SAP Exploited, Jahlives & Linux Kernel Flaws Disclosed
SAP Commerce Cloud exploitation, numerous Jahlives openssl_encrypt flaws, and critical Linux kernel vulnerabilities are highlighted today.

A critical vulnerability in SAP Commerce Cloud, CVE-2026-58231, is being actively exploited. This flaw allows unauthenticated attackers to abuse a default authentication client and submit specially crafted input to functions lacking sufficient validation, potentially leading to arbitrary code execution. The vulnerability was disclosed recently, and exploitation attempts were observed just three days after the patch was released, highlighting the urgency for affected organizations to update their systems. As The Hacker News reported, multiple news outlets have covered this critical issue, emphasizing the potential for severe impact.
Jahlives openssl_encrypt versions prior to 1.4.0 are affected by a suite of 25 critical vulnerabilities, including authentication bypass, sandbox escapes, and predictable key derivation. Notably, CVE-2026-74901 describes an authentication bypass where AES-GCM decryption failures fall back to unauthenticated AES-CTR mode, allowing ciphertext modification in transit. Additionally, CVE-2026-74900 details a critical flaw where KEM decapsulation failures silently revert to simulation mode, enabling attackers to generate deterministic shared secrets from minimal private key data. These issues, as detailed by Vypr Intelligence, pose a significant risk due to the potential for unauthorized access and code execution.
Multiple critical vulnerabilities have been identified in the Linux kernel, impacting various components. CVE-2026-74475 addresses an issue in vxlan where asynchronous updates to the neighbor hardware address could lead to race conditions. Another critical flaw, CVE-2026-74309, in the vdpa/octeon_ep component, has been resolved by fixing the IRQ-to-ring mapping in the interrupt handler to support non-contiguous IRQ numbers. Furthermore, CVE-2026-74280 and CVE-2026-74279 highlight DMA cleanup issues in the crypto subsystems for marvell/octeontx and cavium/cpt respectively, which could lead to leaked DMA buffers. These kernel vulnerabilities underscore the importance of timely patching for maintaining system security.
A critical vulnerability, CVE-2026-74843, has been discovered in Wavlink devices, specifically the WN531P3 and WN535M1 V250922 models. The vulnerability lies within the strcpy function in the Export Pingortrace CGI component, potentially allowing for remote code execution or other malicious actions through specially crafted input. While specific details on the attack vector are limited, the critical severity and CVSS score indicate a significant security risk for users of these Wavlink devices. Prompt patching or mitigation is advised for affected users.