PcVue, RecoverPoint, and GNU Patch Vulnerabilities Disclosed
Critical flaws in ARC Informatique PcVue and EMC RecoverPoint, alongside new GNU patch vulnerabilities, highlight today's security landscape.

ARC Informatique's PcVue industrial control system software is facing multiple critical vulnerabilities, including remote code execution via untrusted data deserialization (CVE-2020-26867) and information exposure (CVE-2020-26869). Versions prior to 12.0.17 are affected by these flaws, which could allow attackers to compromise the web and mobile back-end server or access sensitive session data. Additionally, a denial-of-service vulnerability (CVE-2020-26868) exists due to improper message validation, impacting third-party systems relying on the Web Services Toolkit. Patches are available for versions 12.0.17 and later.
EMC RecoverPoint, used for data protection and disaster recovery, has several vulnerabilities impacting versions prior to 5.0 and 4.4.1.1. These include an SSL stripping vulnerability (CVE-2016-6650) that could lead to system compromise, and multiple command injection flaws (CVE-2016-6649) that allow bypassing user interfaces for malicious administration. A sensitive information disclosure vulnerability (CVE-2016-6648) also exists due to incorrect file permissions. Users are advised to upgrade to patched versions.
The Python programming language's HTML parser is susceptible to a CPU denial-of-service attack (CVE-2026-15308) through repeated unterminated markup declarations. This vulnerability affects Python's ability to process HTML content, potentially leading to system instability.
GNU patch, a widely used utility for applying code changes, has disclosed two vulnerabilities. CVE-2026-56288 involves a NULL pointer dereference when processing specially crafted unified-diff patch files, while CVE-2026-56289 is a denial-of-service vulnerability caused by improper validation of hunk line offsets. Both issues could be exploited by malicious patch files, as reported by Vypr Intelligence. Users should update to a secure version.
Multiple vulnerabilities have been identified in the guardrails-detectors Python package, including SSRF and local file read capabilities via user-supplied XML Schema (CVE-2026-15143, CVE-2026-15378). These flaws could allow attackers to access sensitive files or internal network resources.
Several older vulnerabilities in ARC Informatique PcVue (versions 6.0 through 10.0) and related products like FrontVue and PlantVue involve ActiveX controls. These include remote code execution (CVE-2011-4043, CVE-2011-4042), file modification (CVE-2011-4045), and denial-of-service (CVE-2011-4045) possibilities, often triggered by crafted HTML documents.
PcVue versions 8.10 through 15.2.3 contain a cleartext storage of sensitive information vulnerability (CVE-2022-4312) in email and SMS account configuration files, potentially exposing credentials. Additionally, versions 15 through 15.2.2 have an insertion of sensitive information into log files vulnerability (CVE-2022-4311), exposing data source connection strings.
A vulnerability in the Apprise notification library (CVE-2026-59180) allows for information disclosure via HTTP redirects that resend credentials. This could lead to the exposure of sensitive authentication information.
The Compress & Upload WordPress plugin is vulnerable (CVE-2025-8889) before version 1.0.5, allowing high-privilege users to upload arbitrary files, even when restricted. This could be exploited in multi-user WordPress environments.
A vulnerability in an unspecified device (CVE-2022-2569) allows authenticated users to access session data stored in the OAuth database due to cleartext storage of sensitive information.