VYPR
AI Brief2026-09-03· generated Sep 3, 2026

Critical Vulnerabilities Hit HPE, ServiceNow, Adobe, and WordPress

Critical flaws in HPE, ServiceNow, Adobe, and multiple WordPress plugins pose significant risks, including remote code execution and administrative access.

HPE Fabric Composer is facing multiple critical vulnerabilities, including CVE-2026-76658 which allows unauthenticated remote attackers to gain administrative access via the SSH daemon, and CVE-2026-76657 enabling circumvention of authentication controls through API manipulation. These flaws could lead to complete system compromise. HPE has not yet released specific patches, but users are advised to consult HPE security advisories for mitigation steps. Cyber Security News reported on these critical vulnerabilities.

ServiceNow's AI platform is affected by three critical vulnerabilities, detailed in reports from GovInfoSecurity, SecurityWeek, and Cyber Security News. CVE-2026-18885 involves a code injection flaw, CVE-2026-6876 a sandbox escape, and CVE-2026-74820 a SQL injection vulnerability. All three allow unauthenticated attackers to execute arbitrary code or SQL statements, potentially leading to data breaches and system control. ServiceNow has remediated these issues, and users should ensure their platforms are updated.

Adobe Campaign Classic (ACC) is grappling with several critical vulnerabilities, including CVE-2026-76197, CVE-2026-76195, and CVE-2026-76193, all of which could result in arbitrary code execution. These flaws stem from improper neutralization of OS command elements and Server-Side Request Forgery (SSRF). Exploitation could allow attackers to compromise the application in the context of the current user. Vypr Intelligence and Cyber Security News have highlighted these risks. Users are urged to apply the latest patches provided by Adobe.

A significant number of WordPress plugins are affected by critical vulnerabilities, as detailed by Vypr Intelligence. Among these, CVE-2026-4357 in the Embed HTML5 Game plugin allows unauthenticated attackers to upload PHP backdoors. Additionally, CVE-2025-9314 in the Developer Tools plugin presents an unauthenticated arbitrary file upload risk, and CVE-2026-77009 in the WatchMan-Site7 plugin permits authenticated users to execute arbitrary code via a debugging console. Users should update these plugins immediately to mitigate these threats.

Multiple critical vulnerabilities have been disclosed in various WordPress plugins, including CVE-2026-81780 (Hash Form - unauthenticated arbitrary file upload), CVE-2026-81779 (Newspapers X - malicious software implantation), CVE-2026-82970 (WP Legal Pages WP Cookie Notice - malicious file upload), CVE-2026-81294 (Authorizer - unauthenticated privilege escalation), CVE-2026-78657 (SigmaForms Pro - arbitrary file deletion), and CVE-2026-9055 (Amelia Premium - privilege escalation). These vulnerabilities pose significant risks, ranging from unauthorized file uploads and deletions to privilege escalation and code execution. Prompt updates to the affected plugins are essential.

QVidium Technologies' Opera11 component, specifically the CGI script /cgi-bin/net_tr.cgi, is vulnerable to command injection via manipulation of the 'ipaddr' argument (CVE-2026-82971). This critical flaw could allow an attacker to execute arbitrary commands on the affected system. Further details on exploitation and mitigation are scarce, but users are advised to restrict access to the affected CGI script and monitor for suspicious activity.

The Wapt Server is vulnerable to security restrictions bypass via a specially crafted packet (CVE-2026-33591), allowing unauthenticated remote attackers to retrieve valid session tokens. This could lead to account takeover. Versions prior to 2.6.1.17813 are affected. Users should update to the latest version to patch this vulnerability.

Ozols Grupa OZOLS on Windows has a critical vulnerability (CVE-2026-22306) related to an abandoned auto-update domain, which could lead to download of unverified code, inclusion of untrusted functionality, and cleartext transmission of sensitive information. Users should investigate the auto-update mechanism and ensure its integrity or disable it if compromised.

Adobe Campaign Classic (ACC) is also affected by a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-76193), which could lead to arbitrary code execution in the context of the current user. Attackers can exploit this to execute arbitrary code by tricking the application into making requests to unintended locations. This is in addition to the OS command injection flaws noted previously.

Adobe Campaign Classic (ACC) is affected by an OS Command Injection vulnerability (CVE-2026-76195), allowing arbitrary code execution in the context of the current user. This is due to improper neutralization of special elements used in OS commands. This is one of multiple critical vulnerabilities affecting ACC.

Synthesized by Vypr AI