Zimbra 10.1.20 patches nine vulnerabilities, including a known SNMP-RCE flaw and four XSS weaknesses in the Classic Web Client that Russian groups have already exploited against Ukrainian infrastructure.
A validation flaw in WordPress’s REST Batch API enables pre-authentication remote code execution with full control over website, database, and hosting environment.
An indexing flaw in the REST batch endpoint allows unauthenticated attackers to gain complete control over WordPress installations, but requires immediate patching to version 6.9.5 or 7.0.2.
CVE-2026-60137 and CVE-2026-63030 enable unauthenticated remote code execution on WordPress 6.9–7.0.1 without prerequisites when both vulnerabilities are combined.
CVE-2026-42533 in NGINX 1.30.3, 1.31.2 and older NGINX Plus versions enables denial-of-service and potentially code execution — immediate update to 1.30.4, 1.31.3, or Plus 37.0.3.1 required.