VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
2026-08-28T20:52:02Z•f401fc75cd0b2f3e1d35887420a10ca25e92b215bc61b64dd30221a31e88bf49
CVE-2026-18412CVE-2026-18497CVE-2026-19505CVE-2026-19506CVE-2026-19874CVE-2026-19912CVE-2026-19913CVE-2026-6726CVE-2026-6727CVE-2026-75501CERT/CCKalturaMetal-Gear-OnlineOpenCartRDK-BTPMUPnParbitrary-file-readauthentication-bypassdenial-of-servicedirectory-traversalheap-buffer-overflowmemory-corruptionmissing-authenticationremote-code-executionrouterstb-truetypeunsafe-deserializationvulnerability-disclosure
What happened
CERT/CC advisories describe multiple newly disclosed vulnerabilities affecting Kaltura Player V2, Metal Gear Online 3, Calix GS7 routers, RDK-B WebUI, TPM 2.0 reference code, OpenCart, and the stb TrueType library. Impacts include unauthenticated administrative access, remote code execution, arbitrary file read, NAT/firewall bypass, memory corruption, cryptographic information leakage, directory traversal, denial of service, and information disclosure. Several issues lack vendor patches; affected systems should be updated or exposure-reduction mitigations applied.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- f401fc75cd0b2f3e1d35887420a10ca25e92b215bc61b64dd30221a31e88bf49
- Enrichment time
- 2026-08-28T20:52:02Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.