ImageMagick RCE, Shiro Bypass, LXD SSRF Lead CVEs
ImageMagick RCE, Apache Shiro bypasses, and LXD SSRF lead today's CVEs.

A memory corruption vulnerability in ImageMagick's GraphicsMagick component, identified as CVE-2026-13606, allows for remote code execution through specially crafted Photo CD (PCD) files. This flaw, with a CVSS score of 8.1, poses a significant risk due to the widespread use of ImageMagick in processing various image formats across many applications and systems. Attackers could exploit this by tricking users into opening a malicious image file, leading to system compromise. Further details on exploitation and patching are pending.
Apache Shiro, a popular Java security framework, is affected by two vulnerabilities. CVE-2026-56130 allows attackers to bypass expiration checks on "remember me" cookies, potentially enabling indefinite session hijacking. CVE-2026-56091, specifically impacting Shiro with the shiro-guice module in web servlet contexts, could lead to an authentication bypass via crafted HTTP requests. Both vulnerabilities are rated low risk, but highlight potential weaknesses in session management and authentication mechanisms within Shiro applications.
Several vulnerabilities have been disclosed in Canonical LXD, a container and virtual machine manager. CVE-2026-28385 introduces a Server-Side Request Forgery (SSRF) flaw in the image import functionality, allowing authenticated users to interact with internal network infrastructure. Additionally, CVE-2026-12411 describes a broken access control issue enabling an untrusted guest to mount, read, and overwrite another guest's storage volume. These flaws could lead to unauthorized access, information disclosure, and potential system compromise within LXD environments.
Google Chrome on Android is impacted by two use-after-free vulnerabilities. CVE-2026-13282, a flaw in the Payments component, requires physical access to the device for exploitation but could lead to heap corruption. CVE-2026-13283, affecting the AdFilter component, allows remote attackers to execute arbitrary code via a crafted HTML page after convincing a user to perform specific UI gestures. Both are rated High severity by Chromium and are addressed in Chrome for Android version 149.0.7827.201.
Nghttp2's nghttpx proxy (versions up to 1.69.0) has a vulnerability, CVE-2026-58055, where it forwards HTTP/1.1 Upgrade requests with a Content-Length header and body to backend connections. This could lead to unexpected behavior or potential security issues when proxying traffic. Additionally, libssh2 versions up to 1.11.1 contain vulnerabilities (CVE-2026-58051 and CVE-2026-58050) related to public key handling that could lead to uninitialized data access or integer overflows, potentially causing crashes or exploitable conditions.
GPAC Project's MP4Box (before version 26.02.0) is affected by two use-after-free vulnerabilities, CVE-2025-60464 and CVE-2025-60465. These flaws can be triggered by specially crafted media files, leading to Denial of Service (DoS) conditions. While these are DoS vulnerabilities, they highlight the importance of robust parsing and memory management in media processing tools. Libais through version 0.15 has a vulnerability (CVE-2026-56770) where an unchecked sentinel value can be used as a vector index, potentially causing crashes in services or vessel systems. Patool before 4.0.5 contains a path traversal vulnerability (CVE-2026-29509) in its tarfile extraction, which could allow attackers to write files outside of the intended directory.