The vulnerabilities, tracked as CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111, could allow remote code execution if a user connects to a malicious server.
The vulnerabilities, described as "confused deputy" flaws, allow low-privilege users to trick trusted programs like Sudo or Postfix into performing dangerous actions.
Hewlett Packard Enterprise (HPE) has released patches for several vulnerabilities affecting its Aruba AOS-CX operating system, including a critical flaw that could allow attackers to reset administrator passwords.
The Cybersecurity and Infrastructure Security Agency has released a new emergency directive warning of the active exploitation of flaws in the Cisco Catalyst SD-WAN systems prevalent in federal networks, particularly the maximum severity authentication bypass vulnerability, tracked as CVE-2026-20127, reports Infosecurity Magazine.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.