the ksmbd_decode_ntlmssp_auth_blob function, can be triggered when processing NTLMSSP authentication blobs with oversized session keys. Successful exploitation could lead to kernel-level compromise. A fix has been integrated into the kernel.
Microsoft SQL Server Reporting Services is vulnerable to remote code execution via CVE-2020-0618, stemming from improper handling of page requests. This critical flaw, already added to the CISA Known Exploited Vulnerabilities (KEV) catalog, poses a significant risk to organizations relying on Microsoft's database services. Microsoft has released patches to address this vulnerability.
Sophos Cyberoam OS versions prior to December 4, 2020, are susceptible to SQL injection attacks through the WebAdmin interface, as detailed in CVE-2020-29574. This critical vulnerability allows unauthenticated attackers to execute arbitrary SQL statements, potentially leading to data breaches or system compromise. Patches are available from Sophos.
A local privilege escalation vulnerability, CVE-2021-4034, affects the pkexec utility in polkit on Linux systems. This flaw allows unprivileged users to execute commands as root by exploiting a flaw in how pkexec handles certain inputs. The vulnerability has been added to the CISA KEV catalog, and multiple security outlets have reported on its exploitation, including The Hacker News and Dark Reading. A fix is available in updated polkit versions.
Tenable Security Center is impacted by several critical vulnerabilities, including CVE-2026-19682, CVE-2026-19681, and CVE-2026-19626. These flaws allow for remote code execution and command injection, with some requiring only unauthenticated access or basic user privileges. Exploitation could lead to full system compromise. Tenable has released updates to address these security weaknesses.