🛡️ tsecurity.de
Zur Startseite 🔖 Lesezeichen
🎯 FOKUSSIERTE SCHWACHSTELLE: CVE-2026-19912 CRITICAL 9.5 🔥 EPSS 77.4%
Alle CVEs anzeigen ✕

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The

Angriffsvektor: 🌐 Netzwerk (Remote) • 🔓 Keine Authentifizierung nötig
CWE-Klassifizierung: CWE-94: Code Injection
🔴 Live Security Advisory & EPSS Exploit Radar

Zero-Day & Vulnerability Intelligence Hub

Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.

🟢 SSE Realtime Synchronisiert ⚡ REST API (JSON) 📡 RSS Feed
Ökosystem & Hersteller Bedrohungs-Matrix:
Generic Security 1
Schweregrad & Status:
Hersteller-Filter:
🔍
CRITICAL 9.5 🔥 EPSS 77.4%
Generic Security
CVE-2026-19912 🌐 Netzwerk (Remote) 🔓 Keine Authentifizierung nötig

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The

CWE-94: Code Injection ✓ Offizieller Patch / Advisory verfügbar
💡 Gegenmaßnahme: Sicherheits-Update des Herstellers zeitnah einspielen und Netzwerksegmentierung prüfen.