Security Digest: March 16, 2026 - 13 Critical Vulnerabilities
Today, we highlight 13 critical vulnerabilities, including severe impacts on widely-used systems like Glances, Spinnaker, and authlib. Immediate action is required to patch affected systems and mitigate exploitation risks.
· 8 min read
Security Digest: March 16, 2026
Executive Summary
Today, we highlight 13 critical vulnerabilities, including severe impacts on widely-used systems like Glances, Spinnaker, and authlib. Immediate action is required to patch affected systems and mitigate exploitation risks.
Critical Vulnerabilities
- CVE-2026-25534: URL Validation Bypass in Spinnaker
- Impact: Allows unauthorized URL access bypassing previous security measures.
- Affected Systems: Spinnaker versions prior to 2026.0.0
- Immediate Action: Update to version 2026.0.0 immediately.
- Mitigation: Disable affected artifacts as a temporary workaround.
- CVE-2026-32633: Credential Disclosure in Glances
- Impact: Unauthenticated access to sensitive server credentials.
- Affected Systems: Glances instances without password protection.
- Immediate Action: Implement strict authentication on API endpoints.
- Mitigation: Strip credentials from API responses.
- CVE-2026-27962: JWK Header Injection in authlib
- Impact: Allows token forgery and bypass of authentication.
- Affected Systems: authlib versions before 1.6.7
- Immediate Action: Update to authlib version 1.6.7.
- Mitigation: Ensure key verification uses application context only.
- CVE-2026-28500: Security Bypass in onnx.hub.load()
- Impact: Allows execution of untrusted models without warnings.
- Affected Systems: ONNX versions using silent=True parameter.
- Immediate Action: Avoid using silent=True until patched.
- Mitigation: Implement additional repository verification checks.
- CVE-2026-32634: Network Credential Exposure in Glances
- Impact: Leak of authentication secrets via dynamic server names.
- Affected Systems: Glances with autodiscovery enabled.
- Immediate Action: Disable autodiscovery or restrict to trusted networks.
- Mitigation: Use IP addresses for network connections.
- CVE-2026-32610: CORS Misconfiguration in Glances
- Impact: Enables cross-origin data theft from unauthenticated users.
- Affected Systems: Glances with default CORS settings.
- Immediate Action: Reconfigure CORS to restrict allowed origins and credentials.
- Mitigation: Ensure CORS policies are explicitly defined.
- CVE-2026-32813: SQL Injection in Admidio
- Impact: Allows unauthorized database access and manipulation.
- Affected Systems: Admidio's MyList configuration feature.
- Immediate Action: Apply latest patches and validate all input fields.
- Mitigation: Implement strict SQL parameterization.
- CVE-2026-32606: TPM Bypass in IncusOS
- Impact: Allows unauthorized access to encrypted data with physical access.
- Affected Systems: IncusOS pre-20260314 versions.
- Immediate Action: Upgrade to IncusOS version 20260314 or later.
- Mitigation: Use updated TPM policies to restrict decryption keys.
- CVE-2026-32749: Arbitrary File Write in SiYuan
- Impact: Enables remote code execution through file manipulation.
- Affected Systems: SiYuan versions with unsanitized filename handling.
- Immediate Action: Apply patches to sanitize input filenames.
- Mitigation: Restrict file write permissions to safe directories.
- CVE-2026-32609: Sensitive Data Exposure in Glances
- Impact: Exposes passwords and SNMP credentials through API.
- Affected Systems: Glances without API authentication.
- Immediate Action: Implement API authentication immediately.
- Mitigation: Redact sensitive fields in API responses.
- CVE-2026-29112: Memory Exhaustion in DiceBear Converter
- Impact: Allows denial of service through excessive memory allocation.
- Affected Systems: DiceBear Converter versions < 9.4.0
- Immediate Action: Update to version 9.4.0 or later.
- Mitigation: Validate SVG dimensions before processing.
- CVE-2026-32608: Command Injection in Glances
- Impact: Allows execution of arbitrary commands through malformed variables.
- Affected Systems: Glances with action system enabled.
- Immediate Action: Review and sanitize action definitions.
- Mitigation: Escape all user-controllable variables during execution.
- CVE-2026-32611: SQL Injection in DuckDB Export Module
- Impact: Allows unauthorized SQL operations through unsanitized identifiers.
- Affected Systems: Glances with DuckDB export enabled.
- Immediate Action: Patch to use parameterized queries.
- Mitigation: Quote all identifiers in SQL statements.
Previously Alerted
What to Do Now
- Immediately apply patches for all affected systems.
- Verify configurations to ensure secure settings are applied.
- Monitor network activity for signs of exploitation attempts.
Related Resources
- Check vendor advisories for each product for detailed patch instructions.