VYPR
AI Brief2026-08-05· generated Aug 5, 2026

What you need to know today.

Multiple critical vulnerabilities in Ivanti, Webmin, Oracle, and Zimbra are actively exploited, alongside KEV additions for Chrome and Windows.

Ivanti EPM Cloud Services Appliance (CSA) is affected by CVE-2021-44529, a critical code injection vulnerability that allows unauthenticated attackers to execute arbitrary code with limited privileges. This vulnerability has a CVSS score of 9.8 and is listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Immediate patching or mitigation is strongly recommended to prevent potential compromise.

Webmin, a web-based interface for Unix-like systems, has a critical command injection vulnerability in its password change functionality (CVE-2019-15107). Exploitable via the old parameter in password_change.cgi, this flaw allows authenticated attackers to execute arbitrary commands. With a CVSS score of 9.8 and a 100% exploitation probability score (epss), it is also a KEV entry, demanding urgent attention from administrators.

Multiple critical vulnerabilities in Oracle's Java Runtime Environment (JRE) and Oracle WebCenter Forms Recognition are present in older versions. CVE-2012-4681 and CVE-2012-1723, both with CVSS 9.8, allow remote code execution by bypassing SecurityManager restrictions or affecting confidentiality, integrity, and availability, respectively. CVE-2012-1710 in WebCenter Forms Recognition also poses a critical risk. These are all KEV entries, highlighting their exploitation in the wild.

Zimbra Collaboration Suite (ZCS) versions 8.8.15 and 9.0 are impacted by two critical vulnerabilities. CVE-2022-37042 allows unauthenticated attackers to upload arbitrary files by bypassing authentication in the mboximport functionality. CVE-2022-27925, also in mboximport, permits authenticated administrators to upload arbitrary files. Additionally, CVE-2022-27924 enables unauthenticated attackers to inject memcache commands, leading to the overwrite of cached entries. All three are KEV entries.

Google Chrome versions prior to 103.0.5060.114 contain a critical heap buffer overflow vulnerability in WebRTC (CVE-2022-2294). This flaw, with a CVSS score of 8.8, could allow remote attackers to exploit heap corruption via a crafted HTML page. As a KEV entry, it signifies active exploitation and requires immediate updating to the patched version.

Microsoft's MSDT is affected by CVE-2022-30190, a high-severity remote code execution vulnerability. When MSDT is invoked via the URL protocol from applications like Word, attackers can exploit this flaw to run arbitrary code with the calling application's privileges. This vulnerability has a high exploitation probability (0.99) and is listed on the KEV catalog. As reported by Cyber Security News and Tenable Blog, it is actively being exploited.

RARLAB's UnRAR utility, prior to version 6.12 on Linux and UNIX systems, suffers from a directory traversal vulnerability (CVE-2022-30333). This flaw allows attackers to write to arbitrary files during the extraction process, potentially enabling the creation of malicious files such as ~/.ssh/authorized_keys. This high-severity vulnerability is a KEV entry, underscoring the need for prompt updates.

FortiOS configuration backups are susceptible to sensitive data exposure due to a hard-coded cryptographic key (CVE-2019-6693). Attackers with access to a backup file can decipher sensitive information by leveraging this hard-coded key. This medium-severity vulnerability is listed on the KEV catalog, and its exploitation could lead to significant data breaches, as noted in Mandiant Threat Intelligence.

GIMP, the GNU Image Manipulation Program, has a critical heap-based buffer overflow vulnerability in its DDS plug-in (CVE-2026-42170). This flaw arises from a BPP mismatch within the load_layer() function in ddsread.c. Additionally, GIMP's APNG loader has a heap-based buffer overflow vulnerability (CVE-2026-42169) when the fcTL width exceeds the IHDR width in file-png.c. Both vulnerabilities carry significant risk and require attention from GIMP users.

Stunnel, a secure tunnel for arbitrary TCP applications, has a stack-based out-of-bounds read/write vulnerability (CVE-2026-70368) in its s_vlog function when processing oversized log messages. Furthermore, a server-side request forgery (SSRF) bypass vulnerability (CVE-2026-70367) exists in its SOCKS proxy implementation, allowing access to loopback-only services via IPv4-mapped IPv6 loopback addresses. These vulnerabilities warrant careful review and timely updates.

The Linux kernel's KVM (Kernel-based Virtual Machine) component has a vulnerability (CVE-2026-64561) where checks for invalid or obsolete root memory management unit (MMU) pages are performed *after* these pages are made available. This could lead to potential security issues within virtualized environments. Users of affected Linux kernel versions should apply the necessary patches.

Intel Ethernet diagnostics driver for Windows versions prior to 1.3.1.0 (IQVW32.sys and IQVW64.sys) contains a vulnerability (CVE-2015-2291) that could allow local users to cause a denial of service or execute arbitrary code with kernel privileges. This is a critical KEV entry, indicating active exploitation and demanding immediate remediation.

A spoofing vulnerability in the AppX installer affects Microsoft Windows (CVE-2021-43890). Microsoft is aware of attacks attempting to exploit this by using specially crafted packages containing malware. This high-severity vulnerability is a KEV entry, emphasizing the need for vigilance and timely security updates.

The Zyxel EMG2926 home router, with firmware V1.00(AAQT.4)b8, is vulnerable to command injection (CVE-2017-6884) within its diagnostic tools, specifically the nslookup function. A malicious user could exploit this to execute arbitrary commands on the affected device. This critical KEV entry requires immediate attention from users of this router model.

The Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 is affected by an unspecified vulnerability (CVE-2012-1710). This critical flaw allows remote attackers to impact confidentiality, integrity, and availability via unknown vectors related to the Designer component. As a KEV entry, it signifies active exploitation and requires immediate patching.

Synthesized by Vypr AI
KEV Adds Critical Flaws in Ivanti, Webmin, Oracle, Zimbra · VYPR