VYPR
AI Brief2026-07-03· generated Jul 3, 2026

IoT Devices and Libraries Hit By Critical Flaws

Critical flaws in IoT devices and software libraries, including ST Engineering iDirect terminals and Gardyn devices, expose sensitive data and allow unauthorized access.

ST Engineering iDirect's iQ200 terminals are affected by two critical vulnerabilities. CVE-2026-38057 allows for Cross-Site Request Forgery (CSRF) on state-changing API endpoints, enabling attackers to reboot devices or alter configurations using only a session cookie. Additionally, CVE-2026-38059 exposes sensitive device information like serial numbers and terminal IDs through unauthenticated API endpoints. These flaws could facilitate unauthorized access and control over critical infrastructure. As detailed in CISA ICS Advisories, patches or mitigations should be applied immediately.

Gardyn devices are impacted by a critical vulnerability, CVE-2026-13768, which exposes a privileged iothubowner key. This key allows attackers to retrieve connection information for all Gardyn Home Kit and Studio devices, potentially leading to widespread compromise. Further compounding the risk, CVE-2026-54477 highlights a lack of security headers in the admin panel, making it susceptible to clickjacking and XSS attacks. Separately, CVE-2026-55726 points to an openly accessible Azure Blob Storage container for Gardyn device logs, enabling unauthorized access to sensitive data. CISA ICS Advisories provide further details on these issues.

A critical authentication bypass vulnerability, CVE-2026-58517, has been disclosed in the Wikilambda Extension. This flaw allows unauthorized users to gain access by exploiting improper input neutralization. Separately, CVE-2026-55153 in mchange-commons-java enables remote code execution through JNDI injection, a common attack vector for compromising systems. These vulnerabilities underscore the importance of input validation and secure dependency management.

Multiple vulnerabilities have been identified in ImageMagick, including CVE-2026-53466, an integer overflow in the XCF decoder leading to denial of service, and CVE-2026-53467, an information disclosure flaw in the MNG decoder. Additionally, CVE-2026-55628 permits unauthorized file access due to missing policy checks in the concatenate operation. As reported by Vypr Intelligence, these issues collectively pose a significant risk to systems processing image files.

The Linux kernel is affected by several vulnerabilities, including CVE-2026-53357 and CVE-2026-53358, which relate to use-after-free and channel closure issues within the Bluetooth L2CAP module. These flaws could potentially lead to denial of service or system instability. Vypr Intelligence noted these as part of a larger batch of kernel vulnerabilities.

CVE-2022-32114, a high-severity unrestricted file upload vulnerability in Strapi, allows attackers to perform XSS attacks by uploading crafted PDF files. This impacts the Media Library's asset creation functionality.

CVE-2026-11946 in open62541 allows for denial of service due to an unvalidated endpoint URL length.

CVE-2026-9563 in Eclipse Parsson enables denial of service through uncontrolled resource consumption during JSON parsing.

CVE-2021-34432 in Eclipse Mosquitto can cause server crashes if a client attempts to send a PUBLISH packet with a zero-length topic.

CVE-2026-14363, a SQL injection vulnerability in the MediaWiki Cargo Extension, allows attackers to manipulate database queries.

CVE-2026-13743, an improper signature verification vulnerability in CubeSpace CW0057 Reaction Wheel firmware, could allow attackers with physical access to upload malicious firmware. CISA ICS Advisories have more information.

CVE-2026-38969 in the rubygem-webrick library permits request smuggling by re-parsing the Content-Length header.

CVE-2026-13743, an improper signature verification vulnerability in CubeSpace CW0057 Reaction Wheel firmware, could allow attackers with physical access to upload malicious firmware. CISA ICS Advisories have more information.

CVE-2026-5051 in HashiCorp Vault Enterprise allows an audit device validation bypass via a legacy file audit path option.

Synthesized by Vypr AI