VYPR
AI Brief2026-08-01· generated Aug 1, 2026

What you need to know today.

Zoho and Fortinet products suffer critical RCE flaws, while multiple Linux kernel vulnerabilities allow privilege escalation.

Zoho ManageEngine products are affected by CVE-2022-47966, a critical remote code execution vulnerability stemming from the use of an outdated XML Security library. This flaw allows unauthenticated attackers to execute arbitrary code on affected systems, posing a significant risk to organizations relying on these IT management tools. Patches are available from Zoho, and given the criticality, immediate application is advised.

Fortinet FortiOS and FortiProxy are impacted by CVE-2023-27997, a critical heap-based buffer overflow vulnerability. This flaw, which has reportedly been exploited in the wild as a zero-day, allows for remote code execution. Fortinet has released patches for various versions, and users are urged to update immediately to mitigate the risk of exploitation. As noted by SecurityWeek, this vulnerability has seen active exploitation.

Multiple Linux kernel vulnerabilities present a significant risk, including CVE-2023-1281, CVE-2021-23134, and CVE-2021-27365, all rated as High severity. These flaws, involving use-after-free and improper length checks in components like the traffic control index filter and iSCSI data structures, can lead to privilege escalation. While some have been present for years, their continued presence in older kernel versions warrants attention for systems not yet updated. CVE-2021-20322 also allows for UDP port scanning, and CVE-2021-27364 highlights Netlink message crafting issues.

The Yggdrasil Worker Package Manager is vulnerable to remote code execution via APT argument injection, identified as CVE-2026-18157. This medium-severity vulnerability allows attackers to execute arbitrary code by manipulating package management operations. While specific details on exploitation are limited, any RCE vulnerability warrants careful review and timely patching.

OpenStack Compute (Nova) versions prior to Essex (2012.1) are affected by CVE-2013-0335, a high-severity vulnerability that allows authenticated users to gain access to a Virtual Machine's console. This occurs opportunistically when a VNC token for a deleted VM is reused. Given the age of this vulnerability, it is most relevant for organizations still running very old OpenStack deployments.

Red Hat's ansible-collection-redhat-leapp is subject to two information disclosure vulnerabilities, CVE-2026-68562 and CVE-2026-68563. These medium-severity flaws allow for information disclosure through Leapp report tampering and insecure backup permissions for PostgreSQL data, respectively. While not RCE, these vulnerabilities can expose sensitive system or data information.

OpenVPN versions 2.7_alpha1 through 2.7.4 on Windows are susceptible to CVE-2026-13379, a low-severity vulnerability allowing for persistent DNS state pollution or a service crash. This can be triggered by a crafted search domain during disconnection.

Apache Tika versions 1.8 through 3.3.1 and 4.0.0-alpha-1 are affected by CVE-2026-66755, a relative path traversal vulnerability. This allows attackers to read arbitrary files by placing malicious files in directories that Tika subsequently parses. Additionally, CVE-2026-66756, affecting Tika 4.0.0-alpha-1 before 4.0.0-beta-1, is an improper protection of alternate path vulnerability. Both are low-severity but highlight potential file access risks.

Synthesized by Vypr AI
Zoho, Fortinet RCEs; Linux Kernel Privilege Escalation · VYPR