Security Digest: June 29, 2026 - 15 Critical Vulnerabilities
Today’s alerts are dominated by publicly disclosed remote-exploitation flaws in small-business web apps, enterprise storage, and desktop software. Several issues can lead to SQL injection, unrestricted file upload, path traversal, privilege escalation, or sensitive data exposure—and many have working exploit details already circulating.
· 11 min read
Today's Critical Vulnerabilities Demand Immediate Action
Executive Summary
Today’s alerts are dominated by publicly disclosed remote-exploitation flaws in small-business web apps, enterprise storage, and desktop software. Several issues can lead to SQL injection, unrestricted file upload, path traversal, privilege escalation, or sensitive data exposure—and many have working exploit details already circulating.
Priority now: patch exposed systems first, disable or restrict vulnerable upload and admin endpoints, and verify that storage, CMS, and timetabling platforms are not internet-facing without controls.
Critical Vulnerabilities
CVE-2026-25707: libzypp repository metadata path traversal
Impact: Remote attackers supplying malicious repositories may overwrite files, causing denial of service or privilege escalation.
Affected Systems: libzypp before 17.38.10.
Immediate Action: Block untrusted repository sources now and inventory systems using libzypp.
Mitigation: Upgrade to 17.38.10 or later; restrict repository metadata ingestion to trusted sources only.
CVE-2025-2902: Hitachi Virtual Storage Platform improper authorization
Impact: Attackers may abuse maintenance utilities to bypass authorization on storage platforms.
Affected Systems: Hitachi VSP E390/E590/E790/E990/E1090/E390H/E590H/E790H/E1090H before DKCMAIN 93-07-26-xx/00 and GUM 93-07-26/00; VSP 5100/5500/5100H/5500H/5200/5600/5200H/5600H before DKCMAIN 90-09-27-00/00 and GUM 90-09-27/00; VSP G130/G150/G350/G370/G700/G900/F350/F370/F700/F900 before DKCMAIN 88-08-16-xx/00 and GUM 88-08-20/00.
Immediate Action: Check storage firmware versions and isolate management interfaces from general network access.
Mitigation: Apply the vendor-fixed DKCMAIN and GUM releases; limit maintenance tool access to approved admin hosts only.
CVE-2026-13527: SourceCodester Class and Exam Timetabling System SQL injection
Impact: Remote attackers can inject SQL through /preview4.php, potentially exposing or altering data.
Affected Systems: Class and Exam Timetabling System 1.0.
Immediate Action: Treat any exposed instance as high risk and remove public access until patched.
Mitigation: Apply vendor fixes if available; otherwise disable the endpoint and add WAF rules for course_year_section abuse.
CVE-2026-13528: ruoyi-vue-pro AppFileController path traversal
Impact: Remote attackers can traverse directories via generateUploadPath and write or access unintended files.
Affected Systems: YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT.
Immediate Action: Search for internet-facing deployments and suspend file-upload features if immediate patching is not possible.
Mitigation: Apply patch 4ae3f6b2c9883978837638c14e3d18419819eeb0 or later.
CVE-2026-13546: Feehi CMS unauthenticated articles API
Impact: Attackers can access /api/articles without authentication, risking data exposure and unauthorized changes.
Affected Systems: Feehi CMS up to 2.1.1.
Immediate Action: Restrict or disable the API endpoint immediately on exposed systems.
Mitigation: Upgrade to a fixed release when available; enforce authentication at the reverse proxy as a temporary control.
CVE-2026-13547: Hanwang e-Face unrestricted file upload
Impact: Remote attackers can upload arbitrary files through /manage/resourceUpload/upload.do, creating a likely route to code execution.
Affected Systems: Hanwang e-Face General Management Platform 6.3.5.4.
Immediate Action: Disable upload access or place the system behind strict admin-only network controls.
Mitigation: Apply the vendor patch; verify upload validation and file-type restrictions are enforced.
CVE-2026-13550: Baptism Information Management System SQL injection
Impact: Remote attackers can inject SQL via /delbaptism.php, risking data theft or database compromise.
Affected Systems: itsourcecode Baptism Information Management System 1.0.
Immediate Action: Remove from public exposure and inspect logs for suspicious ID parameters.
Mitigation: Patch or replace the application; use parameterized queries and WAF filtering as interim protection.
CVE-2026-13551: Baptism Information Management System SQL injection
Impact: Remote attackers can inject SQL via /editBaptism.php.
Affected Systems: itsourcecode Baptism Information Management System 1.0.
Immediate Action: Take the application offline if it handles sensitive records and cannot be patched today.
Mitigation: Apply the vendor fix or compensate with strict input validation and database least privilege.
CVE-2026-13552: Online Hotel Management System SQL injection
Impact: Attackers can inject SQL via /admin/mod_amenities/controller.php?action=edit.
Affected Systems: itsourcecode Online Hotel Management System 1.0.
Immediate Action: Restrict admin access to VPN or a trusted admin subnet now.
Mitigation: Patch immediately; monitor for database anomalies tied to amen_id requests.
CVE-2026-13553: Online Hotel Management System unrestricted upload
Impact: Remote attackers can upload malicious files via /admin/mod_amenities/controller.php?action=add.
Affected Systems: itsourcecode Online Hotel Management System 1.0.
Immediate Action: Disable the add flow or block file uploads at the edge.
Mitigation: Enforce file-type allowlists and randomize storage paths after patching.
CVE-2026-13555: Online Hotel Management System SQL injection
Impact: Remote attackers can inject SQL through the user-add endpoint and compromise records.
Affected Systems: itsourcecode Online Hotel Management System 1.0.
Immediate Action: Review exposure of /admin/mod_users/controller.php?action=add and block external access.
Mitigation: Patch immediately and verify prepared statements are used everywhere user input reaches SQL.
CVE-2026-13521: SourceCodester Class and Exam Timetabling System SQL injection
Impact: Remote attackers can inject SQL via /preview5.php and manipulate scheduling data.
Affected Systems: Class and Exam Timetabling System 1.0 / 5.php.
Immediate Action: Treat as an active exploitation candidate because public exploit details exist.
Mitigation: Patch, block the endpoint, and add detection for abnormal course_year_section values.
CVE-2026-13526: SourceCodester Class and Exam Timetabling System SQL injection
Impact: Remote attackers can inject SQL via /edit_class.php.
Affected Systems: Class and Exam Timetabling System 1.0.
Immediate Action: Isolate the app from the internet until remediation is complete.
Mitigation: Patch and validate that the ID parameter is no longer directly concatenated into queries.
CVE-2026-13601: Yelp CSP bypass and host file disclosure
Impact: A malicious Flatpak app can abuse crafted help content to bypass sandbox expectations and disclose host-readable files.
Affected Systems: Yelp with vulnerable yelp-xsl CSP behavior.
Immediate Action: Audit Flatpak deployments and restrict untrusted help content handling.
Mitigation: Update Yelp/yelp-xsl packages as soon as vendor fixes land; reduce exposure to untrusted OpenURI content.
CVE-2026-57346: Embed Privacy path traversal
Impact: Attackers can traverse paths and access files outside the intended directory.
Affected Systems: Embed Privacy through 1.12.3.
Immediate Action: Patch this WordPress-related component immediately if installed on public sites.
Mitigation: Upgrade beyond 1.12.3; block suspicious path sequences at the web server while you roll out the fix.
What to Do Now
- Patch or isolate every exposed system listed above, starting with public-facing CMS, storage, and admin portals.
- Disable risky features now: file uploads, unauthenticated APIs, and maintenance interfaces.
- Restrict access to admin networks, VPN, or allowlisted hosts only.
- Verify versions against vendor advisories and confirm fixes are actually deployed.
- Search logs for SQL injection patterns, path traversal strings, and unexpected upload activity.
Verification steps: confirm package versions, check service banners, review reverse-proxy rules, and test that vulnerable endpoints return 403/404 from untrusted networks.
Monitoring recommendations: alert on unusual ../ sequences, repeated parameter tampering, new files in upload directories, and unexplained storage-management logins.
Related Resources
- Internal blog posts: link your incident response update and patch validation checklist here when published.
- Official vendor advisories: Hitachi VSP security notice, libzypp release notes, Yelp/yelp-xsl update notes, and product advisories for Feehi CMS, ruoyi-vue-pro, Hanwang e-Face, and itsourcecode applications.