Security Digest: January 28, 2026 - 7 Critical Vulnerabilities

Today's security digest covers seven critical vulnerabilities affecting popular software libraries and platforms. Immediate attention is required to address these threats, which could lead to account takeovers, unauthorized file access, and server-side request forgeries.

· 5 min read

Urgent Security Update for Developers and Security Teams

Today's security digest covers seven critical vulnerabilities affecting popular software libraries and platforms. Immediate attention is required to address these threats, which could lead to account takeovers, unauthorized file access, and server-side request forgeries.

Critical Vulnerabilities

  • CVE-2026-24838: Script Execution in DotNetNuke Core
    • Impact: Potential for scripts to execute in certain scenarios, risking unauthorized actions.
    • Affected Systems: Nuget DotNetNuke.Core
    • Immediate Action: Apply the latest patches from the vendor immediately.
    • Mitigation: Update to the latest secure version available on the Nuget repository.
  • CVE-2026-24778: JavaScript Execution in Ghost and Portal
    • Impact: Crafted links could execute JavaScript with victim's permissions, leading to account takeovers.
    • Affected Systems: Ghost versions 5.43.0 to 5.120.4, 6.0.0 to 6.14.0, Portal versions 2.29.1 to 2.57.0.
    • Immediate Action: Upgrade Ghost to v5.121.0 or v6.15.0 and ensure Portal loads the patch version.
    • Mitigation: Ensure auto-updates are enabled or manually update self-hosted installations.
  • CVE-2026-24842: Path Traversal in Node-Tar
    • Impact: Allows creation of hardlinks to arbitrary files, potentially leading to unauthorized file access or modifications.
    • Affected Systems: npm tar
    • Immediate Action: Update the tar package to the latest version that addresses this vulnerability.
    • Mitigation: Review and restrict file extraction permissions and paths.
  • CVE-2026-24837: Script Injection in DotNetNuke Persona Bar
    • Impact: Could allow scripts to execute during module operations.
    • Affected Systems: Nuget DotNetNuke.Core
    • Immediate Action: Apply available patches.
    • Mitigation: Regularly audit and sanitize inputs in the Persona Bar.
  • CVE-2026-24836: Script Execution in DotNetNuke Log Notes
    • Impact: Scripts could execute in the Persona Bar, potentially compromising security.
    • Affected Systems: Nuget DotNetNuke.Core
    • Immediate Action: Patch the affected systems immediately.
    • Mitigation: Implement input validation and update to secure versions.
  • CVE-2026-24783: Incorrect Calculation in Soroban-Fixed-Point-Math
    • Impact: Incorrect math operations could affect financial calculations and data integrity.
    • Affected Systems: Rust soroban-fixed-point-math
    • Immediate Action: Upgrade to version 1.4.1 or later.
    • Mitigation: Validate critical calculations using patched libraries.
  • CVE-2026-24779: SSRF in vLLM MediaConnector
    • Impact: Enables arbitrary requests to internal resources, risking data exposure or denial of service.
    • Affected Systems: Pip vllm
    • Immediate Action: Apply the fix from the latest GitHub pull request.
    • Mitigation: Restrict network access and validate URL inputs rigorously.

What to Do Now

  1. Review and apply patches for all listed vulnerabilities.
  2. Verify that updates are correctly applied and systems are secured.
  3. Monitor network and system logs for unusual activity related to these vulnerabilities.

Related Resources

  • Official vendor advisories for detailed patch information.
  • Company blog posts for deeper insights and mitigation strategies (coming soon).

Keep reading