Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Arista's VeloCloud Orchestrator On-Prem contains a critical OS command injection vulnerability (CVE-2026-16812) that allows remote attackers to execute privileged commands on the system. Successful exploitation could compromise the VCO host, enabling unauthorized access to internal functionality and potentially affecting the confidentiality, integrity, and availability of both the orchestrator and its managed data.
A critical vulnerability (CVE-2026-48939) in iCagenda, a calendar and event management extension for Joomla, allows attackers to upload arbitrary files, including malicious PHP code, through its file attachment feature. This unrestricted file upload flaw can lead to remote code execution, enabling attackers to take control of affected systems.
Joomlack Page Builder: Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Langflow Langflow: Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Fortinet’s FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS products are affected by a critical OS command injection vulnerability, identified as CVE-2026-25089. This flaw enables unauthenticated attackers to execute arbitrary commands on the system by sending specially crafted HTTP requests.
WordPress Core has been identified as containing a SQL injection vulnerability (CVE-2026-60137) that occurs when plugins or themes pass untrusted input to specific parameters. This flaw can be exploited in conjunction with another vulnerability, CVE-2026-63030, enabling unauthenticated attackers to achieve remote code execution on default WordPress installations.