What you need to know today.
Critical flaws in Adobe Campaign Classic, WordPress plugins, and network devices demand immediate attention, alongside patches for Microsoft Edge.

Multiple critical vulnerabilities have been disclosed in Adobe Campaign Classic (ACC), including OS Command Injection flaws (CVE-2026-76197, CVE-2026-76195) and Server-Side Request Forgery (CVE-2026-76193). These vulnerabilities could allow attackers to execute arbitrary code in the context of the current user. Adobe has released patches to address these issues, and users are strongly advised to update their ACC installations immediately. As Cyber Security News reported, these flaws pose a significant risk to organizations using ACC.
A wave of critical vulnerabilities has been identified across several WordPress plugins, with a particular focus on authentication bypass and privilege escalation. CVE-2026-15980 in the MyHome Core plugin allows for authentication bypass due to missing authorization checks. Similarly, CVE-2026-15369 in Custom User Registration Fields for WooCommerce and CVE-2026-16259 in Uix UserCenter plugin enable privilege escalation and unauthorized account modification, respectively. Additionally, CVE-2026-77012 in the 爱采集数据采集和发布插件 plugin presents risks due to reliance on hardcoded defaults and improper path validation. Vypr Intelligence highlighted these as critical, urging users to update affected plugins.
Critical vulnerabilities have been found in Tenda and Totolink network devices, specifically in their web server components. CVE-2026-82542 in Tenda HG10 allows for buffer overflows via manipulation of the destNet argument in the formIPv6Routing function. Totolink's A720R is affected by CVE-2026-82539, a memory corruption vulnerability stemming from manipulation of the desc argument in the setMacFilterRules function. These flaws could lead to device compromise and network instability. Users of these devices should check for firmware updates from the vendors.
Microsoft has patched a critical type confusion vulnerability in Microsoft Edge (Chromium-based) tracked as CVE-2026-72984. This flaw allows an unauthorized attacker to execute code remotely over a network. While details are scarce, the severity indicates a significant risk. Vypr Intelligence noted this as part of a larger batch of patches for Edge. Users are urged to ensure their Edge browsers are up to date.
Several other high-severity vulnerabilities have been disclosed, including a directory traversal in Coderaiser Cloud Commander (CVE-2026-82460), credential exposure in WWBN AVideo (CVE-2026-82645), SQL injection in WordPress Rest Routes plugin (CVE-2026-16061), authorization bypass in IFlytek astron-agent (CVE-2026-82475), and unauthenticated node task reporting in KubeEdge CloudCore (CVE-2026-82473). Additionally, Siyuan Note versions prior to v3.8.1 contain stored cross-site scripting vulnerabilities (CVE-2026-82654, CVE-2026-82653) that could lead to code execution when viewing documents. Patches and updates are available for most of these issues.