Find notable cyber news and cases, enriched with sources, timelines, and signals.

Kaltura mwEmbedLoader.php access restrictions and ServiceUrl allow-list guidance

Advisory/Mitigation
First reported
Last updated
Happening score
H score 43
1 unique sources, 1 articles

Summary

Hide ▲

CERT/CC issued mitigation guidance for exposed Kaltura mwEmbedLoader.php deployments to reduce risk from the unpatched deserialization flaws. Administrators were told to restrict or disable external access to the endpoint and to strictly allow-list ServiceUrl so only legitimate backend API URLs are accepted. The guidance applies to deployments where the loader is reachable, including shared multi-tenant hosts, until a fixed release exists.

Related Happenings

Kaltura mwEmbedLoader unsafe deserialization flaws (multiple vulnerabilities)

Vulnerability
H score37 First: 26.08.2026 14:55 Last: 26.08.2026 14:55 Sources 1

How related: The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it.

About this happening: CERT/CC disclosed two unpatched Kaltura mwEmbedLoader vulnerabilities, CVE-2026-19913 and CVE-2026-19912, that expose html5lib v2.45, v2.103 and earlier to...

N-able security patch release for CVE-2026-18577

Security Patch Release
H score46 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

About this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...

N-able N-central servers hit by network compromise

Incident
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.

Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia

Campaign
H score47 First: 31.07.2026 18:00 Last: 31.07.2026 18:00 Sources 1

About this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...

CISA orders federal mitigation of CVE-2026-16812

Public Sector Action
H score36 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...

Timeline

  1. 26.08.2026 14:55 2 articles · 3h ago

    CERT/CC advises restricting access to Kaltura mwEmbedLoader.php

    Mitigation Patch Update

    CERT/CC discloses two unpatched Kaltura mwEmbed HTML5 player flaws, CVE-2026-19913 and CVE-2026-19912, in mwEmbedLoader.php and advises administrators to restrict or disable external access to the endpoint, enforce a strict allow-list for ServiceUrl, and treat exposed deployments as high risk until a fix exists.

    Show sources