Security Digest: June 28, 2026 - 6 Critical Vulnerabilities

Six high-severity vulnerabilities demand immediate attention today, including multiple publicly exploitable SQL injection flaws in SourceCodester Class and Exam Timetabling System and privilege escalation issues in RustDesk and MyBB. If any of these products are exposed to the internet or used in admin workflows, treat them as active-risk items and move to patching, access review, and exposure reduction now.

· 8 min read

Executive Summary

Six high-severity vulnerabilities demand immediate attention today, including multiple publicly exploitable SQL injection flaws in SourceCodester Class and Exam Timetabling System and privilege escalation issues in RustDesk and MyBB. If any of these products are exposed to the internet or used in admin workflows, treat them as active-risk items and move to patching, access review, and exposure reduction now.

The biggest concern is the combination of remote exploitability and public proof-of-concept availability for the SourceCodester issues. Teams should assume attackers can quickly weaponize these bugs and check for signs of compromise immediately.

Critical Vulnerabilities

CVE-2026-58056: RustDesk session boundary bypass allows unauthorized input and capture access

  • Impact: An attacker with only valid FileTransfer authorization may inject keyboard and mouse input and access screenshot/display-capture functions outside their intended session scope.
  • Affected Systems: RustDesk deployments using per-capability session flags; versions not yet confirmed in the advisory.
  • Immediate Action: Restrict RustDesk use to trusted networks, review all active sessions, and disable or limit file-transfer access until a fix is available.
  • Mitigation: Apply the vendor patch as soon as released; until then, enforce least-privilege session roles and monitor for unexpected input or capture activity.

CVE-2026-13485: SourceCodester Class and Exam Timetabling System SQL injection in /preview.php

  • Impact: Remote attackers can manipulate course_year_section to run SQL injection attacks, potentially exposing or altering database content.
  • Affected Systems: SourceCodester Class and Exam Timetabling System 1.0, /preview.php.
  • Immediate Action: Remove public exposure if possible, block untrusted access, and treat any internet-facing instance as at risk of compromise.
  • Mitigation: Apply the vendor fix or upgrade immediately; if no patch is available, disable the affected page and add server-side input validation and parameterized queries.

CVE-2026-13488: SourceCodester Class and Exam Timetabling System SQL injection in /preview7.php

  • Impact: Remote attackers can exploit course_year_section to inject SQL and access backend data.
  • Affected Systems: SourceCodester Class and Exam Timetabling System 1.0/7.php, /preview7.php.
  • Immediate Action: Assume public exploit use is possible; isolate the application and inspect logs for suspicious parameter values.
  • Mitigation: Patch or remove the vulnerable component now; if patching is delayed, restrict access through authentication and network controls.

CVE-2026-13486: SourceCodester Class and Exam Timetabling System SQL injection in /preview6.php

  • Impact: Remote SQL injection may allow attackers to read, modify, or destroy database records.
  • Affected Systems: SourceCodester Class and Exam Timetabling System 1.0/6.php, /preview6.php.
  • Immediate Action: Prioritize this application for emergency review if it is internet-facing or used in production.
  • Mitigation: Deploy the vendor update, or temporarily remove the affected endpoint and enforce WAF rules to block injection patterns.

CVE-2026-13487: SourceCodester Class and Exam Timetabling System SQL injection in /archive.php

  • Impact: Remote attackers can manipulate the sy parameter to execute SQL injection attacks.
  • Affected Systems: SourceCodester Class and Exam Timetabling System 1.0, /archive.php.
  • Immediate Action: Check whether this endpoint is accessible externally and disable it if business operations allow.
  • Mitigation: Patch immediately; until then, use strict allow-list validation, prepared statements, and WAF blocking.

CVE-2026-58054: MyBB admin role assignment flaw enables privilege escalation

  • Impact: A limited Admin Control Panel user can assign the Administrators group and escalate to full admin privileges.
  • Affected Systems: MyBB 1.8.40 deployments using delegated user-management permissions.
  • Immediate Action: Review all ACP users with user-management rights and remove unnecessary delegation immediately.
  • Mitigation: Apply the vendor fix when available; meanwhile, tightly limit ACP permissions, audit group assignments, and verify no unauthorized accounts were promoted.

Previously Alerted

What to Do Now

  1. Patch or isolate immediately any exposed SourceCodester, RustDesk, or MyBB systems.
  2. Disable or restrict vulnerable endpoints until fixes are deployed, especially /preview.php, /preview6.php, /preview7.php, and /archive.php.
  3. Review admin and service accounts for unexpected privilege changes, especially in MyBB.
  4. Check logs for SQL injection indicators, unusual parameter values, and unexpected database errors.
  5. Assume public exploit attempts will target the SourceCodester issues first.

Verification steps:

  • Confirm product versions and internet exposure.
  • Search web and app logs for repeated requests containing course_year_section, sy, quotes, SQL operators, or encoded payloads.
  • Audit database and admin accounts for unauthorized changes.
  • Review RustDesk session history for unexpected input or capture activity.

Monitoring recommendations:

  • Alert on new admin creation, privilege changes, and group assignment changes.
  • Watch for spikes in 4xx/5xx responses on affected endpoints.
  • Monitor WAF and IDS logs for SQL injection signatures and unusual remote-control session behavior.

Related Resources

  • Internal blog posts: pending publication for today’s SourceCodester, RustDesk, and MyBB coverage.
  • Official vendor advisories: check RustDesk, MyBB, and SourceCodester release channels for patches and remediation notes as they become available.

Keep reading