August 28, 2026
- Two unpatched Kaltura mwEmbed flaws (CVE-2026-19913, CVE-2026-19912) stem from unsafe deserialization in the
mwEmbedLoader.phpendpoint and give a remote unauthenticated attacker arbitrary file read and code execution; disclosed by CERT/CC with no vendor fix (The Hacker News). · Exploitation & Vulnerabilities
in Australia Charges Two Over the TeamPCP Supply-Chain Spree