Security Digest: January 27, 2026 - 6 Critical Vulnerabilities

Today, we highlight six critical vulnerabilities affecting popular software libraries and systems. Immediate action is required to mitigate risks of remote code execution, path traversal, and cross-site scripting.

· 4 min read

Executive Summary

Today, we highlight six critical vulnerabilities affecting popular software libraries and systems. Immediate action is required to mitigate risks of remote code execution, path traversal, and cross-site scripting. Update and patch affected systems without delay to prevent exploitation.

Critical Vulnerabilities

  • CVE-2026-23830: Sandbox Escape in @nyariv/sandboxjs
    • Impact: Remote Code Execution.
    • Affected Systems: npm @nyariv/sandboxjs.
    • Immediate Action: Disable @nyariv/sandboxjs or apply the latest patch.
    • Mitigation: Restrict access to environments using this library until patched.
  • CVE-2026-24747: PyTorch Checkpoint Corruption
    • Impact: Arbitrary code execution via crafted checkpoint files.
    • Affected Systems: pip PyTorch.
    • Immediate Action: Avoid using untrusted checkpoint files. Update PyTorch to latest version.
    • Mitigation: Enforce strict validation of all input files.
  • CVE-2026-24486: Path Traversal in python-multipart
    • Impact: Arbitrary file write on filesystem.
    • Affected Systems: pip python-multipart.
    • Immediate Action: Upgrade to version 0.0.22 or modify config to avoid vulnerable options.
    • Mitigation: Validate file paths in application logic.
  • CVE-2026-24470: Skipper Network Exposure via ExternalName
    • Impact: Potential unauthorized internal network access.
    • Affected Systems: go github.com/zalando/skipper.
    • Immediate Action: Update to Skipper v0.24.0 to disable ExternalName by default.
    • Mitigation: Use allow list for ExternalName targets.
  • CVE-2026-24490: MobSF Android Manifest XSS
    • Impact: Stored XSS leading to account takeover.
    • Affected Systems: pip mobsf.
    • Immediate Action: Sanitize inputs and update MobSF.
    • Mitigation: Restrict access to analysis reports.
  • CVE-2026-24765: Unsafe Deserialization in PHPUnit
    • Impact: Remote code execution via crafted .coverage files.
    • Affected Systems: composer phpunit/phpunit (multiple versions).
    • Immediate Action: Upgrade to the latest PHPUnit version.
    • Mitigation: Isolate CI/CD environments and enforce strict file permissions.

Previously Alerted

What to Do Now

  1. Patch all affected systems immediately.
  2. Verify system configurations to ensure no vulnerable settings are enabled.
  3. Monitor for suspicious activity in logs related to these vulnerabilities.

Related Resources

Keep reading