VYPR
AI Brief2026-09-03· generated Sep 2, 2026

What you need to know today.

Critical vulnerabilities disclosed in HPE, ServiceNow, Adobe, and multiple WordPress plugins allow unauthenticated attackers code execution and system compromise.

Critical vulnerabilities in HPE Networking Fabric Composer could allow unauthenticated remote attackers to gain administrative access or bypass authentication controls. These flaws, including CVE-2026-76658 and CVE-2026-76657, pose a significant risk to organizations using HPE's network management solutions, potentially leading to complete system compromise. As reported by Cyber Security News, exploitation could result in attackers taking over affected systems.

ServiceNow has addressed a cluster of critical vulnerabilities within its AI platform, detailed in CVE-2026-18885, CVE-2026-18886, CVE-2026-6876, and CVE-2026-74820. These flaws could permit unauthenticated users to execute arbitrary SQL statements, escape sandboxes to run code, or inject code, leading to data breaches and system control. Multiple outlets, including GovInfoSecurity and SecurityWeek, highlighted these patches, emphasizing the potential for attackers to execute code and access sensitive data.

Adobe Campaign Classic (ACC) is facing multiple critical vulnerabilities, CVE-2026-76197, CVE-2026-76195, and CVE-2026-76193, that could lead to arbitrary code execution. These OS command injection and Server-Side Request Forgery (SSRF) flaws allow attackers to compromise the software in the context of the current user. Cyber Security News reported that these vulnerabilities could enable attackers to execute arbitrary code, underscoring the urgency for users to update their ACC installations.

Several WordPress plugins are affected by critical vulnerabilities, including unauthenticated arbitrary file uploads in the Embed HTML5 Game plugin (CVE-2026-4357) and the Developer Tools plugin (CVE-2025-9314). Additionally, vulnerabilities in Hash Form (CVE-2026-81780), Newspapers X (CVE-2026-81779), WP Legal Pages (CVE-2026-82970), WatchMan-Site7 (CVE-2026-77009), Authorizer (CVE-2026-81294), and SigmaForms Pro (CVE-2026-78657) allow for code execution, malicious software implantation, or privilege escalation. These widespread issues highlight the ongoing risks associated with popular content management systems and their extensions.

A critical command injection vulnerability in QVidium Technologies' Opera11 CGI script (CVE-2026-82971) allows unauthenticated attackers to manipulate the 'ipaddr' argument to execute arbitrary commands on affected systems. This flaw in the /cgi-bin/net_tr.cgi component poses a significant risk for devices running this software, potentially leading to full system compromise.

The Wapt Server is vulnerable to a security restriction bypass (CVE-2026-33591) that allows remote, unauthenticated attackers to obtain valid session tokens by sending specially crafted packets. This could enable unauthorized access to user accounts and sensitive information within the Wapt environment.

Ozols Grupa OZOLS on Windows has a critical vulnerability (CVE-2026-22306) related to its auto-update mechanism, which involves downloading code without integrity checks, using untrusted sources, and transmitting sensitive information in cleartext. This could allow attackers to compromise systems through a manipulated update process.

Synthesized by Vypr AI
HPE, ServiceNow, Adobe, WordPress Face Critical Vulnerabilities · VYPR