VYPR
AI Brief2026-08-27· generated Aug 27, 2026

Critical Flaws Hit Adobe, Joomla, WordPress; Supply-Chain Attacks Reported

Critical vulnerabilities disclosed in Adobe Campaign Classic, multiple Joomla extensions, and WordPress plugins, alongside supply-chain attacks and SQL injection flaws.

Multiple Joomla extensions are affected by a wave of critical vulnerabilities, with Fabrikar's Fabrik component being particularly hard-hit. CVE-2026-67282, CVE-2026-66915, and CVE-2026-67364 all detail remote code execution flaws, with some allowing unauthenticated attackers to achieve this via various components like the frontend listfilter model or the calc plugin's ajax_calc feature. Other Joomla extensions also suffer from critical issues, including arbitrary account takeover in miniOrange OAuth Client (CVE-2026-77995), path traversal and arbitrary file upload/deletion in J-BusinessDirectory (CVE-2026-75949), and unauthenticated arbitrary file uploads in Yootheme's Zoo (CVE-2026-74803). These vulnerabilities collectively expose a significant attack surface for Joomla sites.

Critical vulnerabilities have been disclosed in Adobe Campaign Classic (ACC), with CVE-2026-76197 and CVE-2026-76195 both detailing OS command injection flaws. These vulnerabilities could allow an attacker to execute arbitrary code in the context of the current user, posing a significant risk to organizations using ACC. As Cyber Security News reported, these flaws underscore the need for prompt patching of Adobe products.

The WordPress ecosystem is facing several critical vulnerabilities. The W3 Total Cache plugin is affected by CVE-2026-18051, which allows unauthenticated attackers to write files to any directory on the server due to improper request path validation. Additionally, the Link Factory plugin has been identified as a backdoor (CVE-2026-15413), exposing a REST API that can be authenticated via a detached Ed25519 signature. The Premium SEO plugin also contains a backdoor, enabling administrator account creation and potentially remote code execution (CVE-2026-14812). These findings were highlighted in the Wordfence Blog and The Hacker News.

A critical SQL injection vulnerability has been found in Siyuan Note versions up to v3.7.2 (CVE-2026-72811). The flaw exists in the backlink/mention search query, where user-supplied keywords are concatenated with stored block metadata without proper sanitization, allowing attackers to inject arbitrary SQL commands. Vypr Intelligence reported on this and other vulnerabilities affecting Siyuan Note.

The official MonsterInsights Pro update distribution channel was compromised, with malicious code found in versions 10.2.2 and 10.2.0 of the plugin (CVE-2026-11976). This supply-chain attack inserted a malicious file, class-sy, into the update process, potentially compromising users who updated their plugins during the affected period.

Metabase versions are vulnerable to SQL injection via publicly shared card or dashboard field-filter parameters (CVE-2026-72899). This allows unauthenticated attackers to inject arbitrary SQL, potentially leading to data breaches or system compromise.

A critical OS command injection vulnerability exists in TOTOLINK N600R firmware version 4.3.0cu.7647_B20210106 (CVE-2026-79911). The vulnerability lies within the setSystemConfig function in the /cgi-bin/cstecgi.cgi component, allowing manipulation of the Hostname argument to achieve code execution.

Joomla extensions from Regular Labs are affected by CVE-2026-74253, an unauthenticated remote code execution vulnerability in Sourcerer versions prior to 16.0.0. The extension improperly processes {source} blocks in rendered HTML, enabling attackers to inject and execute arbitrary code.

Synthesized by Vypr AI