What you need to know today.
Critical flaws in Ubiquiti UniFi, ServiceNow, and WordPress plugins expose users to command injection, authentication bypass, and code execution risks.

A critical command injection vulnerability in UniFi Talk Application (CVE-2026-77554) and UniFi Protect Application (CVE-2026-77537) allows a network-accessible attacker to execute arbitrary commands on the host device. Additionally, a critical authentication bypass flaw in UniFi OS (CVE-2026-77550) enables unauthenticated access to devices. These issues, all with CVSS scores of 10.0, highlight significant security weaknesses across Ubiquiti's UniFi product line, as reported by CyberScoop and Cyber Security News.
ServiceNow's AI platform is affected by three critical vulnerabilities: SQL injection (CVE-2026-74820), improper access control (CVE-2026-18886), and code injection (CVE-2026-18885). These flaws, all rated Critical with CVSS scores, could allow unauthenticated attackers to execute arbitrary SQL statements, arbitrary code, or modify instance data. Cyber Security News and The Hacker News detail the risks, emphasizing the potential for unauthenticated code execution and data compromise.
Multiple critical vulnerabilities have been disclosed in WordPress plugins and core components. The WPMU DEV Dashboard plugin (CVE-2026-76581) suffers from an authentication bypass, while the Sigma Forms Pro plugin (CVE-14494) has a remote code execution flaw. These issues, detailed by The Hacker News and Wordfence Blog, pose significant risks to WordPress site security, potentially leading to full site takeovers.
Critical vulnerabilities are present in several other platforms, including Argoproj Labs' argocd-mcp (CVE-2026-82456), which binds its HTTP transport to all network interfaces and accepts unauthenticated MCP sessions. Siemens SIMATIC IoT2050 Advanced (CVE-2026-58115) does not enforce authentication on its Node-RED HTTP interface, allowing potential command execution. Microsoft Azure SQL Database (CVE-2026-69502) has a server-side request forgery flaw enabling privilege escalation, as noted by SecurityWeek.
IBM's Langflow OSS (versions 1.0.0 through 1.11.1) is impacted by two critical vulnerabilities: arbitrary OS command execution (CVE-2026-19295) when saving crafted flows, and arbitrary code execution (CVE-2026-19286) due to improper security enforcement on its A2A public endpoint. IBM Administration Runtime Expert for i (CVE-2026-18527) also has a critical vulnerability allowing privilege escalation through its GUI component.
Redpanda (through 26.2.2) exposes its Admin API on all interfaces without requiring authentication by default (CVE-2026-82266), allowing unauthenticated users to act as superusers for account management. Similarly, Argo Rollouts dashboard (through 1.10.0) binds to all interfaces and exposes mutating Rollout operations without authentication or authorization (CVE-2026-82277), enabling attackers on the same network to manipulate rollouts. SOY CMS (CVE-2026-78032) has a deserialization vulnerability that could lead to arbitrary code execution.