Kaltura mwEmbedLoader.php access restrictions and ServiceUrl allow-list guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
CERT/CC issued mitigation guidance for exposed Kaltura mwEmbedLoader.php deployments to reduce risk from the unpatched deserialization flaws. Administrators were told to restrict or disable external access to the endpoint and to strictly allow-list ServiceUrl so only legitimate backend API URLs are accepted. The guidance applies to deployments where the loader is reachable, including shared multi-tenant hosts, until a fixed release exists.
Related Happenings
Kaltura mwEmbedLoader unsafe deserialization flaws (multiple vulnerabilities)
Vulnerability
H score37
First: 26.08.2026 14:55
Last: 26.08.2026 14:55
Sources 1
How related:
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it.
About this happening:
CERT/CC disclosed two unpatched Kaltura mwEmbedLoader vulnerabilities, CVE-2026-19913 and CVE-2026-19912, that expose html5lib v2.45, v2.103 and earlier to...
Kaltura mwEmbedLoader unsafe deserialization flaws (multiple vulnerabilities)
VulnerabilityHow related: The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it.
About this happening: CERT/CC disclosed two unpatched Kaltura mwEmbedLoader vulnerabilities, CVE-2026-19913 and CVE-2026-19912, that expose html5lib v2.45, v2.103 and earlier to...
N-able security patch release for CVE-2026-18577
Security Patch Release
H score46
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentAbout this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
Campaign
H score47
First: 31.07.2026 18:00
Last: 31.07.2026 18:00
Sources 1
About this happening:
The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
CampaignAbout this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
CISA orders federal mitigation of CVE-2026-16812
Public Sector Action
H score36
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
CISA orders federal mitigation of CVE-2026-16812
Public Sector ActionAbout this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
Timeline
-
26.08.2026 14:55 2 articles · 3h ago
CERT/CC advises restricting access to Kaltura mwEmbedLoader.php
Mitigation Patch UpdateCERT/CC discloses two unpatched Kaltura mwEmbed HTML5 player flaws, CVE-2026-19913 and CVE-2026-19912, in mwEmbedLoader.php and advises administrators to restrict or disable external access to the endpoint, enforce a strict allow-list for ServiceUrl, and treat exposed deployments as high risk until a fix exists.
Show sources
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code — thehackernews.com — 26.08.2026 14:55