What you need to know today.
Critical RCEs in Poly Voice phones and Dell PowerStore, alongside multiple Oracle Commerce flaws, highlight today's major security concerns.

A critical buffer overflow vulnerability in Poly Voice products on the Linux platform could allow remote code execution when Interactive Connectivity Establishment (ICE) is enabled. This impacts Polycom devices and is a significant concern for enterprise networks. The exact versions affected are not specified, but users should consult vendor advisories for patching information. CVE-2026-0826 was highlighted in several security outlets, including The Hacker News and SecurityWeek, underscoring its potential impact.
Dell PowerStore is affected by multiple critical vulnerabilities. CVE-2026-58574, a Missing Authentication for Critical Function flaw, could allow an unauthenticated attacker with network access to the management interface to read system information. Additionally, CVE-2026-67271, an Out-of-bounds Write in SMB/CIFS, could lead to denial of service and remote execution for unauthenticated attackers with remote access. These vulnerabilities pose a serious risk to data security and system integrity on Dell PowerStore appliances.
Multiple critical vulnerabilities have been disclosed in Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically affecting version 11.4.0. These include issues in the Endeca Application Controller (CVE-2026-71026) and the Content Acquisition System (CVE-2026-70979, CVE-2026-70978, CVE-2026-70977, CVE-2026-70976). These easily exploitable vulnerabilities could lead to significant security breaches within Oracle Commerce deployments.
A critical arbitrary code execution vulnerability exists in openssl_encrypt versions before 1.4.0 due to the use of broad glob patterns for loading .so modules without integrity verification. This allows attackers to place malicious .so files and execute arbitrary code. CVE-2026-74872 highlights a severe supply-chain risk, as it affects the integrity of software dependencies.
Critical command injection vulnerabilities in ZTE products allow attackers to delete core system runtime files, causing monitoring modules to crash and potentially leading to root privilege escalation for credential theft. CVE-2026-49003 indicates a severe risk for systems relying on ZTE devices, potentially leading to complete system compromise and data exfiltration.
A critical SQL injection vulnerability in the WordPress plugin "Super Store Finder" before version 7.11 allows unauthenticated attackers to extract data from the database by exploiting a lack of sanitization in an AJAX action parameter. CVE-2026-12965 poses a direct threat to e-commerce sites using this plugin, potentially exposing sensitive customer and business data.
Google Chrome versions prior to 152.0.7977.65 contain vulnerabilities that, while rated low by Chromium security, could have significant implications. CVE-2026-79148, an off-by-one error in DevTools, could allow a remote attacker leveraging social engineering to read memory within the sandbox via a crafted extension. CVE-2026-79058 involves missing authorization in the Passwords feature, enabling a compromised renderer process to spoof UI elements.
A critical vulnerability in Samba (CVE-2025-10230) allows for remote code execution due to improper handling of NetBIOS names in WINS registration packets, which are passed to a shell without proper validation. This flaw in front-end WINS hook handling poses a significant risk to systems running vulnerable Samba versions.
The Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS has a critical OS command injection vulnerability (CVE-2026-59111) that can be exploited by registering a custom URL scheme, potentially leading to unauthorized actions or system access.
A critical Type Confusion vulnerability in themrdemonized xray-monolith before version 2025.12.30 (CVE-2026-24874) could allow attackers to exploit memory access issues, potentially leading to code execution or denial of service.
A critical vulnerability in Golang (CVE-2026-46595), related to a previous fix for SSH server configurations, could allow an authorization bypass if callbacks other than public key are used, skipping source-address validation.
A high-severity SQL injection vulnerability in Ankara Hosting Site Management Panel through version 15062026 (CVE-2026-5956) allows attackers to manipulate SQL queries, potentially leading to data theft or unauthorized access.
A flaw in the Qute template engine used by Quarkus (CVE-2026-12894) affects how data values are looked up, potentially leading to security issues in dynamically generated content like HTML pages or emails. The exact impact depends on how the engine is used within Quarkus applications.