VYPR
AI Brief2026-07-12· generated Jul 12, 2026

Coturn RCE, osTicket SSRF, ImageMagick Flaws Lead Digest

Critical RCE in coturn, SSRF in osTicket, and ImageMagick flaws lead today's security brief.

A critical SSRF vulnerability in osTicket versions prior to 1.14.3 allows attackers to add malicious files to the server or perform port scanning. This flaw, tracked as CVE-2020-24881, arises from improper handling of file uploads. While not yet actively exploited, its potential for initial access or reconnaissance makes it a significant concern for organizations using osTicket for customer support. Patches are available in versions 1.14.3 and later.

Multiple vulnerabilities have been disclosed in the coturn TURN server software, including a critical arbitrary code execution flaw via SQL injection in its HTTPS admin panel (CVE-2026-53448). Another significant vulnerability, CVE-2026-53450, allows local services to be exposed via an IPv4-mapped IPv6 address, bypassing localhost restrictions. Additionally, CVE-2026-53449 enables arbitrary file overwrites through CLI commands. These issues pose a substantial risk to real-time communication services relying on coturn for signaling and network traversal. Users are urged to update to patched versions immediately.

ImageMagick, a widely used image processing library, is affected by multiple vulnerabilities, including CVE-2026-61857 which allows application crashes via malicious XMP profiles, and CVE-2026-56372 leading to information disclosure and denial of service. As reported by Vypr Intelligence, these ten disclosed vulnerabilities collectively impact memory handling and file writing capabilities within the software. Given ImageMagick's prevalence in web applications and content management systems, these flaws could be exploited for denial-of-service attacks or to expose sensitive information. Users should consult the vendor for specific version information and apply available patches.

A wave of vulnerabilities impacting osTicket, an open-source ticketing system, has been detailed. Among the most severe is CVE-2020-24881, a critical SSRF flaw allowing attackers to upload malicious files or scan ports. Other notable issues include CSV injection (CVE-2019-14749), arbitrary password resets via guest access (CVE-2018-7195), and various stored and reflected XSS vulnerabilities (e.g., CVE-2019-14750, CVE-2019-11537, CVE-2025-26241, CVE-2020-24917, CVE-2018-7196, CVE-2018-7193, CVE-2018-7192, CVE-2022-32074, CVE-2020-16193). While many of these have been addressed in later versions, their cumulative impact highlights the need for diligent patching and security hygiene for systems handling customer support interactions.

The Wget file retrieval utility has a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-15146, stemming from an IP address validation bypass in its FTP PASV response. This could allow an attacker to trick Wget into making requests to arbitrary internal or external resources on behalf of the server. While the CVSS score is moderate, the potential for network reconnaissance or interaction with sensitive internal services warrants attention for systems that heavily rely on Wget for automated file transfers. Patches or updated configurations should be sought from the Wget project.

Synthesized by Vypr AI
Coturn RCE, osTicket SSRF, ImageMagick Flaws Lead Digest · VYPR