Rently Smart Home versions 20.1.0 and prior contain an insufficiently protected credentials vulnerability (CVE-2026-75960) with a CVSS score of 8.1 that could allow authenticated attackers to retrieve PINs, including the Master PIN, and override user permissions. Rently has already patched this vulnerability as of late June, and no user action is required; however, organizations should implement network segmentation and secure remote access controls as defensive measures.
Attackers can exploit a networking vulnerability in NVIDIA's OpenClaw tool to gain unauthenticated access to the local model server via the Ollama API, enabling persistent corruption of AI agents. The flaw allows threat actors to conduct LLM poisoning attacks by manipulating the underlying model through this unprotected interface. This attack vector poses significant risks to organizations deploying NVIDIA's AI tools in production environments.
Two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981), both rated CVSS 9.8, in the miniOrange SAML 2.0 Single Sign On WordPress plugin are being actively exploited in the wild. Notably, the paid editions of the plugin were never listed as vulnerable in any CVE database despite being affected, and affected organizations require manual patching to remediate these flaws.
Researchers have identified a chained SharePoint sequence vulnerability that enables authentication bypass and is already being exploited in active attacks. This latest threat represents part of an ongoing pattern of SharePoint vulnerabilities being targeted by threat actors in the wild.