The vulnerability, tracked as CVE-2026-4415 and rated with a critical severity of 9.2 out of 10, resides in the "pairing" feature of GCC versions 25.07.21.01 and earlier.
Intrusions harnessing a critical SQL injection flaw in Fortinet FortiClient EMS, tracked as CVE-2026-21643, were reported by Defused researchers to have been ongoing since Mar. 24, according to Security Affairs.
The vulnerability, identified as CVE-2025-53521, allows attackers to gain complete control of affected servers through malicious traffic, enabling remote code execution (RCE).
BleepingComputer reports that at least 500,000 WordPress sites are vulnerable to attacks involving a medium-severity flaw in the Smart Slider 3 plugin, which is used for image slider and content carousel creation and management.