What you need to know today.
Actively Exploited Flaws Hit Cisco, Citrix, Fortinet, Chrome, and cPanel; Urgent Patching Advised.

Cisco's Secure Firewall Management Center (FMC) is facing active exploitation due to a critical authentication bypass vulnerability, CVE-2026-20079. This flaw allows unauthenticated, remote attackers to execute script files and gain root access. The vulnerability has been exploited by nation-state actors and ransomware groups, as reported by Help Net Security. Cisco Talos Intelligence also noted ongoing exploitation in their blog posts here and here. Organizations are warned to patch immediately, as detailed by SecurityWeek.
A critical vulnerability in Citrix NetScaler ADC and Gateway, CVE-2026-19490, is being actively exploited and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This authentication bypass flaw allows attackers to gain unauthorized access. Cyber Security News and SecurityWeek reported on the exploitation, with Help Net Security urging customers to apply fixes. The vulnerability affects multiple versions of NetScaler ADC and Gateway.
Fortinet FortiOS and FortiSwitchManager are affected by a heap-based buffer overflow vulnerability, CVE-2025-25249, which is under active exploitation and has been added to the CISA KEV catalog. This critical flaw has been observed in attacks deploying custom Node.js malware and PivotC2 RATs, as detailed by Cyber Security News and SecurityWeek. The vulnerability impacts a wide range of FortiOS versions from 6.4 through 7.6.
Google Chrome users are urged to update to version 153.0.8010.36 immediately due to an actively exploited zero-day vulnerability, CVE-2026-87491. This out-of-bounds write in the V8 JavaScript engine allows remote attackers to execute arbitrary code within the Chrome sandbox via a crafted HTML page. Malwarebytes Labs and The Hacker News highlight the urgency of patching this vulnerability, which is the seventh zero-day exploited in the wild this year for Chrome. Chinese espionage groups have been observed chaining this exploit with other vulnerabilities.
A critical SQL injection vulnerability in the cPanel EmailTrack component, CVE-2026-67401, allows a mail-enabled account to achieve remote code execution as root. This means an attacker with a compromised mail account could gain full control of the server. The Hacker News and Cyber Security News reported on this severe flaw, emphasizing the high risk to hosting environments.
VMware's Zimbra Collaboration (ZCS) versions 8.8.15 and 9.0 are vulnerable to arbitrary file uploads via amavis due to a cpio loophole, identified as CVE-2022-41352. This critical vulnerability allows attackers to upload files to specific web directories, potentially leading to unauthorized access or further compromise.
Adobe Flash Player versions 21.0.0.226 and earlier are affected by CVE-2016-4117, a critical remote code execution vulnerability that was actively exploited in the wild in May 2016.
Microsoft Windows has several vulnerabilities, including CVE-2016-7255, a privilege escalation flaw in kernel-mode drivers affecting multiple Windows versions, and CVE-2022-37969, an elevation of privilege vulnerability in the Common Log File System Driver.
Other critical vulnerabilities include an out-of-bounds write in Google Chrome's V8 engine (CVE-2026-87491), an SQL injection flaw in GIS Informatics GisLab Laboratory Management System (CVE-2026-9163), and a hardcoded session encryption key in MaxSite CMS (CVE-2026-87929). Additionally, vulnerabilities in WordPress plugins (CVE-2026-77770), MicroXR Blobstore (CVE-2026-28659), Streambert (CVE-2026-48056), and Armiya Information Technologies Ltd. Co. Access Control System (CVE-2026-7188) pose significant risks. CVE-2026-71805 in LZ-litchi allows arbitrary file uploads and path traversal. Actions Semiconductor Co. Ltd Tool- Media Player Utilities has a vulnerability (CVE-2026-36433) allowing code execution. Traefik's Kubernetes ingress-nginx provider has a mishandling issue (CVE-2026-88877). GeoVision GV-LPC2211 has a replay vulnerability (CVE-2026-88278). CVE-2026-49883 in Google's PermissionsManager.java allows local information disclosure. CVE-2025-25249 affects Fortinet devices.