< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Major software and hardware vulnerabilities disclosed across multiple platforms

Multiple critical cybersecurity vulnerabilities have been identified across several widely used software platforms, including Apache Tomcat, WordPress plugins, DrayTek hardware, Drupal modules, and Red Hat components.

The Apache Software Foundation released patches for ten vulnerabilities in Apache Tomcat, including important-rated flaws that could allow attackers to bypass security constraints or cause denial-of-service conditions. Similarly, three WordPress plugins—BlogVault Backup & Staging, MalCare, and WP Remote—are affected by a high-severity vulnerability (CVE-2026-19718) involving weak secret generation that could lead to administrative takeover.

Hardware manufacturer DrayTek faces two critical remote vulnerabilities: a command injection flaw in VigorAP models allowing root-level code execution, and an authorization flaw in VigorSwitch models. In the web development sector, four Drupal modules face critical risks related to authentication bypass and unauthorized access. Additionally, vulnerabilities have been noted in cluster-management software like Submariner and Lighthouse, alongside long-standing, actively exploited flaws in Red Hat systems.

Entities

Apache Software Foundation · Apache Tomcat · DrayTek · Red Hat · WordPress