vulnerability Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload PHP files and execute code, potentially leading to remote code execution. The flaw stems from a discrepancy in how the plugin handles empty file entries in its File Upload field. While a patch (ver… The Hacker News · Aug 20, 2026 High CVE-2026-32475CVE-2026-65640wordpressvulnerabilityremote-code-execution
vulnerability CISA Malcolm Several vulnerabilities in CISA Malcolm allow for denial-of-service attacks and arbitrary code execution. Versions prior to 26.06.1 and 26.07.1 are affected. The vulnerabilities stem from issues related to unbounded file… CISA Advisories · Aug 18, 2026 High CVE-2026-55676CVE-2026-63133CVE-2026-63134vulnerabilitynginxlua
vulnerability Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw A vulnerability (CVE-2026-20262) in Cisco Catalyst SD-WAN Manager has been actively exploited in the wild, allowing authenticated attackers to overwrite files on affected systems. The flaw stems from inadequate input val… The Hacker News · Jun 16, 2026 High CVE-2026-20262CVE-2026-20245CVE-2026-20182USsd-wancvefile-upload