VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs
2026-07-14T20:52:16Z•468e12385f6fa27c366f30f8586cec63137b931e1d5a4ca0521adcd05240a9e7
AndroidCORSCVE-2026FTP PASVGNU WgetIoTJWTJavaScript injectionRCESSRFTLS/SSL bypassWebViewanti-cheatauthentication bypassbackdoordata exposurekernel driverlocal privilege escalationmissing authorizationprinterrouter firmware
What happened
CERT/CC vulnerability notes report multiple high-impact flaws across desktop, mobile, cloud/no-code, and IoT ecosystems. Notable issues include: an FTP PASV IP validation SSRF in GNU Wget (CVE-2026-15146) allowing attacker-controlled redirection of data connections; two PayRange Android WebView vulnerabilities (CVE-2026-13462, CVE-2026-13461) permitting acceptance of invalid TLS certificates and JavaScript injection; Xerte Online Toolkits authentication bypass and RCE (CVE-2026-14261, CVE-2026-12116); platform-level full-user-data disclosure and exposed long-lived JWTs in Adalo’s database API,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 468e12385f6fa27c366f30f8586cec63137b931e1d5a4ca0521adcd05240a9e7
- Enrichment time
- 2026-07-14T20:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.