VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
2026-08-25T20:52:01Z•8fbbd85d06278f51197f6cf5afe798bf1c01bff01f3c6acdcfdcb34a490a356e
CVE-2026-18412CVE-2026-18497CVE-2026-19505CVE-2026-19506CVE-2026-19874CVE-2026-19912CVE-2026-19913CVE-2026-6726CVE-2026-6727CVE-2026-75501CERT/CCKalturaMetal-Gear-OnlineOpenCartRDK-BTPMarbitrary-file-readauthentication-bypassbuffer-overflowdirectory-traversalinformation-disclosureinsecure-deserializationmemory-corruptionmissing-authenticationremote-code-executionroutersstb-truetypetiming-side-channelvulnerability-disclosureweb-application
What happened
CERT/CC advisories report multiple vulnerabilities across Kaltura HTML5 Player, Metal Gear Online 3, Calix GS7 routers, RDK-B WebUI, TPM 2.0 reference code, OpenCart, and stb_truetype. Impacts include remote code execution, arbitrary file read, authentication bypass, unauthorized router port mapping, memory corruption, cryptographic information leakage, directory traversal, denial of service, and information disclosure.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 8fbbd85d06278f51197f6cf5afe798bf1c01bff01f3c6acdcfdcb34a490a356e
- Enrichment time
- 2026-08-25T20:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.