Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

2026-08-26T13:24:00Z997694cd00c19aced649e1b3fb12f5f56d7fe2bb6acfe9b8fd944c58c12d5712
CVE-2026-18963CVE-2026-19912CVE-2026-19913CVE-2026-21962CVE-2026-60004CVE-2026-61979AI-securityClickFixGiteaKalturaKeycloakMFA-bypassOracle-WebLogicRATWordPressaccount-takeoveractive-exploitationauthentication-bypassbackdoorcritical-infrastructurecyber-espionagedeserializationmalwarephishingphishing-as-a-serviceremote-code-executionsupply-chain-securityvulnerabilityweb-application-security

What happened

The feed reports multiple significant cybersecurity developments, including actively exploited critical vulnerabilities in Gitea and Oracle WebLogic, unpatched Kaltura mwEmbed flaws enabling arbitrary file reads and remote code execution, Keycloak account takeover, miniOrange SAML authentication bypasses, and a Marimo notebook command-execution flaw. It also covers malware and phishing campaigns such as SLEEPWALKER, E4del, PINHOLE, Weedhack, Mirage2FA, ClickFix, AI voice phishing targeting Apple users, and espionage activity against Myanmar. The highest-priority risks are the actively explo09d

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
997694cd00c19aced649e1b3fb12f5f56d7fe2bb6acfe9b8fd944c58c12d5712
Enrichment time
2026-08-26T13:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code · Baitaphish