What you need to know today.
Mikrotik routers are actively exploited via two critical KEV vulnerabilities, while Tenda, IBM Langflow, and Plesk face RCE and privilege escalation risks.

Two critical vulnerabilities in Mikrotik RouterOS have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. CVE-2026-86060, a critical flaw with a CVSS score of 9.8, allows privilege escalation by manipulating argument handling in the SSH login path. Exploitation requires usernames beginning with a prohibited character, enabling attackers to alter the RouterOS policy mask. Additionally, CVE-2026-67277, a high-severity vulnerability (CVSS 8.2), permits unauthenticated clients to initiate an IPv4 UDP test by exploiting a state where RouterOS accepts a "related" btest connection before primary session authentication is complete. This could lead to data transmission with specific configurations, as reported by Vypr Intelligence and SecurityWeek.
Tenda devices are facing a significant security threat with the disclosure of multiple vulnerabilities, including a critical command injection flaw. CVE-2026-86152, a critical vulnerability in Tenda CP3 devices, allows for OS command injection via manipulation of the CAutoAddWifi::ThreadProc function. This could enable attackers to execute arbitrary commands on the affected devices. The vulnerability, detailed by Vypr Intelligence, underscores the risks associated with insecure handling of network traffic and device configurations.
A series of critical vulnerabilities have been identified across various IBM Langflow OSS versions, potentially allowing for remote code execution and unauthorized access. CVE-2026-81204 and CVE-2026-85025, both critical flaws with CVSS 9.8, enable remote attackers to execute arbitrary code or access/modify chat sessions through publicly shared project endpoints due to improper security enforcement. Another critical vulnerability, CVE-2026-79724, specifically targets improper neutralization of special elements used in OS commands, potentially leading to arbitrary OS command execution. These flaws highlight the risks associated with insecure code handling and inadequate access controls in the Langflow platform.
Critical vulnerabilities affecting Plesk's Backup Manager and symlink handling could lead to significant security breaches. CVE-2026-68487, a critical path traversal vulnerability, allows authenticated customers to write arbitrary files as root. Complementing this, CVE-2026-68488, a critical TOCTOU race condition, enables local privilege escalation to root through insecure symlink following and arbitrary file/directory ownership takeover. These vulnerabilities present a severe risk to Plesk environments, potentially allowing attackers to gain complete control over the server.
Dell devices are vulnerable to critical security exploits, including OS command injection and insufficient data authenticity verification. CVE-2026-81467, a critical OS command injection vulnerability in Dell ThinOS, allows unauthenticated remote attackers to execute arbitrary commands. Similarly, CVE-2026-80172, a critical flaw in Dell SCG Appliance and Application versions, suffers from insufficient verification of data authenticity, potentially allowing remote attackers to exploit the system. As reported by Cyber Security News, these vulnerabilities pose a significant threat to Dell device security.
Forgejo, a code hosting platform, has a critical remote code execution vulnerability. CVE-2026-89094, affecting Forgejo versions before 16.0.4, allows for RCE due to mishandling of template expansion in .forgejo/template files. This could enable attackers to execute arbitrary code on the server hosting Forgejo, posing a severe risk to code repositories and associated infrastructure.
Critical vulnerabilities in Apache Nutch and Flowiseai could allow for remote code execution. CVE-2026-41871, a critical vulnerability in Apache Nutch Server's REST API, involves missing authorization and unsafe reflection, enabling attackers to execute arbitrary code. In Flowise 3.1.2, CVE-2026-52098, a critical flaw in the /api/v1/prediction/<flowId> endpoint, also permits remote code execution.
Samsung Mobile devices are susceptible to heap-based buffer overflows in their JPEG and DNG decoders. CVE-2026-21096 and CVE-2026-21095, both critical vulnerabilities in libimagecodec.quram.so prior to SMR Sep-2026 Release 1, allow remote attackers to execute arbitrary code by exploiting buffer overflows in image decoding processes.
Google Chrome on Android has a critical vulnerability related to missing authorization in WebView. CVE-2026-87534 allows remote attackers, through social engineering and crafted network traffic, to bypass system access restrictions. This could lead to unauthorized access or control over user data and device functions.
Adobe Experience Manager is affected by a critical incorrect authorization vulnerability. CVE-2026-19232 could result in arbitrary code execution in the context of the current user, potentially leading to elevated access or account compromise.
Android X86 has a critical privilege escalation vulnerability. CVE-2026-28606 allows for remote privilege escalation without user consent due to a logic error in the handleBondStateChanged function, potentially enabling attackers to gain unauthorized control over the device.