VYPR
AI Brief2026-06-05· generated Jun 5, 2026

Magento RCE Added to KEV; Oracle, Progress Flaws Surface

CISA flags exploited Magento RCE flaw as actively exploited, while critical Oracle and Progress Sitefinity flaws emerge.

CISA has added CVE-2026-45247, a critical PHP object injection vulnerability in Mirasvit's Full Page Cache Warmer for Magento 2, to its Known Exploited Vulnerabilities (KEV) catalog. This flaw allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the cache warmer's parameters. The vulnerability affects versions prior to 1.11.12 and is being actively exploited in the wild, as reported by multiple security news outlets including The Hacker News and Cyber Security News. Organizations using Magento should prioritize patching or mitigating this vulnerability immediately to prevent further compromise.

A suite of critical vulnerabilities has been disclosed for Oracle REST Data Services, impacting versions 24.2.0 through 26.1.0. CVE-2026-46840 and CVE-2026-46775 are particularly concerning, allowing unauthenticated attackers network access to compromise the system. Another related flaw, CVE-2026-46839, permits low-privileged attackers to achieve similar outcomes. These vulnerabilities, with CVSS scores of 9.9 and 9.8, highlight significant risks for organizations relying on Oracle's REST Data Services, especially when exposed via HTTPS. The Hacker News noted these disclosures in its weekly recap.

Progress Sitefinity faces multiple critical vulnerabilities, including CVE-2026-7312, which involves insufficiently protected credentials in its web services across several versions. Additionally, CVE-2026-7198 presents an improper access control flaw, allowing unauthenticated remote attackers to access restricted content and potentially achieve full system compromise. Vypr Intelligence reported on these five disclosed CVEs, emphasizing the critical nature of these security gaps. Organizations using Progress Sitefinity should review the specific versions affected and apply available patches or workarounds to secure their environments.

OpenStack Mistral is affected by CVE-2026-41283, a critical arbitrary remote code execution vulnerability that can be exploited when the API is exposed. This flaw allows attackers to exfiltrate service credentials, posing a significant risk to the integrity and security of OpenStack deployments. Vypr Intelligence highlighted this RCE vulnerability alongside other Ironic flaws, underscoring the need for immediate attention from OpenStack administrators.

Several other critical vulnerabilities have been disclosed across various products. These include an SEH-based buffer overflow in Mobatek MobaXterm (CVE-2019-25741), an unauthenticated settings change in WordPress Hybrid Composer (CVE-2019-25738), and arbitrary code execution via server-side template injection in PDF Signer (CVE-2019-25729). Additionally, an arbitrary file download vulnerability in a WordPress ad manager plugin (CVE-2019-25727) and an authorization bypass via SQL injection in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass (CVE-2026-4104) were reported. These diverse vulnerabilities underscore the broad attack surface organizations must manage.

Synthesized by Vypr AI