What you need to know today.
MonsterInsights Pro supply-chain attack and critical Joomla extension flaws lead today's security alerts.

A supply-chain attack targeting the official MonsterInsights Pro update distribution channel has been uncovered, with malicious files found in both version 10.2.2 and its rollback version 10.2.0. The compromised files include class-sy..., potentially leading to severe security risks for users who update their plugins. The exact nature and impact of the malicious code are still under investigation, but its presence in the official distribution is a significant concern for the WordPress ecosystem.
Multiple critical vulnerabilities have been disclosed in various Joomla extensions, with a significant number affecting Fabrikar's "Fabrik" extension. These include unauthenticated remote code execution (CVE-2026-67282, CVE-2026-66915), path traversal (CVE-2026-76606), missing ACL checks (CVE-2026-76607), and unauthenticated RCE via a PHP form element (CVE-2026-76604). Additionally, other Joomla extensions are affected by critical flaws such as arbitrary account takeover in miniOrange OAuth Client (CVE-2026-77995), arbitrary file upload/deletion in J-BusinessDirectory (CVE-2026-75949), unauthenticated arbitrary file upload in Zoo (CVE-2026-74803), and pre-auth PHP code injection in Balbooa Forms (CVE-2026-67364). These vulnerabilities collectively expose Joomla sites to a high risk of compromise.
Critical vulnerabilities have been disclosed in Adobe Campaign Classic (ACC), with two instances of OS Command Injection (CVE-2026-76197, CVE-2026-76195) allowing for arbitrary code execution in the context of the current user. This poses a significant risk to organizations using ACC, as it could lead to a full system compromise. Users are advised to update to patched versions as soon as possible.
A critical SQL injection vulnerability has been found in Siyuan Note versions up to v3.7.2 (CVE-2026-72811). The flaw exists in the backlink/mention search query, where user-supplied keywords are concatenated with stored block metadata without proper sanitization. This allows unauthenticated attackers to inject arbitrary SQL commands, potentially leading to data exfiltration or modification. As reported by Vypr Intelligence, Siyuan Note faces numerous vulnerabilities, including RCE and auth bypass.
The W3 Total Cache WordPress plugin, in versions prior to 2.10.5, contains a vulnerability that allows unauthenticated attackers to write files to any directory on the server (CVE-2026-18051). This path traversal vulnerability could be exploited to overwrite critical files or plant malicious ones, leading to website compromise. The Hacker News has also reported on related security news this week.
Metabase versions are affected by a critical SQL injection vulnerability (CVE-2026-72899) that can be exploited by unauthenticated attackers through publicly shared cards or dashboards with field-filter parameters. This allows for arbitrary SQL injection, potentially leading to data breaches.
Two WordPress plugins, Link Factory and Premium SEO, have been found to contain malicious backdoors. Link Factory (CVE-2026-15413) allows for an operator-controlled REST API authenticated by a detached Ed25519 signature, while Premium SEO (CVE-2026-14812) can create hidden administrator accounts and, in some builds, enable RCE, SSRF, and arbitrary front-end scripting. These findings highlight the risks associated with third-party WordPress plugins.
A critical OS Command Injection vulnerability (CVE-2026-79911) has been identified in TOTOLINK N600R routers, specifically in the CGI handler component. This flaw allows attackers to execute arbitrary commands on the affected devices, potentially leading to a full network compromise. Users of this router model should apply any available patches or consider replacing the device.