CISA has published an advisory on multiple critical vulnerabilities affecting Ebyte NE2-D11 gateway devices running firmware FW-9167-0-11, which are deployed across critical manufacturing and energy sectors worldwide. The vulnerabilities include missing authentication, cleartext transmission of credentials, client-side authentication bypass, CSRF, and insufficient token validation—potentially allowing unauthenticated remote attackers to gain administrative access, intercept sensitive data, and disrupt device operations. Ebyte acknowledged the vulnerabilities and indicated a patch was under development, but has not responded to subsequent coordination requests and no patch availability has been confirmed.
Attackers can exploit a networking vulnerability in NVIDIA's OpenClaw tool to gain unauthenticated access to the local model server via the Ollama API, enabling persistent corruption of AI agents. The flaw allows threat actors to conduct LLM poisoning attacks by manipulating the underlying model through this unprotected interface. This attack vector poses significant risks to organizations deploying NVIDIA's AI tools in production environments.
Two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981), both rated CVSS 9.8, in the miniOrange SAML 2.0 Single Sign On WordPress plugin are being actively exploited in the wild. Notably, the paid editions of the plugin were never listed as vulnerable in any CVE database despite being affected, and affected organizations require manual patching to remediate these flaws.
Researchers have identified a chained SharePoint sequence vulnerability that enables authentication bypass and is already being exploited in active attacks. This latest threat represents part of an ongoing pattern of SharePoint vulnerabilities being targeted by threat actors in the wild.