VYPR
AI Brief2026-08-18· generated Aug 18, 2026

What you need to know today.

SAP Commerce Cloud actively exploited; critical flaws in Jahlives openssl_encrypt, Linux kernel, and networking devices disclosed.

A critical vulnerability in SAP Commerce Cloud, CVE-2026-58231, is being actively exploited in the wild. This flaw allows unauthenticated attackers to abuse a default authentication client and submit specially crafted input to functions lacking sufficient validation, potentially leading to arbitrary code execution. The exploitation attempts began just three days after disclosure, highlighting the urgency for organizations to patch their systems. As The Hacker News reported, this vulnerability poses a significant risk to businesses relying on SAP Commerce Cloud for their e-commerce operations.

Multiple critical vulnerabilities have been disclosed in Jahlives openssl_encrypt versions prior to 1.4.0, collectively posing a severe risk. CVE-2026-74901 and CVE-2026-74894 detail authentication bypass flaws, with the former allowing ciphertext modification in transit and the latter enabling attackers to bypass token validation. Additionally, CVE-2026-74900 describes a critical flaw in KEM decapsulation that falls back to simulation mode, enabling deterministic shared secret generation. Sandbox escape vulnerabilities, CVE-2026-74899 and CVE-2026-74896, allow attackers to traverse Python class hierarchies and bypass AST analysis, respectively. Further issues include unrestricted plugin execution (CVE-2026-74895), hardcoded database credentials (CVE-2026-74891), predictable key derivation (CVE-2026-74889), and a plugin sandbox bypass (CVE-2026-74886). Finally, CVE-2026-74880 allows attackers to extract refresh tokens from server logs and other sources.

A significant number of critical vulnerabilities have been identified in the Linux kernel, impacting various components. CVE-2026-74475 addresses a flaw in vxlan where the neighbor hardware address could be updated asynchronously. CVE-2026-74309 fixes an IRQ-to-ring mapping issue in vdpa/octeon_ep. The crypto subsystems in Marvell/OcteonTX (CVE-2026-74280) and Cavium/CPT (CVE-2026-74279) have DMA cleanup issues. Networking components are also affected, with CVE-2026-72421 preventing the ignoring of error routes in IPv4 fib lookups when multiple tables are enabled, and CVE-2026-72408 and CVE-2026-72407 addressing GRO hint handling and inner network offset validation in Geneve. These vulnerabilities collectively highlight the need for prompt kernel updates to maintain system security.

Critical vulnerabilities have been found in Wavlink devices, specifically the WN531P3 and WN535M1 V250922 models. CVE-2026-74843 affects the Export Pingortrace CGI component, where a strcpy vulnerability in the /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi file could allow remote exploitation. Additionally, EFM ipTIME A3004T 14.19.0 is affected by CVE-2026-19977, a session validation vulnerability that results in improper authentication. These flaws in consumer networking devices underscore the importance of securing edge devices.

Synthesized by Vypr AI
SAP Commerce Cloud Exploited; Multiple Critical Vulnerabilities Disclosed · VYPR