March 21-22, 2026 vulnerability digest: BACnet plaintext flaw, WordPress strpos() takeover
A weekend batch of 198 CVEs includes a BACnet plaintext flaw (CVSS 9.1) exposing building automation to traffic interception. WordPress gets hit with five privilege escalation bugs, cookie-based SQL injection bypassing WAFs, and a strpos() admin takeover.
Read more →