Security Digest: July 6, 2026 - 6 Critical Vulnerabilities

Today’s alert is urgent: six high-risk vulnerabilities affect management platforms, API infrastructure, developer tooling, and an examination system. The most dangerous issues include unauthenticated access to sensitive database credentials, SQL injection, command injection, and persistent denial-of-service paths that can take critical services offline.

· 8 min read

Executive Summary

Today’s alert is urgent: six high-risk vulnerabilities affect management platforms, API infrastructure, developer tooling, and an examination system. The most dangerous issues include unauthenticated access to sensitive database credentials, SQL injection, command injection, and persistent denial-of-service paths that can take critical services offline.

Act now: prioritize external-facing systems, rotate exposed credentials, apply vendor patches or mitigations immediately, and verify whether any affected services have already been accessed or degraded.

Critical Vulnerabilities

CVE-2026-14808: PROG Management System sensitive information exposure

  • Impact: Unauthenticated remote attackers can view a specific page and obtain the database account and password, enabling follow-on access to stored data and internal systems.
  • Affected Systems: PROG Management System developed by PROG MIS. Version details were not provided.
  • Immediate Action: Treat all exposed credentials as compromised. Restrict access to the affected page immediately and review logs for unauthenticated requests.
  • Mitigation: Apply the vendor fix as soon as available, rotate database credentials, and audit any accounts that used the exposed password.

CVE-2026-4249: WSO2 throttling event handling leads to persistent denial of service

  • Impact: An unauthenticated attacker can submit malicious JSON payloads that trigger a persistent DoS condition, disrupting API Gateway traffic and blocking legitimate API requests.
  • Affected Systems: Multiple WSO2 products using the throttling event handling mechanism.
  • Immediate Action: Apply emergency patches or disable exposed throttling-event endpoints if possible. Put API Gateway traffic under heightened monitoring now.
  • Mitigation: Upgrade to the patched WSO2 release, add input validation controls at the edge, and block malformed JSON at the WAF or gateway layer.

CVE-2026-9165: Red Hat ACS GraphQL query depth abuse causes management-plane DoS

  • Impact: An authenticated attacker with a valid API token can send deeply nested GraphQL queries that exhaust resources in Central and cause denial of service.
  • Affected Systems: Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central.
  • Immediate Action: Review all API tokens, limit access to trusted users only, and watch Central for abnormal GraphQL activity and rising resource consumption.
  • Mitigation: Apply the Red Hat update that adds query-depth limits. Revoke unused tokens and enforce least privilege for API access.

CVE-2026-14809: PROG Management System SQL injection exposes database contents

  • Impact: Unauthenticated remote attackers can inject SQL commands and read database contents, potentially exposing sensitive records and enabling deeper compromise.
  • Affected Systems: PROG Management System developed by PROG MIS. Version details were not provided.
  • Immediate Action: Assume the database may already be exposed. Restrict public access, inspect application logs for suspicious query patterns, and isolate the system if needed.
  • Mitigation: Patch immediately, replace any exposed credentials, and review database permissions to reduce blast radius.

CVE-2026-14778: SourceCodester Online Examination & Learning Management System improper authorization

  • Impact: Remote attackers can manipulate enrollment-related parameters in /ajax_enroll.php to bypass authorization controls. Public exploit code is already available.
  • Affected Systems: SourceCodester Online Examination & Learning Management System 1.0, specifically the Enrollment Management component.
  • Immediate Action: Disable or restrict the vulnerable endpoint immediately if you cannot patch today. Review enrollment changes for unauthorized activity.
  • Mitigation: Apply any available vendor update, enforce server-side authorization checks, and validate all enrollment actions against session identity.

CVE-2026-14802: react-create-app on macOS allows command injection

  • Impact: Remote exploitation can lead to OS command injection through startBrowserProcess, potentially executing attacker-controlled commands on developer machines.
  • Affected Systems: react create-app up to 5.0.1 on macOS, via react-dev-utils.
  • Immediate Action: Stop using affected versions on macOS for active development until patched. Warn developers not to launch untrusted projects or URLs from affected environments.
  • Mitigation: Upgrade beyond the vulnerable version, remove exposed development tooling from internet-facing environments, and review endpoints for unexpected shell activity.

Previously Alerted

What to Do Now

  1. Patch or isolate first: Fix internet-facing PROG, WSO2, RHACS, and SourceCodester systems before routine maintenance work.
  2. Rotate credentials: Assume any database or API secrets exposed by CVE-2026-14808 are compromised and replace them immediately.
  3. Block abuse paths: Add WAF rules for malformed JSON, suspicious GraphQL depth, and abnormal enrollment requests.
  4. Check for compromise: Review logs for unauthenticated access, unusual SQL patterns, repeated API token use, and unexplained service degradation.
  5. Contain developer risk: Update or remove vulnerable react-create-app installations on macOS developer systems.

Verification steps: confirm patched versions are deployed, validate that exposed endpoints are no longer reachable, and test that credentials were rotated successfully. For RHACS and WSO2, verify service health and request handling after remediation.

Monitoring recommendations: watch for new admin accounts, database reads outside normal hours, repeated 4xx/5xx spikes, GraphQL query anomalies, and persistent API Gateway failures. Escalate immediately if any sign of credential reuse or unauthorized data access appears.

Related Resources

  • Internal blog post: “How to Triage Multi-Vendor Critical CVEs in 24 Hours” — coming soon.
  • Internal blog post: “Credential Rotation After Sensitive Data Exposure” — coming soon.
  • Official vendor advisories: PROG MIS security notice, WSO2 advisory, Red Hat RHACS advisory, SourceCodester update notice, and react-dev-utils release notes.

Keep reading