What you need to know today.
Cisco faces multiple actively exploited critical vulnerabilities, while Google Pixel devices are targeted by a modem flaw, driving urgent patching and KEV catalog additions.

Cisco is grappling with multiple critical vulnerabilities, including CVE-2026-20079, a flaw in Secure Firewall Management Center (FMC) that allows unauthenticated attackers to gain root access. This vulnerability has been actively exploited by both nation-state actors and ransomware groups, including Sandworm and Qilin, for credential theft and malware deployment. Cisco has released patches and urges immediate application. As The Hacker News reported, exploitation has been ongoing, with Cisco Talos Intelligence confirming active exploitation.
Another critical vulnerability, CVE-2026-76460, affecting Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), is also being actively exploited. This flaw allows unauthenticated remote attackers to bypass authentication and gain administrative access. CISA has added this to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch by a specific deadline. Multiple news outlets, including CyberScoop and The Register, have covered the urgency of this advisory.
Google Pixel devices are targeted by CVE-2026-58704, a critical vulnerability in the cellular modem that allows for privilege escalation with no user interaction required. This flaw has been observed in targeted attacks and is now listed on the CISA KEV catalog. The Hacker News and Malwarebytes Labs have detailed the implications and the need for patching.
Critical vulnerabilities have also been disclosed in Arista EOS (CVE-2026-73456, CVE-2026-73453) and Dell ObjectScale (CVE-2026-70416). The Arista flaws allow for arbitrary code execution via gRPC Network Packet Sampling Interface (gNPSI) and P4Runtime, respectively, while the Dell vulnerability involves deserialization of untrusted data, leading to remote code execution. Both are rated critical and exploitable by unauthenticated attackers.
A significant number of critical vulnerabilities are present in various Oracle Fusion Middleware products, including Oracle Hyperion Financial Management (CVE-2026-87230), Oracle Forms (CVE-2026-83099), Oracle Internet Directory (CVE-2026-83059), Oracle WebLogic Server (CVE-2026-83021), Oracle Platform Security for Java (CVE-2026-83020), and Oracle Access Manager (CVE-2026-71133). These vulnerabilities are easily exploitable by unauthenticated network attackers and could lead to various impacts, including remote code execution and unauthorized access.
The vm2 JavaScript sandbox has critical vulnerabilities (CVE-2026-92953, CVE-2026-92937) that allow attackers to escape the sandbox and execute code in the host Node.js process. These flaws stem from incomplete fixes for previously identified issues and pose a significant risk to applications relying on vm2 for sandboxing.
Altium Enterprise Server is affected by CVE-2026-92808, a critical server-side request forgery (SSRF) vulnerability in its UnifiedLogin service. This allows unauthenticated network attackers to compel the server to make arbitrary outbound HTTP requests, potentially leading to further system compromise. ASUS Control Center also has critical vulnerabilities including missing authentication and SSRF (CVE-2026-75754).