What you need to know today.
Actively exploited Oracle and Zammad flaws lead today's critical vulnerability disclosures, alongside KEV additions for Apache Struts and Dell CSM.

A critical vulnerability in Oracle Concurrent Processing (CVE-2025-61882) within Oracle E-Business Suite versions 12.2.3 through 12.2.14 is being actively exploited. This flaw allows unauthenticated attackers to execute arbitrary code, and has already been linked to data breaches at companies like Bimbo Bakeries USA and Estée Lauder. The exploitation of this vulnerability highlights the significant risk posed by unpatched Oracle systems. BleepingComputer reported that over 900 instances were exposed to ongoing attacks.
Zammad versions 6.3.0 to 6.5.4 and 7.0.0 to 7.1.2 are affected by a session hijack vulnerability (CVE-2026-102489) that can lead to remote code execution as the zammad user. This flaw has been actively exploited, with reports indicating its use in an AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD). Proof-of-concept exploits have been released, underscoring the urgency for patching. Cyber Security News noted that Zammad 0-day vulnerabilities were exploited to gain remote code execution and root access.
Apache Struts versions 2.3.19 through 2.3.28 are susceptible to remote code execution via chained expressions when Dynamic Method Invocation is enabled (CVE-2016-3081). This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. The flaw allows attackers to execute arbitrary code by leveraging method: prefixes, posing a significant risk to applications using vulnerable Struts versions. The Hacker News covered this as part of a broader campaign by Flax Typhoon.
Critical vulnerabilities have been disclosed in Dell Container Storage Modules (CSM) prior to version 1.18.0 (CVE-2026-63692). These flaws allow unauthenticated remote attackers to gain full administrative control over systems, including Kubernetes nodes. The severity of these vulnerabilities necessitates immediate patching to prevent unauthorized access and potential system compromise. The Hacker News reported that these flaws enable unauthenticated admin access and root on Kubernetes nodes.
The mod_copy module in ProFTPD version 1.3.5 (CVE-2015-3306) allows remote attackers to read and write arbitrary files using the site cpfr and site cpto commands. This vulnerability has been flagged by CISA and is considered actively exploited, with links to campaigns by China-linked threat actors. The ease of exploitation and potential for data exfiltration or modification make this a high-priority issue for systems running vulnerable ProFTPD instances. The Register Security noted this vulnerability in the context of state-sponsored cyber activity.
Cisco has released patches for a dozen critical vulnerabilities in Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem) (CVE-2026-76482). While details are scarce, the critical nature of these flaws suggests a significant risk to organizations relying on this software for license management. Prompt application of these patches is crucial to mitigate potential exploitation. SecurityWeek highlighted Cisco's proactive patching efforts.