Security Digest: March 16, 2026 - 13 Critical Vulnerabilities

Today, we highlight 13 critical vulnerabilities, including severe impacts on widely-used systems like Glances, Spinnaker, and authlib. Immediate action is required to patch affected systems and mitigate exploitation risks.

· 8 min read

Security Digest: March 16, 2026

Executive Summary

Today, we highlight 13 critical vulnerabilities, including severe impacts on widely-used systems like Glances, Spinnaker, and authlib. Immediate action is required to patch affected systems and mitigate exploitation risks.

Critical Vulnerabilities

  • CVE-2026-25534: URL Validation Bypass in Spinnaker
    • Impact: Allows unauthorized URL access bypassing previous security measures.
    • Affected Systems: Spinnaker versions prior to 2026.0.0
    • Immediate Action: Update to version 2026.0.0 immediately.
    • Mitigation: Disable affected artifacts as a temporary workaround.
  • CVE-2026-32633: Credential Disclosure in Glances
    • Impact: Unauthenticated access to sensitive server credentials.
    • Affected Systems: Glances instances without password protection.
    • Immediate Action: Implement strict authentication on API endpoints.
    • Mitigation: Strip credentials from API responses.
  • CVE-2026-27962: JWK Header Injection in authlib
    • Impact: Allows token forgery and bypass of authentication.
    • Affected Systems: authlib versions before 1.6.7
    • Immediate Action: Update to authlib version 1.6.7.
    • Mitigation: Ensure key verification uses application context only.
  • CVE-2026-28500: Security Bypass in onnx.hub.load()
    • Impact: Allows execution of untrusted models without warnings.
    • Affected Systems: ONNX versions using silent=True parameter.
    • Immediate Action: Avoid using silent=True until patched.
    • Mitigation: Implement additional repository verification checks.
  • CVE-2026-32634: Network Credential Exposure in Glances
    • Impact: Leak of authentication secrets via dynamic server names.
    • Affected Systems: Glances with autodiscovery enabled.
    • Immediate Action: Disable autodiscovery or restrict to trusted networks.
    • Mitigation: Use IP addresses for network connections.
  • CVE-2026-32610: CORS Misconfiguration in Glances
    • Impact: Enables cross-origin data theft from unauthenticated users.
    • Affected Systems: Glances with default CORS settings.
    • Immediate Action: Reconfigure CORS to restrict allowed origins and credentials.
    • Mitigation: Ensure CORS policies are explicitly defined.
  • CVE-2026-32813: SQL Injection in Admidio
    • Impact: Allows unauthorized database access and manipulation.
    • Affected Systems: Admidio's MyList configuration feature.
    • Immediate Action: Apply latest patches and validate all input fields.
    • Mitigation: Implement strict SQL parameterization.
  • CVE-2026-32606: TPM Bypass in IncusOS
    • Impact: Allows unauthorized access to encrypted data with physical access.
    • Affected Systems: IncusOS pre-20260314 versions.
    • Immediate Action: Upgrade to IncusOS version 20260314 or later.
    • Mitigation: Use updated TPM policies to restrict decryption keys.
  • CVE-2026-32749: Arbitrary File Write in SiYuan
    • Impact: Enables remote code execution through file manipulation.
    • Affected Systems: SiYuan versions with unsanitized filename handling.
    • Immediate Action: Apply patches to sanitize input filenames.
    • Mitigation: Restrict file write permissions to safe directories.
  • CVE-2026-32609: Sensitive Data Exposure in Glances
    • Impact: Exposes passwords and SNMP credentials through API.
    • Affected Systems: Glances without API authentication.
    • Immediate Action: Implement API authentication immediately.
    • Mitigation: Redact sensitive fields in API responses.
  • CVE-2026-29112: Memory Exhaustion in DiceBear Converter
    • Impact: Allows denial of service through excessive memory allocation.
    • Affected Systems: DiceBear Converter versions < 9.4.0
    • Immediate Action: Update to version 9.4.0 or later.
    • Mitigation: Validate SVG dimensions before processing.
  • CVE-2026-32608: Command Injection in Glances
    • Impact: Allows execution of arbitrary commands through malformed variables.
    • Affected Systems: Glances with action system enabled.
    • Immediate Action: Review and sanitize action definitions.
    • Mitigation: Escape all user-controllable variables during execution.
  • CVE-2026-32611: SQL Injection in DuckDB Export Module
    • Impact: Allows unauthorized SQL operations through unsanitized identifiers.
    • Affected Systems: Glances with DuckDB export enabled.
    • Immediate Action: Patch to use parameterized queries.
    • Mitigation: Quote all identifiers in SQL statements.

Previously Alerted

What to Do Now

  1. Immediately apply patches for all affected systems.
  2. Verify configurations to ensure secure settings are applied.
  3. Monitor network activity for signs of exploitation attempts.

Related Resources

  • Check vendor advisories for each product for detailed patch instructions.

Keep reading