VYPR
AI Brief2026-08-22· generated Aug 22, 2026

What you need to know today.

CISA adds exploited TrueConf flaws to KEV; MLflow SSRF actively exploited; Cisco, IBM, and others patch critical vulnerabilities.

Two critical vulnerabilities in TrueConf, a video conferencing platform, have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-72529 allows for arbitrary script execution, while CVE-2026-72530 enables an attacker to break out of an isolated environment. Both affect TrueConf server versions 5.3.X through 5.5.5 and earlier, and are accessible remotely via port 4307/TCP. Immediate patching is advised by CISA and other security outlets. The Register Security reported, and SecurityWeek noted, that these flaws pose a significant risk.

A critical Server-Side Request Forgery (SSRF) vulnerability in MLflow, an open-source AI engineering platform, is being actively exploited in the wild to steal cloud credentials. CVE-2026-64849 affects versions prior to 3.15.0 and allows unauthenticated attackers to exploit the POST /api/2.0/mlflow/webhooks/{id}/test endpoint. This flaw was added to the CISA KEV catalog, as reported by CISA Alerts. The Hacker News and SecurityWeek highlighted the severity and active exploitation of this vulnerability.

Cisco has released a software hardening release addressing multiple critical vulnerabilities across its Crosswork and Secure Workload products. Notably, CVE-2026-20315, a critical flaw in Cisco Secure Workload, allows for arbitrary code execution. Several other vulnerabilities with high CVSS scores were also patched, as detailed by The Hacker News and SecurityWeek.

A critical pre-authentication PHP code injection vulnerability, CVE-2026-67364, has been disclosed in the Balbooa Forms Joomla extension, specifically in versions prior to 2.4.3.2. This flaw, rated Critical with a CVSS score of 9.8, allows unauthenticated attackers to execute arbitrary PHP code on the server. Vypr Intelligence reported on this and other Joomla-related vulnerabilities.

Multiple critical vulnerabilities affecting IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1, have been disclosed. These include buffer overflows (CVE-2026-17152, CVE-2026-17141, CVE-2026-17122), improper privilege management (CVE-2026-17145), improper authentication (CVE-2026-17142), a use-after-free vulnerability (CVE-2026-17118), and a format string vulnerability (CVE-2026-17136). All these flaws could allow remote attackers to execute arbitrary code or commands.

A critical vulnerability in the WordPress plugin "Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code" has been identified. CVE-2026-77264, affecting versions up to 4.8.6, allows for an authentication bypass due to a flaw in the handle_email_otp_return() function. Vypr Intelligence noted this as part of a larger disclosure of WordPress plugin vulnerabilities.

Three Rust crates—arrayref (0.3.10), append-only-vec (0.1.9), and internment (0.8.7)—have been found to contain critical vulnerabilities that could lead to malicious code execution during the compilation process. These crates have rogue dependencies that register with command-and-control servers, offering arbitrary code execution. The affected CVEs are CVE-2026-77651, CVE-2026-77650, and CVE-2026-77649, respectively.

A critical vulnerability in Samba, CVE-2025-10230, allows for remote code execution due to improper validation and escaping of NetBIOS names in the front-end WINS hook handling. Unsanitized data from WINS registration packets can be inserted into a shell command, leading to potential compromise.

Oracle has released patches for a critical vulnerability in its Oracle Internet Directory product, specifically the OID LDAP Server component. CVE-2026-61241 affects versions 12.2.1.4.0 and 14.1.2.1.0, and allows unauthenticated attackers to exploit the vulnerability, as reported by Cyber Security News.

A critical vulnerability was found in TRENDnet TEW-WLC100 firmware version 1v2.07b01. CVE-2026-75784 affects the HTTP Header Handler component, where manipulation of the 'Server' argument can lead to a stack-based buffer overflow, potentially allowing remote code execution.

A critical command injection vulnerability has been discovered in Comfast CF-N1-S firmware version 2.6.0.1. CVE-2026-77683 affects the system function within the /cgi-bin/mbox-config?method=SET&section=ntp_timezone endpoint, allowing attackers to inject arbitrary commands by manipulating the timestr argument.

Synthesized by Vypr AI
TrueConf, MLflow Exploits Lead Daily Security Briefing · VYPR