🛡️ Magma Integrity Validation Flaw Exposes Remote Attack Surface
Teams running Magma 1.9.0 should prioritize remediation or mitigating exposure of the affected handler. The public availability of an exploit raises the urgency even though active exploitation is not stated.
CVE-2026-82549 affects Linux Foundation Magma 1.9.0 and involves improper validation of an integrity check value in the SecurityModeComplete Handler. The flaw can be attacked remotely, and a public exploit is available. It is rated HIGH with CVSS 8.3.
🔗 Read more 🔗
Source: NVD
🔐 ash_postgres Tenant Rename Flaw Can Cross Data Boundaries
Multi-tenant applications using affected ash_postgres versions should upgrade to 2.13.0 or later promptly. The flaw can break tenant isolation and expose another customer’s live data.
CVE-2026-78699 affects ash_postgres from 0.25.0 before 2.13.0 and stems from an unchecked return value during tenant schema renaming. A failed PostgreSQL schema rename can still cause the tenant record to be repointed to another tenant’s existing schema, exposing that tenant’s data. It is rated HIGH with CVSS 7.2.
🔗 Read more 🔗
Source: NVD
💉 Admidio Blind SQL Injection Exposes Credentials
Internet-facing Admidio deployments should upgrade to 5.0.12 or later as a high priority. Because exploitation is unauthenticated and can expose credential material, delaying remediation carries significant risk.
CVE-2026-82655 affects Admidio before 5.0.12 and is a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php. Unauthenticated attackers can bypass authentication conditions and execute arbitrary SQL queries, potentially extracting password hashes and user credentials. It is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
🧨 SiYuan Block Metadata Enables Stored Script Execution
SiYuan users and administrators should move to v3.8.1 or later promptly, especially where notebooks are shared between users. Stored script execution makes this particularly relevant for collaborative environments.
CVE-2026-82654 affects SiYuan before v3.8.1 and results from insufficient escaping of block name, alias, and memo fields in hint, backlink, and breadcrumb rendering. An attacker can place HTML or script content in a block name that executes when another user views content referencing that block. It is rated HIGH with CVSS 8.9.
🔗 Read more 🔗
Source: NVD
⚠️ SiYuan Stored XSS Targets Package and Notebook Workflows
SiYuan installations should be upgraded to v3.8.1 or later promptly. Environments where users install third-party bazaar packages deserve particular attention because a malicious package name can trigger stored script execution.
CVE-2026-82653 affects SiYuan before v3.8.1 and is a stored cross-site scripting vulnerability in confirmDialog(). Unescaped package and notebook names are inserted into innerHTML, allowing malicious package names to execute script when users uninstall packages or unlock encrypted notebooks. It is rated HIGH with CVSS 8.9.
🔗 Read more 🔗
Source: NVD
🪟 SiYuan Windows Installer Flaw Enables Privilege Escalation
Windows users and software deployment teams should replace affected SiYuan installers with version 3.8.1 or later. The issue requires local file placement but can turn an elevated installation into local privilege escalation.
CVE-2026-82649 affects the SiYuan Windows installer before version 3.8.1, with affected versions >= 2.0.14. Its NSIS installer can resolve system executables from the launch directory before System32, allowing a planted executable such as TASKKILL.exe to run and potentially inherit elevated privileges during an all-users installation. It is rated HIGH with CVSS 7.0.
🔗 Read more 🔗
Source: NVD
🌐 AVideo NAT64 Parsing Flaw Bypasses SSRF Defenses
AVideo operators should apply the vendor fix as soon as available and restrict outbound connectivity from the application in the meantime. Cloud-hosted deployments are especially exposed because successful SSRF can reach metadata services.
CVE-2026-82648 affects WWBN AVideo and is an SSRF filter bypass in the isSSRFSafeURL function. Hexadecimal NAT64 addresses are not normalized correctly, allowing attackers to bypass protections and reach targets such as cloud metadata services and loopback interfaces. It is rated HIGH with CVSS 7.1.
🔗 Read more 🔗
Source: NVD
🔑 AVideo Flaw Exposes External Streaming Credentials
AVideo administrators using affected builds should patch urgently and rotate any stream credentials that may have been exposed. Because exploitation can be unauthenticated and the affected secrets grant access to external streaming accounts, credential rotation should accompany remediation.
CVE-2026-82645 affects AVideo at current commit e01e41ecc and earlier and allows unauthenticated disclosure of restream credentials. Attackers can forge tokens and retrieve arbitrary users’ stream_key and stream_url values for external services such as YouTube, Facebook, and Twitch. It is rated HIGH with CVSS 8.6.
🔗 Read more 🔗
Source: NVD
🚨 AVideo Rate-Limit Bypass Enables Unlimited Password Guessing
AVideo deployments should patch promptly and consider temporary upstream rate limiting on login and other affected endpoints. Internet-facing instances are particularly at risk because unauthenticated attackers can conduct unrestricted password guessing.
CVE-2026-82644 affects WWBN AVideo at current e01e41ecc and earlier and bypasses brute-force rate limiting in enforceRateLimit(). Requests identified as bots, including those with no User-Agent or common values such as curl, do not have their attempt counters stored, enabling unlimited login attempts. It is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
📚 Malicious EPUBs Can Reach Code Execution in Readest
Readest users should upgrade to 0.11.16 or later before opening untrusted EPUB files. The path from crafted book content to arbitrary code execution makes this a high-priority desktop client update.
CVE-2026-82642 affects Readest versions prior to 0.11.16 and stems from insufficient sanitization of EPUB chapter HTML. An attacker can use an iframe srcdoc payload to execute script in the application’s trusted origin and access Tauri IPC commands, escalating to arbitrary code execution. It is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🔓 Keploy Control Plane Leaks TLS Session Keys
Anyone running keploy 3.1.0 through 3.6.25 should patch promptly and immediately restrict the agent control-plane to trusted interfaces or networks. Exposure can undermine TLS confidentiality by giving attackers the material needed to decrypt recorded traffic.
CVE-2026-82641 affects keploy versions 3.1.0 through 3.6.25, which expose the agent control-plane HTTP server on all interfaces without authentication. Attackers able to reach the service can retrieve TLS session keys and traffic data or manipulate recording sessions through exposed agent endpoints. It is rated HIGH with CVSS 8.6.
🔗 Read more 🔗
Source: NVD
🔐 NextChat Proxy Flaw Can Leak OpenAI API Keys
NextChat operators on versions 2.15.8 through 2.16.1 should patch promptly and rotate the configured OpenAI API key if the proxy was reachable by untrusted users. Treat exposed internet-facing instances as potentially having leaked credentials.
CVE-2026-82639 affects NextChat versions from 2.15.8 through 2.16.1 and involves improper URL validation in its proxy endpoint. Substring-based validation of the x-base-url header lets attacker-controlled URLs containing api.openai.com pass checks and receive the server’s OpenAI API key in the Authorization header. It is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD