Security Digest: October 5, 2026 - 31 Critical Vulnerabilities

Today’s security picture is severe: multiple publicly disclosed vulnerabilities allow remote code execution, SQL injection, path traversal, SSRF, XSS, and even kernel-level memory corruption. The most urgent risks are the Totolink router buffer overflow, Papermerge RCE, and the cluster of publicly exploitable SQL injection flaws in web apps and admission systems.

· 18 min read

Executive Summary

Today’s security picture is severe: multiple publicly disclosed vulnerabilities allow remote code execution, SQL injection, path traversal, SSRF, XSS, and even kernel-level memory corruption. The most urgent risks are the Totolink router buffer overflow, Papermerge RCE, and the cluster of publicly exploitable SQL injection flaws in web apps and admission systems.

Act now: patch exposed systems, take vulnerable services offline where patching is not immediately available, and assume any internet-facing instance with these products is at risk of active exploitation.

Critical Vulnerabilities

  • CVE-2026-105285: Totolink A3002MU stack-based buffer overflow
    • Impact: Remote attackers can trigger a stack overflow and potentially execute code. Exploit code is already public.
    • Affected Systems: Totolink A3002MU 1.0.0-B20230403.1455
    • Immediate Action: Remove the device from internet exposure now; block management access from untrusted networks.
    • Mitigation: Apply vendor firmware updates as soon as available; if none exist, replace the device.
  • CVE-2026-104389: Sirv blind SQL injection
    • Impact: Attackers can extract data from the backend and potentially pivot into connected services.
    • Affected Systems: Sirv through 8.2.5
    • Immediate Action: Disable exposed admin/API endpoints until patched.
    • Mitigation: Upgrade to a fixed release and audit database access logs.
  • CVE-2026-19184: Zephyr NXP GAU ADC memory corruption
    • Impact: User-mode code can corrupt kernel memory, crash devices, or escalate privileges on affected builds.
    • Affected Systems: Zephyr builds with CONFIG_USERSPACE=y on NXP RW61x with GAU ADC enabled
    • Immediate Action: Restrict user-mode access to ADC devices and deploy the vendor patch immediately.
    • Mitigation: Update to the fixed Zephyr driver using adc_sequence_validate_buffer().
  • CVE-2026-105293: Legcord path traversal in theme handlers
    • Impact: Script running in Discord can write files outside the themes directory, delete directories, or launch local executables.
    • Affected Systems: Legcord 1.1.0 through 1.3.0
    • Immediate Action: Treat any Discord-origin XSS as a full local compromise risk.
    • Mitigation: Upgrade immediately and disable untrusted theme imports.
  • CVE-2026-105220: Twine 2 desktop XSS leading to code execution
    • Impact: Crafted story files can execute code as the user through the editor window.
    • Affected Systems: Twine 2 desktop through 2.12.0
    • Immediate Action: Block untrusted story imports until patched.
    • Mitigation: Update to a fixed version and review IPC bridge exposure.
  • CVE-2026-104408: Groundhogg blind SQL injection
    • Impact: Attackers can read or alter backend data through injected queries.
    • Affected Systems: Groundhogg through 4.8.3
    • Immediate Action: Patch WordPress plugins on all public sites now.
    • Mitigation: Upgrade Groundhogg and review database anomalies.
  • CVE-2026-105314: Papermerge upload traversal to RCE
    • Impact: A standard user can write a malicious .pth file and gain code execution on next interpreter start.
    • Affected Systems: Papermerge 3.5.3
    • Immediate Action: Disable uploads or isolate the service immediately.
    • Mitigation: Apply the vendor fix and inspect site-packages for unexpected files.
  • CVE-2026-105295: GitAhead insecure update mechanism
    • Impact: Network attackers can deliver a fake update and execute code as the user.
    • Affected Systems: GitAhead 2.5.0 through 2.7.1
    • Immediate Action: Turn off auto-update and verify all installed binaries.
    • Mitigation: Upgrade after vendor fixes signature verification and TLS handling.
  • CVE-2026-105294: Legcord config injection via Discord XSS
    • Impact: Attackers can persist proxy and certificate-bypass flags, enabling interception of client traffic.
    • Affected Systems: Legcord 1.1.0 through 1.3.0
    • Immediate Action: Reset affected configs and monitor for unexpected launch arguments.
    • Mitigation: Patch Legcord and remove unsafe bridge permissions.
  • CVE-2026-105223: maclof kubernetes-client TLS verification bypass
    • Impact: On-path attackers can impersonate the Kubernetes API server and steal tokens.
    • Affected Systems: maclof kubernetes-client 0.17.0 before 0.32.0
    • Immediate Action: Stop using affected parsing functions for untrusted kubeconfigs.
    • Mitigation: Upgrade immediately and audit credentials exposed to API traffic.
  • CVE-2026-105222: google-maps Laravel package disables TLS verification
    • Impact: Attackers can intercept requests and steal API keys.
    • Affected Systems: alexpechkarev/google-maps through 12.16
    • Immediate Action: Rotate exposed API keys now.
    • Mitigation: Update the package and enforce certificate verification.
  • CVE-2026-105221: gist RubyGem improper certificate validation
    • Impact: HTTPS traffic can be intercepted, exposing OAuth tokens and credentials.
    • Affected Systems: gist before 6.1.0
    • Immediate Action: Stop using the affected gem in production workflows.
    • Mitigation: Upgrade and rotate any credentials used with GitHub API access.
  • CVE-2026-105232: food-waste-management-system SQL injection in registration
    • Impact: Remote attackers can extract or manipulate database content via signup fields.
    • Affected Systems: kishor-23 food-waste-management-system rolling releases through affected commits
    • Immediate Action: Put the app behind maintenance mode if it is public.
    • Mitigation: Patch the vulnerable endpoint and add query parameterization.
  • CVE-2026-105238: NextChat SSRF via proxy handler
    • Impact: Attackers can force the server to make requests to internal or arbitrary destinations.
    • Affected Systems: ChatGPTNextWeb NextChat up to 2.16.1
    • Immediate Action: Restrict outbound server traffic and disable the proxy path if possible.
    • Mitigation: Apply the upstream fix and validate all user-supplied URLs.
  • CVE-2026-105246: Online Reviewer Management System SQL injection
    • Impact: Remote SQL injection can expose or alter reviewer and assessment data.
    • Affected Systems: SourceCodester Online Reviewer Management System 1.0
    • Immediate Action: Block public access until patched.
    • Mitigation: Update affected PHP handlers and review database credentials.
  • CVE-2026-105247: Online Reviewer Management System SQL injection
    • Impact: Remote attackers can tamper with course-related records.
    • Affected Systems: SourceCodester Online Reviewer Management System 1.0
    • Immediate Action: Treat this as active-exploitation risk if exposed online.
    • Mitigation: Patch the course action endpoint and validate inputs server-side.
  • CVE-2026-105253: Online Admission System login SQL injection
    • Impact: Attackers can bypass or abuse login processing and extract data.
    • Affected Systems: itsourcecode Online Admission System Project 1.0
    • Immediate Action: Restrict access to login endpoints immediately.
    • Mitigation: Upgrade or patch the login handler and rotate database secrets.
  • CVE-2026-105185: Online Admission System examinee SQL injection
    • Impact: Remote SQL injection against the examinee management function.
    • Affected Systems: itsourcecode Online Admission System 1.0
    • Immediate Action: Monitor for suspicious requests to /admin/examinee.php.
    • Mitigation: Apply vendor fixes and add WAF rules for injection patterns.
  • CVE-2026-105167: food-waste-management-system donate SQL injection
    • Impact: Attackers can query or alter donation records remotely.
    • Affected Systems: kishor-23 food-waste-management-system rolling releases
    • Immediate Action: Limit exposure of donation endpoints.
    • Mitigation: Patch the admin/donate.php handler and log all SQL errors.
  • CVE-2026-105169: food-waste-management-system delivery SQL injection
    • Impact: Remote attackers can tamper with order and delivery assignments.
    • Affected Systems: kishor-23 food-waste-management-system rolling releases
    • Immediate Action: Disable direct internet access to delivery endpoints.
    • Mitigation: Fix query handling in delivery/delivery.php.
  • CVE-2026-105170: food-waste-management-system missing authentication
    • Impact: Attackers may create admin accounts without proper authentication.
    • Affected Systems: kishor-23 food-waste-management-system rolling releases
    • Immediate Action: Audit for unauthorized admin signups now.
    • Mitigation: Patch admin/signup.php and invalidate suspicious accounts.
  • CVE-2026-105172: Online Admission System login SQL injection
    • Impact: Remote attackers can manipulate login processing.
    • Affected Systems: itsourcecode Online Admission System 1.0
    • Immediate Action: Apply emergency filtering at the edge if patching is delayed.
    • Mitigation: Fix /login1.php and rotate credentials.
  • CVE-2026-105175: Drug Recommendation System student registration SQL injection
    • Impact: Attackers can inject SQL through registration parameters.
    • Affected Systems: SourceCodester Drug Recommendation System 1.0
    • Immediate Action: Take the registration form offline if internet-facing.
    • Mitigation: Patch /Auth/add_student.php and validate inputs.
  • CVE-2026-105182: Online Reviewer Management System activity update SQL injection
    • Impact: Remote attackers can alter assessment activity records.
    • Affected Systems: SourceCodester Online Reviewer Management System 1.0
    • Immediate Action: Block suspicious activity update requests.
    • Mitigation: Fix btn_functions.php?action=update and sanitize Title.
  • CVE-2026-105183: Online Admission System schedule SQL injection
    • Impact: Attackers can manipulate scheduling records remotely.
    • Affected Systems: itsourcecode Online Admission System 1.0
    • Immediate Action: Review exposed admin endpoints for exploitation attempts.
    • Mitigation: Patch /admin/confirm.php and rotate DB credentials.
  • CVE-2026-105184: Online Admission System criteria SQL injection
    • Impact: Remote SQL injection can expose or corrupt admissions criteria.
    • Affected Systems: itsourcecode Online Admission System 1.0
    • Immediate Action: Restrict access to administrative pages immediately.
    • Mitigation: Fix /admin/creteria.php and deploy WAF protections.
  • CVE-2026-105166: food-waste-management-system food donation SQL injection
    • Impact: Remote attackers can manipulate donation form data and database content.
    • Affected Systems: kishor-23 food-waste-management-system rolling releases
    • Immediate Action: Monitor and block malformed donation submissions.
    • Mitigation: Patch fooddonateform.php and inspect for abuse.
  • CVE-2026-105229: food-waste-management-system user registration SQL injection
    • Impact: Attackers can inject SQL through registration fields.
    • Affected Systems: kishor-23 food-waste-management-system rolling releases
    • Immediate Action: Temporarily disable public registration if possible.
    • Mitigation: Patch signup.php and add server-side query binding.
  • CVE-2026-105230: food-waste-management-system delivery SQL injection
    • Impact: Remote attackers can alter delivery assignment data.
    • Affected Systems: kishor-23 food-waste-management-system rolling releases
    • Immediate Action: Watch for unusual delivery ID patterns in requests.
    • Mitigation: Patch delivery/deliverymyord.php and review logs.
  • CVE-2026-105231: food-waste-management-system admin signup SQL injection
    • Impact: Remote attackers can inject SQL during admin registration.
    • Affected Systems: kishor-23 food-waste-management-system rolling releases
    • Immediate Action: Audit admin accounts created recently.
    • Mitigation: Fix admin/signup.php and invalidate suspicious sessions.
  • CVE-2026-104407: PowerPress CSRF
    • Impact: An attacker can trick an authenticated admin into changing plugin settings.
    • Affected Systems: Blubrry Podcasting PowerPress Podcasting through 11.17.9
    • Immediate Action: Require re-authentication for admin actions where possible.
    • Mitigation: Upgrade PowerPress and verify nonce protections.

Previously Alerted

What to Do Now

  1. Patch or isolate internet-facing systems running any affected product, starting with Totolink, Papermerge, Legcord, Twine, and all public PHP apps.
  2. Disable risky features such as auto-update, file import, upload endpoints, and admin registration until fixes are confirmed.
  3. Rotate secrets if you use any vulnerable TLS-bypassing libraries or exposed API integrations.
  4. Review logs for SQL injection patterns, unusual file writes, unexpected outbound requests, and new admin accounts.
  5. Block exploit paths with WAF rules, network ACLs, and temporary maintenance pages where patching is delayed.

Verification steps: confirm installed versions, compare against the affected ranges above, and check whether any exposed instance is reachable from the internet. Validate that fixes actually remove the vulnerable code path, not just the UI entry point.

Monitoring recommendations: alert on spikes in 4xx/5xx responses, database errors, new files in web roots or package directories, outbound connections to unfamiliar hosts, and repeated requests to the listed vulnerable endpoints.

Related Resources

  • Internal blog post on emergency vulnerability triage and public exploit response — to be published.
  • Internal blog post on hardening web apps against SQL injection and SSRF — to be published.
  • Official vendor advisories and release notes for Totolink, Zephyr, Papermerge, Legcord, Twine, GitAhead, PowerPress, and the affected PHP applications.

Keep reading