Critical Flaws Found in Samba, Dell, ServiceNow, Poly Voice
Critical vulnerabilities disclosed in Samba, Dell PowerStore, ServiceNow, and Poly Voice products pose significant risks, including remote code execution and data breaches.

A critical vulnerability in Samba, CVE-2025-10230, allows for remote code execution due to improper handling of NetBIOS names in WINS registration packets. This flaw enables attackers to inject commands by exploiting the lack of validation and escaping, potentially leading to system compromise. The vulnerability affects Samba software and requires immediate attention due to its high severity and potential impact on network services.
Dell PowerStore is facing multiple critical vulnerabilities, including CVE-2026-58574 and CVE-2026-67271. CVE-2026-58574, a Missing Authentication for Critical Function flaw, could allow unauthenticated attackers to read system information. CVE-2026-67271, an Out-of-bounds Write in SMB/CIFS, could lead to denial of service and remote code execution. Both vulnerabilities pose significant risks to data security and system integrity.
Poly Voice products are vulnerable to remote code execution via a buffer overflow flaw, CVE-2026-0826, when Interactive Connectivity Establishment (ICE) is enabled. This critical vulnerability, detailed by Rapid7, affects Linux-based Polycom devices and could allow unauthenticated attackers to gain control of affected systems.
ServiceNow has addressed three critical vulnerabilities, including CVE-2026-6876, which could permit unauthenticated users to execute arbitrary code within the Now Platform. As reported by The Hacker News, these flaws pose a severe risk, potentially leading to extensive system access and data breaches. Organizations using ServiceNow are urged to apply patches immediately.
A critical arbitrary code execution vulnerability exists in the Whirlpool hash implementation of openssl_encrypt versions prior to 1.4.0 (CVE-2026-74872). The flaw stems from the use of broad glob patterns to load .so modules without integrity verification, allowing attackers to introduce malicious modules and execute arbitrary code. This impacts systems relying on this specific version of openssl_encrypt for cryptographic operations.
Zte devices are susceptible to command injection vulnerabilities (CVE-2026-49003) that allow attackers to delete critical system files, crash monitoring modules, and gain root privileges. This could lead to system paralysis and the theft of sensitive configuration passwords, severely compromising the security and operational integrity of Zte equipment.
Google Chrome versions prior to 152.0.7977.65 contain two vulnerabilities, CVE-2026-79148 and CVE-2026-79058. CVE-2026-79148, an off-by-one error in DevTools, could allow remote attackers to read memory within the sandbox via social engineering. CVE-2026-79058, a missing authorization flaw in Passwords, could enable attackers who compromised the renderer process to spoof UI elements. While Chromium security severity is rated low, these could still be leveraged in targeted attacks.
Multiple critical vulnerabilities have been identified in Oracle Commerce Guided Search and Experience Manager (CVE-2026-71026, CVE-2026-70979, CVE-2026-70978, CVE-2026-70977, CVE-2026-70976). These flaws, affecting version 11.4.0, are easily exploitable and could lead to significant security breaches within Oracle Commerce environments.
The Super Store Finder WordPress plugin versions before 7.11 contain a SQL injection vulnerability (CVE-2026-12965). Unauthenticated attackers can exploit this flaw by manipulating an unauthenticated AJAX action parameter, allowing them to extract sensitive data from the database. This poses a direct threat to website data integrity and user privacy.
Quarkusio's Qute template engine has a vulnerability (CVE-2026-12894) in its ReflectionValueResolver, which fails to properly handle data lookups. This could lead to security issues when generating dynamic content like HTML pages or emails. Additionally, Quarkus OIDC has a cross-tenant authentication bypass vulnerability (CVE-2026-19625) via a shared token-introspection cache, allowing unauthorized access between tenants.