What you need to know today.
GitLab, Apache HTTP Server, and Tomcat RCE flaws join CISA KEV; multiple SQL injection and PeopleSoft vulns disclosed.

Multiple critical vulnerabilities have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog today, including a remote code execution flaw in GitLab CE/EE (CVE-2021-22205) that affects all versions since 11.9. The vulnerability arises from improper validation of image files passed to a parser. Additionally, a critical Apache HTTP Server vulnerability (CVE-2021-40438) allows attackers to forward crafted requests to an origin server chosen by the remote user, impacting versions 2.4.48 and earlier. Another critical KEV addition is CVE-2017-12615, a flaw in Apache Tomcat versions 7.0.0 through 7.0.79 on Windows, which, with HTTP PUTs enabled, could allow attackers to upload JSP files via specially crafted requests. A medium-severity vulnerability in Adobe BlazeDS (CVE-2009-3960) and its related products also made it into the KEV catalog, though details are scarce.
Beyond the KEV catalog, several other vulnerabilities warrant attention. A denial-of-service vulnerability in the http-proxy-middleware package (CVE-2024-21536) affects versions before 2.0.7 and from 3.0.0 before 3.0.3. This flaw stems from an unhandled promise rejection error thrown by micromatch, potentially allowing an attacker to crash a Node.js process. Oracle's PeopleSoft Enterprise CS Campus Community is affected by multiple medium-severity vulnerabilities, including CVE-2021-2421, CVE-2017-3577, CVE-2021-35606, and CVE-2020-2912, which could allow low-privileged attackers to gain unauthorized access or execute code. Additionally, a series of critical SQL injection vulnerabilities were discovered in the Campcodes Retro Basketball Shoes Online Store (CVE-2023-2208, CVE-2023-2207, CVE-2023-2206, CVE-2023-2205, CVE-2023-2204), all affecting version 1.0.
Several low-severity vulnerabilities were also disclosed. Sigstore's go library (sigstore-go, CVE-2026-54787) has a flaw where it does not check a bundle signing timestamp against the validity window of an ExpiringKey. RubyGems (CVE-2026-18446) has an issue with the fast-uri component where it requires a literal double forward slash to recognize a URI authority. Coturn, an open-source TURN and STUN server implementation, has two disclosed vulnerabilities: CVE-2026-65981, which involves improper authentication for resumed REFRESH requests when using the --mobility flag, and CVE-2026-62959, where an unauthenticated remote client can send a single ordinary HTTP request to trigger an ACME redirect. Lastly, two entries with no specific details were noted: CVE-2026-18536 and CVE-2026-63343.