VYPR
AI Brief2026-09-28· generated Sep 28, 2026

What you need to know today.

Critical vulnerabilities disclosed in Adobe Campaign Classic, Joomla extensions, and Dahua EIMS pose significant RCE and command injection risks.

Multiple critical vulnerabilities have been disclosed in Adobe Campaign Classic (ACC), including code injection and server-side request forgery (SSRF) flaws. These vulnerabilities, detailed in CVE-2026-75699, CVE-2026-89276, and CVE-2026-82013, could allow unauthenticated attackers to execute arbitrary code or escalate privileges. The SSRF vulnerability, CVE-2026-82013, specifically could enable a low-privileged attacker to gain elevated access to internal resources. As Adobe Campaign Classic: 17 Critical Vulnerabilities Disclosed Together, Including Code Injection and SSRF reported, these issues collectively pose a significant risk to users of ACC.

Critical vulnerabilities affecting Joomla extensions have been detailed, with a particular focus on the UP plugin from lomart.fr. CVE-2026-97163 describes an unauthenticated remote code installation flaw, while CVE-2026-97160 points to an authenticated, privileged PHP command injection vulnerability. Additionally, CVE-2026-97161 highlights various path traversal and file access vectors. These issues, affecting versions 5.0.0-5.2.0 and 6.0.0-6.0.29, were disclosed together and could lead to significant compromise, as noted by Vypr Intelligence.

A critical command injection vulnerability in Dahua EIMS, identified as CVE-2024-13985, allows unauthenticated remote attackers to execute arbitrary system commands. The flaw resides in the capture_handle.action interface due to improper input validation. This could lead to a full system compromise if exploited.

Wikimedia Foundation's Mediawiki ExternalData Extension is affected by an OS command injection vulnerability, CVE-2026-100382. This flaw arises from the improper neutralization of special elements used in OS commands, potentially allowing attackers to execute arbitrary commands on the server.

Fortinet FortiPAM Chrome Extension versions 8.0 and 7.4 are impacted by a vulnerability (CVE-2026-84388) that could allow an unauthenticated remote attacker to disclose information. This is due to an improper restriction of rendered UI layers or frames. SecurityWeek also reported on this, noting that Fortinet has released patches for this and other vulnerabilities.

Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 contain a remote code execution vulnerability in the addParam function. CVE-2024-32641 arises from the function accepting user input without proper sanitization, enabling attackers to inject and execute malicious code.

Multiple critical vulnerabilities have been disclosed in Joomla extensions, including an arbitrary file upload vulnerability in AcyMailing Enterprise extension versions prior to 11.1.0 (CVE-2026-94132). This flaw stems from MIME parts of incoming emails being saved without proper extension checks, allowing for the upload of malicious files.

A path traversal vulnerability in QiAnXin TianQing Management Center (versions up to 6.7.0.4130) allows unauthenticated attackers to upload files to arbitrary locations on the server via the rptsvr component (CVE-2024-13984). This could be used to overwrite critical system files or upload web shells.

A remote command execution vulnerability exists in H3C Intelligent Management Center (IMC) versions up to E0632H07 (CVE-2024-13980). The vulnerability in the /byod/index.xhtml endpoint is due to improper handling of JSF ViewState, allowing unauthenticated attackers to craft malicious requests to execute commands.

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to arbitrary file upload in all versions up to 2.9.2 (CVE-2026-18143). This is due to missing file extension and MIME type validation in the afrfq_submit_quote_via_popup() function, allowing attackers to upload malicious files.

LiveBOS, an object-oriented business architecture middleware suite, has an arbitrary file upload vulnerability in its UploadFile.do;.js.jsp endpoint (CVE-2024-13981). This affects the LiveBOS Server component and could allow attackers to upload and execute malicious files.

D-Link DIR-895L A1_102b07 is affected by an out-of-bounds write vulnerability in the tunnel_set_params function of the L2TP Control Channel Parser (CVE-2026-100740). This could lead to a denial-of-service or potentially remote code execution.

Claroty devices are affected by two critical vulnerabilities. CVE-2023-49900 allows unauthenticated remote code execution due to incorrectly sanitized user input in the SetParameter command. CVE-2023-49899 enables unauthenticated remote attackers to execute any command by exploiting improper verification of communication channel origins.

Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806, and Synology Unified Controller (DSMUC) before 3.1.4-23079, are vulnerable to Cross-Site Request Forgery (CSRF) in the WebAPI Framework (CVE-2024-45538). This could allow remote attackers to execute arbitrary actions on behalf of authenticated users.

An iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and earlier (CVE-2024-27708) allows remote attackers to execute arbitrary code via the src parameter. This could be used to host malicious content or redirect users to phishing sites.

Synthesized by Vypr AI
Critical Flaws Hit Adobe, Joomla, and Dahua · VYPR