CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.