CISA flags actively exploited CVE-2026-21962 (CVSS 10.0) in Oracle WebLogic/HTTP Server. Unauthenticated attackers can access critical data remotely—immediate patching essential for any org running these services.
A maximum-severity RCE flaw in Microsoft Entra ID (formerly Azure AD) was exploited in the wild. Microsoft patched it server-side—no action needed, but SMBs should verify identity security posture.
ShieldBreak vulnerability (CVE-2026-69414) bypasses Microsoft Defender protections while patch is in development. SMBs relying solely on built-in AV should review layered security controls now.
A root-level OS command injection vulnerability in Haiwell's IoT Cloud HMI Gateway allows unauthenticated attackers to execute arbitrary commands. If you use industrial IoT devices, audit your exposure now.
CISA added CVE-2026-63077, a JetBrains TeamCity deserialization flaw, to its KEV catalog due to active exploitation. If your DevOps pipeline uses TeamCity, patch immediately and check for compromise.
Apple's bounty program flooded with AI-generated junk reports, NC ports attacked, and QuickFox VPN compromised. SMBs face similar vendor and supply chain risks daily—vigilance is essential.
A critical SQL injection flaw in Metabase was exploited before a patch existed, hitting companies like Framework and Tally. If you run business intelligence tools, audit access and update immediately.
A maximum-severity flaw in Metabase business intelligence software is being actively exploited, allowing unauthenticated attackers to inject SQL and gain admin control. If you run Metabase, patch immediately.
New Linux KVM vulnerability lets attackers escape VM isolation when nested virtualization is enabled. SMBs running virtualized infrastructure should audit their hypervisor configurations now.