VYPR
AI Brief2026-09-05· generated Sep 4, 2026

What you need to know today.

Critical RCE flaws hit Veeam ONE and vm2 Node.js library, alongside numerous WordPress plugin vulnerabilities.

A critical remote code execution vulnerability in Veeam ONE allows unauthenticated attackers to compromise agent hosts. The exact versions affected are not specified, but the vulnerability poses a significant risk given Veeam's widespread use in enterprise environments for backup and recovery. Immediate patching or mitigation is advised. CVE-2026-64633 was highlighted in Cyber Security News and Cyber Security News.

Two critical vulnerabilities in the vm2 Node.js sandbox library, CVE-2026-44005 and CVE-2026-43997, allow for sandbox escapes and arbitrary code execution. These flaws stem from issues with mutable proxies and the ability to obtain host objects, respectively. The vulnerabilities affect versions prior to 3.11.0 and are particularly concerning for applications relying on vm2 for secure execution of untrusted code. The Hacker News reported on these critical flaws.

A critical vulnerability in the WordPress Embed HTML5 Game plugin (versions up to 1.3) allows unauthenticated attackers to upload PHP backdoors, leading to site compromise. This is due to insufficient restrictions on file uploads. Additionally, several other WordPress plugins, including Divi Ajax Filter (CVE-2026-11613), JobSearch (CVE-2026-84834), Bricksforge (CVE-2026-84814), and Mail Mint (CVE-2026-84753), have critical vulnerabilities ranging from local file inclusion and object injection to privilege escalation. Vypr Intelligence covered the Embed HTML5 Game plugin flaw.

Critical vulnerabilities have been disclosed across various AI and machine learning platforms. OpenTalker's SadTalker (CVE-2026-85696) suffers from OS command injection due to unsanitized audio filenames. Getomni AI's zerox (CVE-2026-85672) has OS command injection in its file download mechanism. Aimhubio's Aim (CVE-2026-85663) allows unauthenticated attackers to invoke arbitrary methods. Sciphi AI's R2R (CVE-2026-82526) contains a stacked SQL injection vulnerability. These flaws highlight the need for robust security practices in the rapidly evolving AI landscape.

Several critical vulnerabilities affect web applications and frameworks. Miniorange.com's Joomla Extension OAuth Client (versions < 3.2.0) has an arbitrary account takeover flaw via cookie manipulation (CVE-2026-77995). Stuub's WGDashboard (versions 4.2.3 and earlier) has multiple OS command injection vulnerabilities allowing authenticated attackers to execute commands as root (CVE-2026-15733). TEN Framework (0.11.71) has arbitrary file read/write vulnerabilities in its TMAN Designer API (CVE-2026-85688). IBM Operational Decision Manager (multiple versions) is vulnerable to SQL injection (CVE-2026-18658).

Critical vulnerabilities have been identified in network devices and infrastructure. Versa Networks Director has a critical vulnerability related to default PostgreSQL passwords, potentially allowing unauthorized access to sensitive data (CVE-2024-42450). Dlink DNS-340L (1.01B04) has a vulnerability in its CGI handler that could be exploited via manipulation of specific arguments (CVE-2026-85223). Peppermint Lab's Peppermint (through 0.5.5) has a hardcoded JWT signing secret, enabling unauthenticated attackers to forge session tokens (CVE-2026-85391).

Synthesized by Vypr AI
Critical RCEs and Plugin Flaws Dominate CVE Briefing · VYPR