What you need to know today.
Critical code injection and OS command injection flaws in InternLM and Ahsay, alongside multiple critical Zitadel vulnerabilities, lead today's security brief.

A critical code injection vulnerability in InternLM MindSearch 0.1.0 (CVE-2026-105135) allows attackers to execute arbitrary code by manipulating the 'inputs' argument in the ExecutionAction.run function within mindsearch/agent/graph.py. This high-risk flaw demands immediate attention from users of this AI model's search capabilities.
Ahsay AhsayCBS versions up to 10.3.2 are affected by a critical OS command injection vulnerability (CVE-2026-105134). Attackers can exploit this by manipulating the 'random' argument in the Replication Receiver component's UpdateReceivers.do endpoint, potentially leading to full system compromise.
Zitadel versions 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 contain a critical flaw where user accounts are linked to external identity providers without proper verification, including during identify-only Login V2 sessions. This improper authorization allows for account takeover. Additionally, Zitadel versions before 3.4.14 and 4.x before 4.16.2 suffer from an authentication bypass in the hosted Login V1 UI (CVE-2026-105215), where the external account registration endpoint trusts client-supplied fields without a completed IdP challenge. Further, Zitadel 3.x before 3.4.15 and 4.x before 4.17.1 have a missing authentication flaw in the hosted Login V1 UI (CVE-2026-105210), allowing second-factor enrollment on identify-only sessions. Zitadel 4.x before 4.17.1 also fails to check an organization's inactive state during Login V2 authentication (CVE-2026-105213), allowing users of deactivated organizations to maintain access. Finally, Zitadel versions before 4.17.1 have an authentication bypass in Login V2 (CVE-2026-105211), enabling attackers to take over accounts by obtaining OTP codes via the returnCode delivery type.
WordPress plugins are facing multiple critical and high-severity vulnerabilities. Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) is affected by a blind SQL injection vulnerability (CVE-2026-103355) and a reflected cross-site scripting flaw (CVE-2026-103344). Additionally, Gutenberg Blocks by Kadence Blocks suffers from a stored cross-site scripting vulnerability (CVE-2026-103354). These issues pose significant risks to WordPress sites relying on these plugins.
A remote code execution vulnerability exists in Vincent Peugnet's WCMS through 3.18.0 (CVE-2026-105123). Authenticated editors can exploit this by uploading arbitrary files via the unvalidated path in the media upload API, allowing for RCE.
WWBN AVideo versions up to 29.2.0 are impacted by two stored cross-site scripting vulnerabilities. CVE-2026-105089 allows script injection via malicious video trailer URLs, while CVE-2026-105086 enables HTML injection through doubly-encoded entities in video titles, both posing risks to users viewing content on AVideo platforms.
StylemixThemes Cost Calculator Builder through version 4.0.17 has a vulnerability (CVE-2026-97307) that allows for the retrieval of embedded sensitive data, posing a risk to data confidentiality.
RainyGao DocSys up to 2.02.85 contains a critical vulnerability in its database management component (CVE-2026-105158). Manipulating the 'url' argument in the createDBForMysql function can lead to unauthorized access or modification of database configurations.
MooSocial versions up to 3.2.4 are affected by a SQL injection vulnerability (CVE-2026-105149) in the /stores/all-products endpoint. Attackers can exploit this by manipulating the 'rating' argument, potentially leading to data breaches or unauthorized data manipulation.
SciPhi-AI R2R versions up to 3.6.6 have multiple high-severity issues. CVE-2026-105148 involves a vulnerability in the Retrieval Completion API Endpoint where manipulation of the 'generation_' argument can lead to unintended consequences. Furthermore, CVE-2026-105147 reveals hard-coded credentials in the JWT Secret Handler due to manipulation of the DEFAULT_BCRYPT_SECRET_KEY/DEFAULT_NACL_SECRET_KEY arguments, posing a significant security risk.
Ahsay AhsayCBS up to 10.3.2 has another vulnerability (CVE-2026-105133) in its API component. Manipulating the 'random' argument in the checkSysPwd function can result in improper authentication, potentially allowing unauthorized access.