Overview
Cisco has released a security advisory addressing an actively exploited vulnerability affecting Cisco Secure Firewall Management Center (FMC) Software. The vulnerability is caused by the presence of static credentials for a low-privileged account within the FMC web interface. An unauthenticated, remote attacker could exploit this issue to gain access to sensitive information available to the account. This vulnerability has the potential for attackers to chain it with other vulnerabilities to elevate privileges and further compromise affected systems.
- CVE-2026-20316: Static Credential Vulnerability (CVSSv3 5.3)
Affected Versions: 7.0, 7.2, 7.4, 7.6, 7.7, 10.0
SolarWinds has released security updates for Web Help Desk (WHD) addressing a critical authentication bypass vulnerability and a separate denial-of-service vulnerability. The flaw could allow a remote attacker to gain unauthorised access without valid credentials. An additional denial-of-service vulnerability could be exploited to exhaust server resources and cause the Web Help Desk service to crash.
- CVE-2026-28323: SAML Authentication Bypass Vulnerability (CVSSv3 9.8)
- CVE-2026-28299: Denial-of-Service Vulnerability (CVSSv3 8.2)
Affected Versions:
- SolarWinds Web Help Desk versions prior to 2026.2.1 (CVE-2026-28323)
- SolarWinds Web Help Desk versions prior to 2026.2 (CVE-2026-28299)
Adobe has released a security advisory addressing a critical vulnerability affecting Adobe Campaign Classic (ACC). The vulnerability is caused by improper authorisation controls and could allow arbitrary code execution in the context of the current user without requiring any user interaction. The flaw is remotely exploitable and has been assigned a CVSS score of 10.0, reflecting the potential for complete compromise of affected systems.
- CVE-2026-48449: Incorrect Authorisation Vulnerability Leading to Arbitrary Code Execution (CVSSv3 10.0)
Affected Versions: Adobe Campaign Classic versions up to and including 7.4.3 Build 9397
Recommended Action
Organisations are encouraged to review the appropriate security advisory pages and apply the updates:
Cisco – Cisco Security Advisory
Solarwinds – nvd.nist.gov: CVE-2026-28323 and nvd.nist.gov: CVE-2026-28299
Adobe – Adobe Security Bulletin
If you have any concerns, or have been affected by a cyber-related issue, report it to us by submitting a Cyber Concerns Online Reporting Form.