Emergency security updates have been released by Microsoft to remediate the actively exploited Office security feature bypass zero-day, tracked as CVE-2026-21509, Security Affairs reports.
Infosecurity Magazine reports that threat actors have been actively exploiting a critical authentication flaw in the open-source low-code application platform Appsmith, tracked as CVE-2026-22794, to facilitate user account takeovers.
The newly cataloged vulnerabilities include an improper access control flaw in Vitejs (CVE-2025-31125), an improper authentication bypass in Versa Concerto SD-WAN (CVE-2025-34026), a supply-chain compromise in eslint-config-prettier (CVE-2025-54313), and a PHP remote file inclusion vulnerability in Synacor Zimbra Collaboration Suite (CVE-2025-68645).
All GNU InetUtils telnetd versions 1.9.3 to 2.7 were affected by a critical remote authentication bypass issue that has been unidentified for almost 11 years, according to The Hacker News.
Fixes have been rolled out by Cisco to address a critical zero-day impacting its Unified Communications suite, tracked as CVE-2026-20045, amid ongoing exploitation, reports The Register.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.