The vulnerabilities, including three RCE flaws (CVE-2026-21666, CVE-2026-21667, and CVE-2026-21669) and one allowing execution as the postgres user (CVE-2026-21708), enable low-privileged users to execute remote code on vulnerable servers with low complexity.
Security researchers at Tenable identified the nine flaws, which impact users of various Looker Studio data connectors, including Google Sheets and PostgreSQL.
FedScoop reports that Sen. Gary Peters, D-Mich., is calling for an independent investigation into reports that representatives from the Department of Government Efficiency may have improperly accessed and transferred sensitive data from the Social Security Administration.
Widely used WordPress plugin Ally, which focuses on website usability and accessibility, has been impacted by a high-severity security vulnerability, which could be harnessed to compromise sensitive information without authentication, reports BleepingComputer.
Bell Ambulance, which is Wisconsin's leading ambulance provider, had information from 237,830 individuals stolen after its systems were compromised in a February 2025 cyberattack claimed by the Medusa ransomware-as-a-service operation, according to The Record, a news site by cybersecurity firm Recorded Future.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.