What you need to know today.
Apple zero-day exploited, GNU telnetd auth bypass, and critical Joomla extension flaws lead daily security updates.

A critical zero-day vulnerability in Apple's CoreGraphics framework, CVE-2026-86950, has been added to the CISA Known Exploited Vulnerabilities catalog. This flaw, which allows for arbitrary code execution, has reportedly been exploited in "extremely sophisticated" targeted attacks. The vulnerability was patched by Apple in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. Multiple security outlets, including The Hacker News and Infosecurity Magazine, have detailed the exploit and Apple's emergency patch.
A critical remote code execution vulnerability, CVE-2026-24061, has been identified in GNU telnetd within the GNU Inetutils package up to version 2.7. This flaw allows for authentication bypass by sending a specific "-f root" value for the USER environment variable, potentially enabling unauthenticated attackers to gain privileged access. Securelist and watchTowr Labs have published analyses of this vulnerability, highlighting its potential impact on systems running older versions of Inetutils.
Several critical vulnerabilities have been disclosed in various Joomla extensions, including unauthenticated remote code execution, SQL injection, and cross-site scripting flaws. CVE-2026-102427 in OrdaSoft Joomla CCK, CVE-2026-76570 in Joomcode.com JCTables, CVE-2026-96349 in WordPress SiteSkite, CVE-2026-97163 in Lomart.fr UP plugin, and CVE-2026-67364 in Balbooa Forms are among those highlighted. These vulnerabilities often stem from a lack of proper authentication or input validation, allowing unauthenticated attackers to compromise Joomla sites. Vypr Intelligence has provided a comprehensive overview of these Joomla extension vulnerabilities.
A critical vulnerability in Microsoft Container Registry, CVE-2026-69865, allows for authorization bypass through user-controlled keys, potentially leading to privilege escalation. This flaw affects Microsoft's container registry services, and unauthenticated attackers could exploit it to gain unauthorized access. Vypr Intelligence has reported on this vulnerability, noting its critical severity and potential for privilege escalation.
Critical vulnerabilities have also been disclosed in the Viidure Android application (CVE-2026-96587) and Netcore NAP930 (CVE-2026-102240). The Viidure app embeds permanent, plaintext cloud storage credentials, allowing attackers to access and manipulate stored data. The Netcore vulnerability, a command injection flaw in the Network Tools CGI component, allows for operating system command injection. CISA has issued an advisory for the Viidure vulnerability, while Vypr Intelligence has detailed the Netcore flaws.