,

Vulnerability Watch No22

⚠️ Yggdrasil Package Manager Flaw Enables Root Code Execution
Teams running yggdrasil-worker-package-manager should patch promptly and restrict local access in the meantime. Root-level code execution makes this a high-priority issue even though exploitation requires existing access.
CVE-2026-18157 is an argument injection vulnerability in the APT backend of yggdrasil-worker-package-manager. A local attacker with existing system access can use package names beginning with a hyphen to inject apt-get options, potentially achieving remote code execution with root privileges. The vulnerability is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD

🔑 Advantech ECU-1251D Exposes Passwordless Root SSH Access
ECU-1251D operators should immediately set strong root credentials, restrict SSH exposure, and apply any vendor remediation. Internet-facing or operational-technology deployments should be treated as urgent.
CVE-2026-6890 affects the Advantech ECU-1251D and stems from documented default credentials. A remote attacker can access the device over SSH through the default root account with no password, while the configuration process provides no prompt to replace the credentials. The vulnerability is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD

🛡️ Joomla Gridbox Admin Interface Hit by Multiple CSRF Flaws
Joomla administrators using Gridbox should upgrade to version 2.20.2 or later promptly. Prioritize sites with multiple administrators or where privileged users may encounter untrusted links.
CVE-2026-65947 affects the balbooa.com Gridbox extension for Joomla in versions earlier than 2.20.2. Multiple cross-site request forgery vectors exist in the administrative interface and could cause an authenticated administrator to perform unintended actions. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD

🏥 Hospital Management System Report Page Exposed to Critical SQL Injection
Organizations running Hospital Management System 4.0 should patch or remove public access to the affected endpoint immediately. Apply strict input validation and database least-privilege controls as temporary safeguards.
CVE-2025-65340 is an SQL injection vulnerability in kishan0725 Hospital Management System 4.0. The flaw affects the /betweendates-detailsreports.php endpoint and may allow crafted input to manipulate database queries. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD