VYPR
AI Brief2026-07-10· generated Jul 10, 2026

OpenPLC, GitLab, and Wireshark Vulnerabilities Disclosed

Critical OpenPLC file write flaw, GitLab patches, and multiple Wireshark DoS vulnerabilities lead daily security updates.

OpenPLC Runtime v3 is affected by a critical arbitrary file write vulnerability in its legacy web UI. This flaw, tracked as CVE-2026-14480, allows authenticated attackers to write files with attacker-controlled names to the database, potentially leading to system compromise. The vulnerability was detailed in a CISA ICS Advisory, highlighting its significance in industrial control systems. Mitigation requires updating to a patched version.

GitLab has addressed multiple vulnerabilities, including CVE-2026-13320, an arbitrary script execution flaw stemming from improper input sanitization. This issue, along with others, was patched in recent GitLab releases, as noted by Cyber Security News and detailed in GitLab's security releases. Users are urged to update to the latest versions to protect against potential exploitation.

The LiteLLM Python library is impacted by three vulnerabilities, including arbitrary code execution and directory traversal. CVE-2026-59820, a directory traversal flaw, and CVE-2026-59821, which allows for arbitrary code execution and information disclosure via custom code guardrails, are particularly concerning. These issues were reported by Vypr Intelligence, and users should update LiteLLM to the latest version to mitigate these risks.

AsyncSSH, a popular SSHv2 library, has a vulnerability (CVE-2026-54591) that permits arbitrary file writes through path traversal in its SCP client. This could allow attackers to overwrite critical system files. Additionally, gpsd is vulnerable to command injection (CVE-2026-58459) via GPS device subtypes, enabling arbitrary code execution. Users of these libraries should apply available patches or updates.

A series of Denial of Service (DoS) vulnerabilities have been disclosed in Wireshark, affecting multiple protocol dissectors. CVE-2026-15163, CVE-2026-15164, CVE-2026-15165, CVE-2026-15166, CVE-2026-15167, CVE-2026-15169, CVE-2026-15170, CVE-2026-15171, CVE-2026-15172, and CVE-2026-15174 all relate to crashes in various dissectors, potentially leading to DoS conditions. Vypr Intelligence reported on these issues, and users should update Wireshark to the latest version.

Other vulnerabilities disclosed include an authentication bypass in etcd (CVE-2026-59818) due to improper Certificate Revocation List enforcement, a denial of service in HashiCorp memberlist (CVE-2026-14362), and a regular-expression denial of service in the Python library guardrails-detectors (CVE-2026-15154). Patches and updates should be applied where available.

Synthesized by Vypr AI
OpenPLC, GitLab, and Wireshark Vulnerabilities Disclosed · VYPR