Continue reading the full briefing.
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Why it matters: Apple Multiple Products is a memory-safety issue whose practical impact depends on the reachable parser, process privileges, platform protections, and reliability of attacker-controlled input.
What to verify: Confirm the exact affected build and component exposure, update from the vendor channel, review crash and restart telemetry, and keep network containment in place until the fixed process is running.
Open the original source record
CVE-2026-97637: The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass…
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()` endpoint — which embeds a live WordPress `logged_in` cookie produced by `wp_generate_auth_cookie()` directly in its JSON response body…
Why it matters: The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass… may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.
What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.
CVE-2026-15896: The Super Forms – Drag & Drop Form Builder plugin for WordPress…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does…
Why it matters: The Super Forms – Drag & Drop Form Builder plugin for WordPress… may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.
What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.
CVE-2026-19660: The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in…
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in…
Why it matters: The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in… may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.
What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.
Coverage by security desk
Exploited and critical vulnerabilities
- CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability – Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.
- CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability – Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.
- CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability – Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on…
Linux and open-source operations
- USN-8864-1: Linux kernel vulnerabilities – Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: -…
Windows and Microsoft security
- Insights from the 2026 Microsoft Digital Defense Report – Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected. The post Insights from the 2026 Microsoft Digital…
Network, VPN, firewall, and edge security
- CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability – Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on…
- CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability – Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due…
- CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway (Severity: MEDIUM) –
Web applications, APIs, and WordPress
- CVE-2026-19652: The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in… – The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new…
- CVE-2026-97637: The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass… – The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists…
- CVE-2026-15896: The Super Forms – Drag & Drop Form Builder plugin for WordPress… – The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request…
DevOps and software supply chain
- How we found 24 Android vulnerabilities using our open source AI security agent – A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app.…
AI and agent security
- How we found 24 Android vulnerabilities using our open source AI security agent – A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app.…
- DevDay 2026 Recap – Explore more than 20 announcements from OpenAI DevDay 2026, including GPT-6 Astra, ChatGPT, Codex, APIs, security, and new tools for builders.
Cloud and identity controls
- CVE-2023-54405: H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud… – H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers…
Priority actions for today
- Confirm exposure: match CVEs and vendor advisories to exact products, versions, internet reachability, and business-critical roles.
- Move exploited items first: patch, isolate, or disable affected paths for confirmed known-exploited technology before routine CVSS-only work.
- Preserve evidence: review authentication, process, endpoint, network, and management-plane telemetry before rebooting or replacing an affected system.
- Validate remediation: prove that the fixed version is running, required restarts are complete, controls still report healthy, and exceptions have owners and deadlines.
Primary sources and references
- CISA Known Exploited Vulnerabilities: CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability
- NIST National Vulnerability Database: CVE-2026-102490: All versions of Zammad including the latest alpha enable the local zammad…
- CISA Known Exploited Vulnerabilities: CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability
- NIST National Vulnerability Database: CVE-2026-102489: Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that…
- CISA Known Exploited Vulnerabilities: CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability
- CISA Cybersecurity Advisories: CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability
- CISA Known Exploited Vulnerabilities: CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
- CISA Cybersecurity Advisories: CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
- NIST National Vulnerability Database: CVE-2023-54405: H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud…
- NIST National Vulnerability Database: CVE-2026-19652: The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in…
- CISA Known Exploited Vulnerabilities: CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability
- CISA Cybersecurity Advisories: CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability
- NIST National Vulnerability Database: CVE-2026-97637: The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass…
- NIST National Vulnerability Database: CVE-2026-15896: The Super Forms – Drag & Drop Form Builder plugin for WordPress…
- NIST National Vulnerability Database: CVE-2026-19660: The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in…
- Palo Alto Networks Security Advisories: CVE-2026-0250 GlobalProtect App: Buffer Overflow Vulnerability during connection to Portal or Gateway (Severity: MEDIUM)
- Cisco Security Advisories: Cisco IOS XE Software Security Hardening Release: August 2026
- Ubuntu Security Notices: USN-8864-1: Linux kernel vulnerabilities
- Ubuntu Security Notices: USN-8851-2: Linux kernel (Raspberry Pi) vulnerabilities
- Microsoft Security Blog: Insights from the 2026 Microsoft Digital Defense Report
- GitHub Security Blog: How we found 24 Android vulnerabilities using our open source AI security agent
- OpenAI News: DevDay 2026 Recap
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.