An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant.
The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges
A vulnerability, which was classified as critical, has been found in Rapid7 InsightConnect Finger Plugin up to 1.0.2 on Linux. This impacts an unknown function of the component Shell Command Handler. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-8664. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Rapid7 InsightConnect Sed Plugin up to 2.0.4 on Linux. It has been classified as critical. This affects an unknown part. The manipulation of the argument expression leads to path traversal.
This vulnerability is referenced as CVE-2026-9154. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability was found in Rapid7 InsightConnect Sed Plugin up to 2.0.4 on Linux. It has been rated as critical. This issue affects some unknown processing of the component Expressions Handler. This manipulation causes os command injection.
This vulnerability is tracked as CVE-2026-9155. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, has been found in wedevs Dokan Pro Plugin up to 5.0.4 on WordPress. This issue affects some unknown processing. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-12079. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in GravityMore Gravity Bookings Plugin up to 2.7.1 on WordPress. It has been rated as critical. Affected is an unknown function. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-2508. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability categorized as problematic has been discovered in wpdevteam Gutenberg Essential Blocks Plugin up to 6.1.4 on WordPress. This vulnerability affects unknown code of the component Block Attribute Handler. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-10833. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability has been found in wedevs Dokan Pro Plugin up to 5.0.4 on WordPress and classified as critical. The affected element is an unknown function. This manipulation of the argument latitude/longitude causes sql injection.
This vulnerability is handled as CVE-2026-12077. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in SAP BusinessObjects Business Intelligence Platform and SE. It has been classified as problematic. Affected is an unknown function of the component Credentials Handler. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2022-39013. The attack needs to be done within the local network. There is no exploit available.
It is suggested to install a patch to address this issue.
A vulnerability was found in Huawei Aslan Children Watch. It has been classified as problematic. Impacted is an unknown function. This manipulation causes improper input validation.
This vulnerability is handled as CVE-2022-39012. The attack can only be done within the local network. There is not any exploit available.
A vulnerability categorized as critical has been discovered in Huawei EMUI and Magic UI. Impacted is an unknown function of the component Storage Module. Executing a manipulation can lead to double free.
This vulnerability is tracked as CVE-2022-39002. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Huawei HarmonyOS and classified as critical. Affected by this vulnerability is an unknown functionality of the component Fingerprint Module. Such manipulation leads to improper access controls.
This vulnerability is traded as CVE-2022-38982. The attack can be executed directly on the physical device. There is no exploit available.