VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs

2026-07-14T20:52:16Z468e12385f6fa27c366f30f8586cec63137b931e1d5a4ca0521adcd05240a9e7
AndroidCORSCVE-2026FTP PASVGNU WgetIoTJWTJavaScript injectionRCESSRFTLS/SSL bypassWebViewanti-cheatauthentication bypassbackdoordata exposurekernel driverlocal privilege escalationmissing authorizationprinterrouter firmware

What happened

CERT/CC vulnerability notes report multiple high-impact flaws across desktop, mobile, cloud/no-code, and IoT ecosystems. Notable issues include: an FTP PASV IP validation SSRF in GNU Wget (CVE-2026-15146) allowing attacker-controlled redirection of data connections; two PayRange Android WebView vulnerabilities (CVE-2026-13462, CVE-2026-13461) permitting acceptance of invalid TLS certificates and JavaScript injection; Xerte Online Toolkits authentication bypass and RCE (CVE-2026-14261, CVE-2026-12116); platform-level full-user-data disclosure and exposed long-lived JWTs in Adalo’s database API,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
468e12385f6fa27c366f30f8586cec63137b931e1d5a4ca0521adcd05240a9e7
Enrichment time
2026-07-14T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.