VYPR
AI Brief2026-07-06· generated Jul 6, 2026

KEV Adds Sitecore RCE; Multiple Critical Flaws Disclosed

KEV adds Sitecore XP RCE, D-Link router flaws; Chamilo, NextGen Mirth Connect face critical RCE risks.

Several critical vulnerabilities were added to the CISA Known Exploited Vulnerabilities (KEV) catalog today, including a remote code execution flaw in Sitecore XP (CVE-2021-41653) affecting versions 7.5 through 8.2 Update-7, where insecure deserialization can lead to RCE without authentication. D-Link DIR-820L routers are also impacted by an RCE vulnerability (CVE-2022-26258) due to an HTTP POST to get set ccp. Additionally, Nagios XI versions prior to xi-5.7.5 are susceptible to OS command injection flaws in several configuration wizard files, including cloud-vm.inc.php (CVE-2021-25298), windowswmi.inc.php (CVE-2021-25296), and switch.inc.php (CVE-2021-25297), all stemming from improper input sanitization. ZKTeco BioTime v8.5.5 has a path traversal vulnerability (CVE-2023-38950) allowing unauthenticated file reads, patched in version 9.0.120240617.19506.

Beyond KEV, a critical command injection vulnerability in Chamilo (CVE-2023-34960) allows arbitrary command execution via a SOAP API call with a crafted PowerPoint name, affecting versions v1.11.* up to v1.11.18. NextGen Mirth Connect v4.3.0 contains a critical RCE vulnerability (CVE-2023-37679) that enables arbitrary command execution on the hosting server. Optoma 1080PSTX C02 suffers from an authentication bypass (CVE-2023-27823), allowing administrative console access without credentials. IOBit IOTransfer 4.3.1.1561 has a critical vulnerability (CVE-2022-24562) enabling arbitrary file read/write access via the Airserv component, leading to data compromise.

Several TP-Link router models are affected by command injection vulnerabilities. Specifically, the TL-WR840N(ES)_V6.20_180709 is vulnerable via the oal_setIp6DefaultRoute component (CVE-2022-25060) and the oal_startPing component (CVE-2022-25060). The TL-WR840N EU v5 router (CVE-2021-41653) is vulnerable to RCE via a crafted payload in an IP address field within its PING function. Additionally, D-Link DIR-615 devices with firmware 20.06 have an unauthenticated information disclosure and data modification vulnerability on their WAN configuration page (CVE-2021-42627). Wondershare Dr. Fone (as of 2021-12-06 version) has a remote code execution flaw (CVE-2021-44596) due to insecure UDP communication with the InstallAssistService.exe service. MailEnable before v10 has a cross-site scripting vulnerability (CVE-2025-44148) in the failure.aspx component that can lead to arbitrary code execution. Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses privileged APIs to modify registry values (CVE-2022-25089). Siklu Communications Etherhaul devices (CVE-2025-57174) have an issue with the rfpiped service using static AES encryption keys, potentially exposing sensitive information. Syncovery for Linux versions v9.47x and below allow privilege escalation (CVE-2022-36536) via crafted session tokens.

Synthesized by Vypr AI
KEV Adds Sitecore RCE; Multiple Critical Flaws Disclosed · VYPR