What you need to know today.
Zimbra RCE vulnerability added to CISA KEV, while critical flaws hit Joomla, WordPress plugins, and network devices.

A critical remote code execution vulnerability in Zimbra Collaboration Suite (ZCS) before 10.1.20, specifically when the optional zimbra-snmp package is installed and SNMP notifications are enabled, has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to execute arbitrary code by exploiting improper sanitization of untrusted input during SNMP notification processing. The vulnerability is already being actively exploited in the wild, as reported by multiple security outlets including Dark Reading and The Hacker News. Users are urged to update to ZCS version 10.1.20 or later to mitigate this risk.
Multiple critical vulnerabilities have been disclosed in the Fabrik extension for Joomla, affecting versions prior to 4.7.2. These include a missing Access Control List (ACL) check in the download element (CVE-2026-76607), a path traversal vulnerability via the image element (CVE-2026-76606), and a critical remote code execution flaw also stemming from the image element (CVE-2026-76605). Furthermore, an unauthenticated remote code execution vulnerability exists in the PHP form element (CVE-2026-76604), allowing attackers to execute user-provided code. These flaws collectively pose a significant risk to Joomla sites utilizing the Fabrik extension.
A critical vulnerability in TRENDnet TEW-821DAP firmware version 2.2.01b05, identified as CVE-2026-77946, allows for command injection. The vulnerability lies within the uci_safe_get function in the /cgi-bin/apply_time.cgi component, which handles NTP Timezone Configuration. Attackers can exploit this by manipulating specific parameters to execute arbitrary commands on the affected devices. This discovery was highlighted by Vypr Intelligence, underscoring the need for users to update their TRENDnet devices to the latest firmware.
Several critical vulnerabilities have been identified across various WordPress plugins, including unauthenticated PHP object injection in FreightCo (CVE-2026-66650), unauthenticated privilege escalation in Jawn (CVE-2026-66648), unauthenticated local file inclusion in WP Cafe Pro (CVE-2026-66587), unauthenticated privilege escalation in Affiliate Pro (CVE-2026-32558), and unauthenticated privilege escalation in Digits (CVE-2026-28165). Additionally, the Mailgun for WordPress plugin is vulnerable to Server-Side Request Forgery (SSRF) via path traversal up to version 2.2.0 (CVE-2026-78003). These flaws, detailed by Vypr Intelligence, highlight the ongoing security challenges within the WordPress ecosystem.
Critical vulnerabilities have been disclosed in several other network devices and software. This includes an OS command injection vulnerability in 4MOSAn GCB Doctor (CVE-2026-78211), a stack-based buffer overflow in Netis NC63 firmware up to V3.0.0.3327 (CVE-2026-76071), and a vulnerability in UTT HiPER 1250GW up to 3.2.7-210907-180535 impacting its HTTP Request Handler (CVE-2026-78169). Additionally, improper authentication in EFM ipTIME T24000M up to 14.20.0 (CVE-2026-78168), privilege escalation in StackGres operator (CVE-2026-78155), and command injection in Comfast CF-N1-S 2.6.0.1 (CVE-2026-78050) have been reported. Finally, a vulnerability in the AWS Neptune connector could allow unauthorized access to Lambda properties (CVE-2026-77810).