VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers

2026-08-28T20:52:02Zf401fc75cd0b2f3e1d35887420a10ca25e92b215bc61b64dd30221a31e88bf49
CVE-2026-18412CVE-2026-18497CVE-2026-19505CVE-2026-19506CVE-2026-19874CVE-2026-19912CVE-2026-19913CVE-2026-6726CVE-2026-6727CVE-2026-75501CERT/CCKalturaMetal-Gear-OnlineOpenCartRDK-BTPMUPnParbitrary-file-readauthentication-bypassdenial-of-servicedirectory-traversalheap-buffer-overflowmemory-corruptionmissing-authenticationremote-code-executionrouterstb-truetypeunsafe-deserializationvulnerability-disclosure

What happened

CERT/CC advisories describe multiple newly disclosed vulnerabilities affecting Kaltura Player V2, Metal Gear Online 3, Calix GS7 routers, RDK-B WebUI, TPM 2.0 reference code, OpenCart, and the stb TrueType library. Impacts include unauthenticated administrative access, remote code execution, arbitrary file read, NAT/firewall bypass, memory corruption, cryptographic information leakage, directory traversal, denial of service, and information disclosure. Several issues lack vendor patches; affected systems should be updated or exposure-reduction mitigations applied.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
f401fc75cd0b2f3e1d35887420a10ca25e92b215bc61b64dd30221a31e88bf49
Enrichment time
2026-08-28T20:52:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.