Critical Flaws Hit Adobe, WordPress, and Network Devices
Critical flaws in Adobe Campaign Classic, WordPress plugins, and Siyuan Note allow code execution and data compromise, while network devices and Edge are also impacted.

Adobe Campaign Classic is facing a critical wave of vulnerabilities, with CVE-2026-76197, CVE-2026-76195, and CVE-2026-76193 allowing for arbitrary code execution through OS command injection and server-side request forgery. These flaws, detailed in reports by Vypr Intelligence and Cyber Security News, pose a significant risk due to their critical severity and potential for deep system compromise. The exact versions affected are not specified, but the potential impact is high, necessitating immediate attention from administrators.
WordPress plugins are once again a target, with multiple critical vulnerabilities disclosed. CVE-2026-15980 and CVE-2026-15369 present authentication bypass and privilege escalation risks, respectively. Additionally, CVE-2026-77012 and CVE-2026-16947 introduce risks of arbitrary code execution and path traversal. These flaws, highlighted by Vypr Intelligence, affect various plugins including MyHome Core, Custom User Registration Fields for WooCommerce, and Total processing card payments for WooCommerce, underscoring the need for diligent plugin management and timely updates.
Siyuan Note versions prior to v3.8.1 are vulnerable to stored cross-site scripting (XSS) and path traversal attacks, as detailed by Vypr Intelligence. CVE-2026-82653 and CVE-2026-82654 allow attackers to inject malicious script tags into documents, which can be executed when viewed by other users, and to traverse directories to access sensitive files. These vulnerabilities, stemming from improper escaping of block names and aliases, pose a significant risk to user data and system integrity.
Critical vulnerabilities have been found in Tenda and Totolink network devices. CVE-2026-82542 in Tenda HG10 involves a buffer overflow in the Boa Web Server component due to manipulation of IPv6 routing arguments, potentially leading to code execution. Similarly, CVE-2026-82539 in Totolink A720R affects the MAC Filtering component, where manipulation of arguments can lead to memory corruption. These flaws highlight the ongoing risks associated with embedded device security.
Microsoft Edge (Chromium-based) has a high-severity 'type confusion' vulnerability, CVE-2026-72984, which could allow an unauthorized attacker to execute code over a network. This is part of a batch of seven CVEs patched by Microsoft, as reported by Vypr Intelligence. While the specific attack vector is not detailed, type confusion bugs are often complex and can lead to significant system compromise.
WWBN AVideo versions prior to the latest commit are affected by CVE-2026-82645, which exposes stream credentials through a specific API endpoint. This vulnerability allows bypassing access controls by supplying a 'token' parameter, potentially leading to unauthorized access and control of live streams. Vypr Intelligence noted this alongside other vulnerabilities in AVideo.
Cloud Commander versions before 19.20.2 contain a directory traversal vulnerability in its REST file-operation and markdown endpoints. CVE-2026-82460 allows attackers to read, write, move, or delete files by exploiting improper path normalization, posing a significant risk to data integrity and confidentiality.
Qubes OS before qubes-core-dom0-linux 4.3.22 has a vulnerability, CVE-2026-82636, that could lead to OS command injection. This occurs during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, as a system library function processes an error message that may contain shell metacharacters.
Readest, an open-source e-book reader, has a vulnerability in versions prior to 0.11.16, CVE-2026-82642. The EPUB chapter HTML sanitization was misconfigured, allowing script tags to be executed, which could lead to cross-site scripting attacks.
The Linux Foundation's Magma component has a vulnerability, CVE-2026-82549, related to improper validation of an integrity check value. This could potentially be exploited to launch attacks, though further details on the specific impact are limited.
The Rest Routes WordPress plugin through version 5.5.5 is affected by CVE-2026-16061, a SQL injection vulnerability that can be exploited by unauthenticated attackers due to a lack of sanitization and validation of URL parameters used in SQL queries.
The User Profile Builder WordPress plugin before version 4.0.1 has a vulnerability, CVE-2026-76548, where its front-end file upload feature does not properly restrict access, allowing unauthenticated visitors to perform actions reserved for privileged roles, including listing the site's media library.