Security Digest: June 25, 2026 - 24 Critical Vulnerabilities

Today’s alert is dominated by Quest NetVault Backup flaws that can lead to remote code execution and authentication bypass, including multiple high-severity SQL injection and command injection issues. We are also tracking urgent fixes for GitLab EE/CE, Rapid7 InsightConnect plugins, Cacti, WordPress plugins, OpenBSD, and shell-quote.

· 15 min read

Executive Summary

Today’s alert is dominated by Quest NetVault Backup flaws that can lead to remote code execution and authentication bypass, including multiple high-severity SQL injection and command injection issues. We are also tracking urgent fixes for GitLab EE/CE, Rapid7 InsightConnect plugins, Cacti, WordPress plugins, OpenBSD, and shell-quote.

Immediate priority: patch exposed systems now, restrict access to admin and automation interfaces, and assume any unpatched NetVault Backup instance is at elevated risk. Several issues require user interaction or authenticated access, but the combination of bypasses and injection flaws makes exploitation practical.

Critical Vulnerabilities

  • CVE-2026-7569: Quest NetVault Backup viewclient XSS authentication bypass
    • Impact: Remote attackers can bypass authentication and potentially chain to SYSTEM-level code execution.
    • Affected Systems: Quest NetVault Backup installations with the vulnerable viewclient webpage.
    • Immediate Action: Restrict access to the web interface immediately and apply vendor fixes as soon as available.
    • Mitigation: Patch, disable unnecessary web exposure, and review for suspicious browser-delivered payloads.
  • CVE-2026-9781: Quest NetVault Backup NVBURASDevice SQL injection RCE
    • Impact: Remote code execution as NETWORK SERVICE.
    • Affected Systems: Quest NetVault Backup JSON-RPC processing for NVBURASDevice.
    • Immediate Action: Treat as internet-facing RCE risk; isolate management access now.
    • Mitigation: Patch immediately and block untrusted access to JSON-RPC endpoints.
  • CVE-2026-9782: Quest NetVault Backup NVBUDeviceDrive SQL injection RCE
    • Impact: Remote code execution as NETWORK SERVICE.
    • Affected Systems: NVBUDeviceDrive JSON-RPC handlers.
    • Immediate Action: Restrict admin interfaces and apply the vendor update.
    • Mitigation: Patch and monitor for abnormal database queries.
  • CVE-2026-9783: Quest NetVault Backup NVBURemovableMedia SQL injection RCE
    • Impact: Remote code execution as NETWORK SERVICE.
    • Affected Systems: NVBURemovableMedia JSON-RPC handlers.
    • Immediate Action: Remove public exposure and patch now.
    • Mitigation: Update NetVault and review logs for injected parameters.
  • CVE-2026-9784: Quest NetVault Backup NVBULibraryPort SQL injection RCE
    • Impact: Remote code execution as NETWORK SERVICE.
    • Affected Systems: NVBULibraryPort JSON-RPC handlers.
    • Immediate Action: Limit access to trusted admin networks only.
    • Mitigation: Patch and rotate credentials if exposure is suspected.
  • CVE-2026-9785: Quest NetVault Backup NVBULibrarySlot SQL injection RCE
    • Impact: Remote code execution as NETWORK SERVICE.
    • Affected Systems: NVBULibrarySlot JSON-RPC handlers.
    • Immediate Action: Apply fixes across all NetVault servers in scope.
    • Mitigation: Patch and restrict RPC traffic at the network layer.
  • CVE-2026-9786: Quest NetVault Backup NVBUDashboard SQL injection RCE
    • Impact: Remote code execution as NETWORK SERVICE.
    • Affected Systems: NVBUDashboard JSON-RPC handlers.
    • Immediate Action: Disable unnecessary dashboard access until patched.
    • Mitigation: Update immediately and inspect for anomalous dashboard requests.
  • CVE-2026-9787: Quest NetVault Backup NVBULogDaemon command injection RCE
    • Impact: Remote code execution as SYSTEM.
    • Affected Systems: NVBULogDaemon JSON-RPC handlers.
    • Immediate Action: Prioritize this above routine maintenance; patch immediately.
    • Mitigation: Restrict access, update, and review host-level command execution telemetry.
  • CVE-2026-7570: Quest NetVault Backup NVBUDashboard SQL injection RCE
    • Impact: Remote code execution as NETWORK SERVICE.
    • Affected Systems: NetVault NVBUDashboard JSON-RPC processing.
    • Immediate Action: Treat as a second independent path to compromise and patch now.
    • Mitigation: Apply vendor remediation and segment backup management systems.
  • CVE-2026-9780: Quest NetVault Backup addclient3 XSS authentication bypass
    • Impact: Authentication bypass that can be chained to SYSTEM-level execution.
    • Affected Systems: NetVault addclient3 webpage.
    • Immediate Action: Block access to the page and warn users not to open unsolicited files or links.
    • Mitigation: Patch and harden browser-based admin workflows.
  • CVE-2026-10086: GitLab EE client-side code execution in another user’s session
    • Impact: Authenticated developer-role users may execute code in another user’s browser session.
    • Affected Systems: GitLab EE 16.4 < 18.11.6, 19.0 < 19.0.3, 19.1 < 19.1.1.
    • Immediate Action: Upgrade GitLab EE immediately and review developer-role access.
    • Mitigation: Patch, limit privileged project access, and monitor for malicious content injections.
  • CVE-2026-12053: GitLab EE Duo Workflows sensitive data exposure
    • Impact: Users may access sensitive information already committed to a project.
    • Affected Systems: GitLab EE 19.1 < 19.1.1.
    • Immediate Action: Patch and review repositories for secrets exposure.
    • Mitigation: Upgrade and scan for leaked credentials or tokens.
  • CVE-2026-10712: GitLab CE/EE arbitrary JavaScript via path validation flaw
    • Impact: Unauthenticated attackers can execute JavaScript in a user’s browser session.
    • Affected Systems: GitLab CE/EE 18.10 < 18.11.6, 19.0 < 19.0.3, 19.1 < 19.1.1.
    • Immediate Action: Patch all GitLab instances exposed to users now.
    • Mitigation: Upgrade and enforce strict access controls on user-facing paths.
  • CVE-2026-8666: Rapid7 InsightConnect Traceroute Plugin OS command injection
    • Impact: Remote attackers can execute arbitrary OS commands.
    • Affected Systems: InsightConnect Traceroute Plugin on Linux.
    • Immediate Action: Disable or restrict the plugin until patched.
    • Mitigation: Update immediately and validate all input parameters.
  • CVE-2026-8665: Rapid7 InsightConnect Translate Plugin OS command injection
    • Impact: Remote OS command execution.
    • Affected Systems: InsightConnect Translate Plugin on Linux.
    • Immediate Action: Remove untrusted access to automation workflows using this plugin.
    • Mitigation: Patch and review workflow inputs for abuse.
  • CVE-2026-8592: Rapid7 InsightConnect AWK Plugin OS command injection
    • Impact: Remote OS command execution.
    • Affected Systems: InsightConnect AWK Plugin on Linux.
    • Immediate Action: Suspend affected automations until updated.
    • Mitigation: Patch and audit all expression/text inputs.
  • CVE-2026-8660: Rapid7 InsightConnect Ping Plugin OS command injection
    • Impact: Remote OS command execution.
    • Affected Systems: InsightConnect Ping Plugin on Linux.
    • Immediate Action: Restrict use of the plugin and update immediately.
    • Mitigation: Patch and monitor for unexpected shell activity.
  • CVE-2026-39951: Cacti stored SQL injection in Reports
    • Impact: Stored SQL injection that can lead to broader compromise of reporting data and backend systems.
    • Affected Systems: Cacti 1.2.30 and prior.
    • Immediate Action: Upgrade to 1.2.31 now.
    • Mitigation: Patch and review report inputs for tampering.
  • CVE-2026-12937: Tourfic WordPress plugin unauthenticated SQL injection
    • Impact: Attackers can extract sensitive database information without authentication.
    • Affected Systems: Tourfic plugin 2.22.7 and earlier.
    • Immediate Action: Update the plugin immediately or disable it until fixed.
    • Mitigation: Patch, review public AJAX endpoints, and check database logs.
  • CVE-2026-12077: Dokan Pro WordPress time-based SQL injection
    • Impact: Unauthenticated data extraction from the database.
    • Affected Systems: Dokan Pro 5.0.4 and earlier.
    • Immediate Action: Patch the plugin and limit public-facing store APIs.
    • Mitigation: Upgrade and monitor for slow-query abuse.
  • CVE-2026-13311: shell-quote denial of service
    • Impact: Small attacker-controlled input can freeze the Node.js event loop, causing service outage.
    • Affected Systems: shell-quote < 1.8.5.
    • Immediate Action: Upgrade to 1.8.5 immediately.
    • Mitigation: Patch and rate-limit any code paths that parse user input.
  • CVE-2026-57589: OpenBSD sysv_sem use-after-free local privilege escalation
    • Impact: Local attackers can escalate privileges to root.
    • Affected Systems: OpenBSD through 7.9.
    • Immediate Action: Apply the OpenBSD security update as soon as it is available.
    • Mitigation: Patch and reduce local shell access on affected hosts.
  • CVE-2026-9154: Rapid7 InsightConnect Sed Plugin arbitrary file write
    • Impact: Authenticated attackers can write attacker-controlled content to arbitrary file paths.
    • Affected Systems: InsightConnect Sed Plugin on Linux.
    • Immediate Action: Disable or isolate the plugin until patched.
    • Mitigation: Update immediately and verify file integrity across automation hosts.
  • CVE-2026-9155: Rapid7 InsightConnect Sed Plugin OS command injection
    • Impact: Authenticated attackers can execute arbitrary OS commands via the expression parameter.
    • Affected Systems: InsightConnect Sed Plugin on Linux.
    • Immediate Action: Patch and review all workflows using this plugin.
    • Mitigation: Restrict access, upgrade, and monitor for shell execution.

What to Do Now

  1. Patch first: Prioritize Quest NetVault Backup, GitLab, and Rapid7 InsightConnect systems exposed to users or automation.
  2. Reduce exposure: Block management web UIs, JSON-RPC endpoints, and plugin interfaces from untrusted networks.
  3. Disable risky components: Turn off affected plugins and public AJAX handlers until updates are verified.
  4. Verify versions: Confirm you are not running vulnerable builds, especially NetVault, GitLab, Cacti, Tourfic, Dokan Pro, and shell-quote.
  5. Assume compromise if exposed: Review for unexpected admin logins, new accounts, web shell indicators, and abnormal command execution.

Verification steps: inventory affected products, compare installed versions against the vulnerable ranges above, confirm vendor patches are applied, and validate that exposed services are no longer reachable from the internet.

Monitoring recommendations: watch for unusual SQL queries, shell spawning from automation services, suspicious browser activity, and changes to backup or GitLab project data. Pay close attention to any signs of credential theft or secret leakage.

Related Resources

  • Internal: See the upcoming internal briefing on backup platform hardening and GitLab exposure reduction.
  • Official vendor advisories: Quest NetVault Backup, GitLab, Rapid7 InsightConnect, Cacti, WordPress plugin vendor notices, OpenBSD security updates, and shell-quote release notes.

Keep reading