Critical Flaws Hit IBM Db2, WordPress, and IoT Gateways
Critical vulnerabilities disclosed in IBM Db2, Haiwell IoT Gateway, and WordPress plugins, alongside RCEs in Microsoft SQL Server and Sophos Cyberoam OS.

Multiple critical vulnerabilities have been disclosed in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6, including remote code execution, arbitrary CL command execution, and authentication bypass. CVE-2026-17186 allows arbitrary CL command execution due to improper neutralization of special elements in a command. CVE-2026-17184 enables remote code execution via external control of file names or paths. CVE-2026-17182 permits authentication bypass and sensitive information alteration due to improper validation of request URI path segments. As Vypr Intelligence reported, these flaws collectively pose a significant risk to systems running this software.
A critical OS command injection vulnerability (CVE-2026-19188) has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability resides in the Net Check feature, accessible via the /setting endpoint, where the cmdPing Socket.io event fails to properly sanitize user input, allowing unauthenticated attackers to execute arbitrary OS commands. This critical flaw was detailed in a CISA ICS Advisory.
Several critical vulnerabilities affecting WordPress plugins and core functionalities have been disclosed. CVE-2026-61962 and CVE-2026-27544 represent unauthenticated arbitrary code execution and remote code execution, respectively. Additionally, CVE-2026-15341 in the User Session Synchronizer plugin and CVE-2026-15303 in the 6Storage Rentals plugin allow for authentication bypass, potentially leading to account takeover. These vulnerabilities highlight ongoing risks within the WordPress ecosystem.
A critical vulnerability in the Linux kernel, CVE-2023-52440, has been resolved. This flaw, a slub overflow in ksmbd_decode_ntlmssp_auth_blob(), could occur if the authblob->SessionKey.Length exceeded the session key size. The fix addresses a potential memory corruption issue within the ksmbd module, which handles SMB protocol operations.
A critical remote code execution vulnerability (CVE-2020-0618) exists in Microsoft SQL Server Reporting Services. This flaw arises from the improper handling of page requests, allowing unauthenticated attackers to execute arbitrary code on the affected server. This vulnerability has been present for some time and remains a significant risk for organizations utilizing this Microsoft product.
The pkexec utility in Oracle's HTTP Server is affected by CVE-2021-4034, a local privilege escalation vulnerability. This flaw allows unprivileged users to execute commands with elevated privileges by exploiting the setuid nature of pkexec and its policy definitions. The vulnerability has been discussed in various security analyses, including The Hacker News, Dark Reading, and Securelist.
A critical SQL injection vulnerability, CVE-2020-29574, impacts Sophos Cyberoam OS through version 2020-12-04. Unauthenticated attackers can exploit this flaw in the WebAdmin interface to execute arbitrary SQL statements, potentially leading to data compromise or system control.
Tenable Security Center is impacted by multiple critical vulnerabilities, including CVE-2026-19682, CVE-2026-19681, and CVE-2026-19626. These flaws allow for remote code execution and command injection, with varying prerequisites such as unauthenticated access or authenticated file uploads. The vulnerabilities could enable attackers to execute arbitrary commands on the underlying operating system with the privileges of the service account.
Critical vulnerabilities have been disclosed in MindsDB Minds Platform (CVE-2026-73678) and Mcp Memory Service (CVE-2026-50027). The MindsDB flaw allows unauthenticated remote code execution via crafted prompts to an unprotected API endpoint. The Mcp Memory Service vulnerability permits unauthenticated access to HTTP routes under /api/documents/*, even when authentication is configured.
Emlog (CVE-2026-73849) and Metacat (CVE-2026-48528) are affected by critical vulnerabilities. Emlog's install.php script allows reinstallation without authentication, bypassing security checks. Metacat suffers from an unauthenticated SQL injection vulnerability in its REST API endpoints.
Microsoft's Win32k component is affected by CVE-2022-21882, a high-severity elevation of privilege vulnerability. This flaw allows attackers to gain higher privileges on a compromised system by exploiting a weakness within the Win32k driver.