What you need to know today.
Critical vulnerabilities in SonicWall, Zyxel, and Apple products are actively exploited, alongside numerous critical flaws in routers and enterprise software.
A critical vulnerability in SonicWall SonicOS (CVE-2024-40766) allows for unauthorized resource access and potential firewall crashes due to improper access control in the management interface. While patches are available, misconfigurations may leave systems exposed, as noted by SANS ISC. This flaw has been linked to ransomware tactics, techniques, and procedures, highlighting its potential impact on network security infrastructure. The vulnerability could also be chained with other exploits, as seen in the exploitation of SonicWall SMA 1000 zero-days.
Zyxel GS1900 series switches are facing active exploitation due to a stack-based buffer overflow vulnerability (CVE-2026-7273) in their CGI program. This allows unauthenticated LAN-based attackers to execute OS commands. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, with reports indicating that Chinese hackers have been exploiting it since August, compromising nearly 1000 switches. The Hacker News and SecurityWeek have reported on the active exploitation and the potential for command and SYSTEM access.
Apple's Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS are affected by multiple vulnerabilities, including a use-after-free issue (CVE-2023-43000) and memory corruption flaws (CVE-2025-31277). These issues, addressed in recent updates, could be triggered by processing maliciously crafted web content. The Dark Reading and Cyber Security News outlets have highlighted the proliferation of exploits targeting these platforms, with some being linked to the DarkSword iOS exploit chain adopted by various threat actors.
Critical vulnerabilities have been disclosed in Dell ObjectScale versions prior to 4.4.0.0, including a deserialization of untrusted data flaw (CVE-2026-70416) that could lead to remote code execution. The Hacker News and Cyber Security News have reported on these critical flaws, emphasizing the potential for attackers to compromise affected systems.
Several critical vulnerabilities have been identified in Totolink routers, including command injection (CVE-2026-93742) and buffer overflow vulnerabilities (CVE-2026-93741, CVE-2026-93738) in models like the A3002MU. These flaws affect various functions, including web administration and wireless settings, and can be exploited through manipulation of specific arguments.
Netcore NBR200V2 routers are susceptible to critical vulnerabilities, including command injection in the WAN VLAN reconfiguration component (CVE-2026-94100) and issues in the backup restore functionality (CVE-2026-94099) and traceroute diagnostic feature (CVE-2026-94095). These flaws allow for potential system compromise through manipulation of various configuration parameters.
Oracle Access Manager (Fusion Middleware component: Authentication Engine) versions 12.2.1.4.0 and 14.1.2.1.0 contain an easily exploitable vulnerability (CVE-2026-71133) that allows unauthenticated attackers to gain unauthorized access.
MongoDB, specifically the Mongoid component, has a weakness (CVE-2026-93762) in its query path for embedded documents. This could allow unauthenticated parties to obtain unintended information by passing externally supplied field names to certain in-memory query methods.
CareCam CM2507 IP cameras store the root password with a fixed, weak hash (CVE-2026-85497), making it susceptible to offline cracking. CISA has issued an advisory for this vulnerability.
Multiple critical vulnerabilities have been identified and remediated within HP's HPLIP software (CVE-2026-91106, CVE-2026-91105, CVE-2026-91104, CVE-2026-91103, CVE-2026-91102), with potential impacts including remote code execution, privilege escalation, and denial of service.