What you need to know today.
Zammad and Cisco SD-WAN Manager flaws are actively exploited and added to CISA KEV, while MLflow SSRF vulnerability is also exploited.

Two critical Zammad vulnerabilities, CVE-2026-102490 and CVE-2026-102489, are now on the CISA Known Exploited Vulnerabilities (KEV) catalog. The first allows local Zammad users to escalate privileges to root, while the second enables remote code execution as the Zammad user via session hijacking. These flaws have reportedly been exploited in attacks against the Dutch Institute for Vulnerability Disclosure (DIVD) by an AI-powered agent, as detailed by Cyber Security News and The Register.
Cisco Catalyst SD-WAN Manager is facing active exploitation due to CVE-2026-76504, a critical authentication bypass vulnerability. This flaw allows unauthenticated remote attackers to gain administrative privileges. Cisco has released patches, and the vulnerability has been added to the CISA KEV catalog, as reported by Help Net Security and The Hacker News.
A critical vulnerability in MLflow, CVE-2026-64849, is being actively exploited, allowing unauthenticated attackers to perform server-side request forgery (SSRF) and steal cloud credentials. The vulnerability exists in versions prior to 3.15.0. The Hacker News and GovInfoSecurity provide further details on the exploitation and impact.
Multiple critical vulnerabilities have been disclosed in WordPress plugins. CVE-2026-19652 and CVE-2026-19660 in the Divi Membership plugin allow for privilege escalation and authentication bypass, respectively. Additionally, CVE-2026-94541 in WPMobile.App and CVE-2026-97637 in JSON API Auth also present authorization bypass and authentication bypass risks. CVE-2026-14378 in DevKit Pro enables administrator account takeover.
Critical vulnerabilities affecting Linux kernel and Google Chrome have been detailed. CVE-2026-68161 and CVE-2026-20272 address issues within the Linux kernel related to socket handling and network security. In Google Chrome, CVE-2026-103628 is a critical out-of-bounds write in WebGL that could lead to arbitrary code execution outside the sandbox, as noted by Vypr Intelligence.
Other notable vulnerabilities include CVE-2026-76504 affecting Cisco Catalyst SD-WAN Manager, CVE-2026-84411 in MikroTik RouterOS enabling unauthenticated code execution, CVE-2023-54405 in H3C CVM allowing arbitrary file uploads, CVE-2026-96658 in Foreman Debug enabling remote code execution, CVE-2026-51858 in Camel AI allowing prompt-driven shell command execution, CVE-2026-88920 in Apache WSS4J enabling SOAP message forgery, and CVE-2026-77987 in GitHub Enterprise Server allowing server-side request forgery. CVE-2026-20272 in Cisco IOS XE has also been patched as part of ongoing security hardening.