Key Findings ManageEngine ADAudit Plus CVE-2026-6516 combines authentication bypass and path traversal in Agent APIs to enable unauthenticated remote code execution with CVSS 10.0 Patch available since April 2026 in build 8606, but exploitation status remains unconfirmed SGLang CVE-2026-14890 exposes LLM inference servers through unpatched pickle deserialization flaw rated CVSS 9.1 SGLang maintainers have not responded to CERT/CC coordination efforts, leaving no official fix