VYPR
AI Brief2026-08-05· generated Aug 5, 2026

OpenAM, Ivanti, Webmin, Oracle Java Hit By Critical Flaws

Critical RCEs in OpenAM and Ivanti, alongside KEV additions for Webmin and Oracle Java, dominate today's security landscape.

A critical pre-authentication remote code execution vulnerability in OpenAM allows an attacker to load arbitrary Java classes by exploiting a flaw in the authentication endpoint. This could lead to complete system compromise. CVE-2026-62379.

Ivanti EPM Cloud Services Appliance is affected by a critical code injection vulnerability (CVE-2021-44529) that allows unauthenticated attackers to execute arbitrary code with limited privileges. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.

Webmin, a popular web-based system administration tool, has a critical command injection vulnerability in its password change feature (CVE-2019-15107). This flaw, also listed on the KEV catalog, allows unauthenticated attackers to execute arbitrary commands on the server. As SentinelOne Labs reported, this vulnerability is a significant risk.

Multiple critical vulnerabilities in Oracle's Java Runtime Environment (JRE) dating back to 2012 are now listed on the KEV catalog. CVE-2012-4681 and CVE-2012-1723 allow remote attackers to execute arbitrary code or affect confidentiality, integrity, and availability due to bypasses in SecurityManager restrictions and other unspecified flaws.

Zimbra Collaboration Suite (ZCS) versions 8.8.15 and 9.0 are impacted by critical vulnerabilities in their mboximport functionality. CVE-2022-37042 allows unauthenticated attackers to upload arbitrary files by bypassing authentication, while CVE-2022-27925, also affecting these versions, allows authenticated administrators to upload arbitrary files. The Hacker News and Securelist have reported on related threats, highlighting the potential for exploitation.

Microsoft's MSDT is vulnerable to remote code execution via the URL protocol (CVE-2022-30190), allowing attackers to run arbitrary code with the privileges of the calling application, such as Microsoft Word. This critical vulnerability is actively exploited and has been added to the KEV catalog. Cyber Security News and Tenable Blog have covered this threat.

RARLAB's UnRAR utility (versions prior to 6.12 on Linux and UNIX) is susceptible to a high-severity directory traversal vulnerability (CVE-2022-30333). Attackers can exploit this flaw during file extraction to write to arbitrary files, including creating SSH authorized_keys files for persistent access. This vulnerability is also on the KEV catalog.

A high-severity heap-based buffer overflow in GIMP's DDS plug-in (CVE-2026-42170) could allow remote attackers to execute arbitrary code. Additionally, a heap buffer overflow in the APNG loader (CVE-2026-42169) presents a moderate risk.

Stunnel is affected by a moderate severity vulnerability (CVE-2026-70368) involving a stack-based out-of-bounds read/write in its logging function due to oversized log messages.

A critical vulnerability in the Linux kernel's KVM: x86 component (CVE-2026-64561) allows for checks on invalid/obsolete root *after* MMU pages are made available, potentially leading to security bypasses.

FortiOS configuration backups are vulnerable to data deciphering due to a hard-coded cryptographic key (CVE-2019-6693). Attackers with access to a backup file can potentially retrieve sensitive data. Mandiant Threat Intelligence has discussed related ransomware tactics.

Synthesized by Vypr AI
OpenAM, Ivanti, Webmin, Oracle Java Hit By Critical Flaws · VYPR