Overview
Cisco has released software hardening updates addressing multiple internally discovered vulnerabilities within Cisco IOS XE Software. The vulnerability may permit command, operating system, or argument injection under certain circumstances. A successful exploit could potentially result in complete compromise of affected devices.
- CVE-2026-20272: Improper Neutralisation of Special Elements (CVSSv3 9.8)
Affected Versions: 17.9, 17.12, 17.15, 17.18, 26.1
cPanel has released security updates addressing a critical privilege escalation vulnerability affecting all supported versions of cPanel & WHM. The flaw could allow authenticated users to execute arbitrary database commands with administrative privileges. An authenticated cPanel account with access to MySQL or MariaDB database features could potentially execute arbitrary database commands with full administrative privileges. Depending on the underlying operating system and database configuration, successful exploitation may lead to operating system compromise.
- CVE-2026-58048: Database Privilege Escalation (CVSSv4 9.4)
Affected Versions: 11.110.0.13, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, WP Squared 138.1.6
Google has released Chrome 151 to the Stable channel, addressing 41 security vulnerabilities, including six critical memory-safety flaws that could enable browser crashes, memory corruption, or arbitrary code execution through malicious web content. Six critical severity vulnerabilities were addressed in the latest update, including the following.
- CVE-2026-19170: WebGL Use-After-Free Sandbox Escape (CVSSv3 9.6)
- CVE-2026-19157: ANGLE Out-of-Bounds Write (CVSSv3 9.6)
Affected Versions:
- Windows and MacOS versions prior to 151.0.7922.108 / 151.0.7922.109
- Linux versions prior to 151.0.7922.108
Recommended Action
Organisations and individuals are encouraged to review the appropriate security advisory pages and apply the updates:
Cisco – Cisco Security Advisories
cPanel – cPanel Support Topics - Security
Google – Chrome Releases | Chrome