VYPR
AI Brief2026-06-19· generated Jun 19, 2026

Kirby CMS Patches Critical Auth Bypass

Kirby CMS patches a critical auth bypass alongside six other bugs, while CISA warns on AVer camera RCE and Gitea discloses ten CVEs.

Kirby CMS ships a critical-severity patch bundle covering seven vulnerabilities, including an unauthenticated auth bypass. CVE-2026-54003 carries a critical rating and affects Kirby sites with no configured user accounts that are running behind a reverse proxy setting Forwarded, X-Client-IP, or X-Real-IP headers — an attacker can leverage this to gain full access. Three additional high-severity bugs were also patched: CVE-2026-54005 (page-access bypass when pages.access is disabled), CVE-2026-54002 (sanitizer bypass in writer/list fields), and CVE-2026-49276 (scripting link injection via the writer field). As Vypr Intelligence reported, all seven CVEs were disclosed in a single advisory. Sites should update to the latest Kirby release immediately, and administrators should review reverse-proxy header configurations.

CISA warns of actively exploited AVer PTZ camera flaws, adding CVE-2026-40624 to its ICS advisory list. The critical improper input validation vulnerability (CVSS 9.8) affects AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras, allowing a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request. As CISA noted, these cameras are widely deployed in education, enterprise, and government settings. No public PoC or active exploitation has been confirmed yet, but the critical CVSS score and network-exposed nature of PTZ cameras make this an urgent patching priority for any organization using AVer hardware.

Gitea disclosed ten CVEs simultaneously, with CVE-2026-28737 standing out as a stored XSS via crafted 3D model files. The high-severity bug resides in Gitea's built-in 3D file viewer (powered by Online3DViewer) — an attacker can upload a malicious .gltf file that, when viewed by another user, executes arbitrary JavaScript in the victim's browser session. As Vypr Intelligence reported, the broader disclosure includes seven high-severity token-scope and auth bypass flaws. Self-hosted Gitea instances should update to the latest release; administrators should also consider disabling the 3D viewer for untrusted repositories until patched.

Mitsubishi Electric MELSEC iQ-F Series Ethernet modules carry two high-severity DoS vulnerabilities. CVE-2026-8805 is an integer overflow or wraparound in the EtherNet/IP function, while CVE-2026-8806 is an expected-behavior violation (CWE-440). Both allow a remote attacker to cause a denial-of-service condition on FX5-ENET/IP modules. As CISA advisories detail, these modules are used extensively in industrial control environments. Mitsubishi has released firmware updates; operators should apply them during planned maintenance windows and restrict network access to these modules where possible.

AzeoTech DAQFactory version 21.1 and prior are vulnerable to a type confusion bug that enables code execution. CVE-2026-12390 (CVSS 7.8) can be triggered by an attacker supplying a specially crafted .ctl file. As CISA noted, DAQFactory is used for data acquisition and control in critical manufacturing and energy sectors. Exploitation requires user interaction (opening a malicious file), but the potential for lateral movement into OT networks makes this a significant concern. Users should upgrade to the latest version and enforce strict file-origin policies.

Open WebUI disclosed 16 CVEs in a single batch, with CVE-2026-54018 highlighting SSRF bypass weaknesses. The SafePlaywrightURLLoader's validate_url function checks the initial URL for SSRF prevention, but Playwright's automatic redirects allow an attacker to bypass this check entirely. As Vypr Intelligence reported, many of the 16 CVEs bypass earlier patches, suggesting a pattern of incomplete fixes. Organizations running Open WebUI should update immediately and audit any exposed instances for signs of SSRF-based internal network reconnaissance.

Synthesized by Vypr AI
Kirby CMS Patches Critical Auth Bypass · VYPR