Security Digest: October 5, 2026 - 31 Critical Vulnerabilities
Today’s security picture is severe: multiple publicly disclosed vulnerabilities allow remote code execution, SQL injection, path traversal, SSRF, XSS, and even kernel-level memory corruption. The most urgent risks are the Totolink router buffer overflow, Papermerge RCE, and the cluster of publicly exploitable SQL injection flaws in web apps and admission systems.
· 18 min read
Executive Summary
Today’s security picture is severe: multiple publicly disclosed vulnerabilities allow remote code execution, SQL injection, path traversal, SSRF, XSS, and even kernel-level memory corruption. The most urgent risks are the Totolink router buffer overflow, Papermerge RCE, and the cluster of publicly exploitable SQL injection flaws in web apps and admission systems.
Act now: patch exposed systems, take vulnerable services offline where patching is not immediately available, and assume any internet-facing instance with these products is at risk of active exploitation.
Critical Vulnerabilities
- CVE-2026-105285: Totolink A3002MU stack-based buffer overflow
- Impact: Remote attackers can trigger a stack overflow and potentially execute code. Exploit code is already public.
- Affected Systems: Totolink A3002MU 1.0.0-B20230403.1455
- Immediate Action: Remove the device from internet exposure now; block management access from untrusted networks.
- Mitigation: Apply vendor firmware updates as soon as available; if none exist, replace the device.
- CVE-2026-104389: Sirv blind SQL injection
- Impact: Attackers can extract data from the backend and potentially pivot into connected services.
- Affected Systems: Sirv through 8.2.5
- Immediate Action: Disable exposed admin/API endpoints until patched.
- Mitigation: Upgrade to a fixed release and audit database access logs.
- CVE-2026-19184: Zephyr NXP GAU ADC memory corruption
- Impact: User-mode code can corrupt kernel memory, crash devices, or escalate privileges on affected builds.
- Affected Systems: Zephyr builds with CONFIG_USERSPACE=y on NXP RW61x with GAU ADC enabled
- Immediate Action: Restrict user-mode access to ADC devices and deploy the vendor patch immediately.
- Mitigation: Update to the fixed Zephyr driver using adc_sequence_validate_buffer().
- CVE-2026-105293: Legcord path traversal in theme handlers
- Impact: Script running in Discord can write files outside the themes directory, delete directories, or launch local executables.
- Affected Systems: Legcord 1.1.0 through 1.3.0
- Immediate Action: Treat any Discord-origin XSS as a full local compromise risk.
- Mitigation: Upgrade immediately and disable untrusted theme imports.
- CVE-2026-105220: Twine 2 desktop XSS leading to code execution
- Impact: Crafted story files can execute code as the user through the editor window.
- Affected Systems: Twine 2 desktop through 2.12.0
- Immediate Action: Block untrusted story imports until patched.
- Mitigation: Update to a fixed version and review IPC bridge exposure.
- CVE-2026-104408: Groundhogg blind SQL injection
- Impact: Attackers can read or alter backend data through injected queries.
- Affected Systems: Groundhogg through 4.8.3
- Immediate Action: Patch WordPress plugins on all public sites now.
- Mitigation: Upgrade Groundhogg and review database anomalies.
- CVE-2026-105314: Papermerge upload traversal to RCE
- Impact: A standard user can write a malicious
.pthfile and gain code execution on next interpreter start. - Affected Systems: Papermerge 3.5.3
- Immediate Action: Disable uploads or isolate the service immediately.
- Mitigation: Apply the vendor fix and inspect
site-packagesfor unexpected files.
- Impact: A standard user can write a malicious
- CVE-2026-105295: GitAhead insecure update mechanism
- Impact: Network attackers can deliver a fake update and execute code as the user.
- Affected Systems: GitAhead 2.5.0 through 2.7.1
- Immediate Action: Turn off auto-update and verify all installed binaries.
- Mitigation: Upgrade after vendor fixes signature verification and TLS handling.
- CVE-2026-105294: Legcord config injection via Discord XSS
- Impact: Attackers can persist proxy and certificate-bypass flags, enabling interception of client traffic.
- Affected Systems: Legcord 1.1.0 through 1.3.0
- Immediate Action: Reset affected configs and monitor for unexpected launch arguments.
- Mitigation: Patch Legcord and remove unsafe bridge permissions.
- CVE-2026-105223: maclof kubernetes-client TLS verification bypass
- Impact: On-path attackers can impersonate the Kubernetes API server and steal tokens.
- Affected Systems: maclof kubernetes-client 0.17.0 before 0.32.0
- Immediate Action: Stop using affected parsing functions for untrusted kubeconfigs.
- Mitigation: Upgrade immediately and audit credentials exposed to API traffic.
- CVE-2026-105222: google-maps Laravel package disables TLS verification
- Impact: Attackers can intercept requests and steal API keys.
- Affected Systems: alexpechkarev/google-maps through 12.16
- Immediate Action: Rotate exposed API keys now.
- Mitigation: Update the package and enforce certificate verification.
- CVE-2026-105221: gist RubyGem improper certificate validation
- Impact: HTTPS traffic can be intercepted, exposing OAuth tokens and credentials.
- Affected Systems: gist before 6.1.0
- Immediate Action: Stop using the affected gem in production workflows.
- Mitigation: Upgrade and rotate any credentials used with GitHub API access.
- CVE-2026-105232: food-waste-management-system SQL injection in registration
- Impact: Remote attackers can extract or manipulate database content via signup fields.
- Affected Systems: kishor-23 food-waste-management-system rolling releases through affected commits
- Immediate Action: Put the app behind maintenance mode if it is public.
- Mitigation: Patch the vulnerable endpoint and add query parameterization.
- CVE-2026-105238: NextChat SSRF via proxy handler
- Impact: Attackers can force the server to make requests to internal or arbitrary destinations.
- Affected Systems: ChatGPTNextWeb NextChat up to 2.16.1
- Immediate Action: Restrict outbound server traffic and disable the proxy path if possible.
- Mitigation: Apply the upstream fix and validate all user-supplied URLs.
- CVE-2026-105246: Online Reviewer Management System SQL injection
- Impact: Remote SQL injection can expose or alter reviewer and assessment data.
- Affected Systems: SourceCodester Online Reviewer Management System 1.0
- Immediate Action: Block public access until patched.
- Mitigation: Update affected PHP handlers and review database credentials.
- CVE-2026-105247: Online Reviewer Management System SQL injection
- Impact: Remote attackers can tamper with course-related records.
- Affected Systems: SourceCodester Online Reviewer Management System 1.0
- Immediate Action: Treat this as active-exploitation risk if exposed online.
- Mitigation: Patch the
courseaction endpoint and validate inputs server-side.
- CVE-2026-105253: Online Admission System login SQL injection
- Impact: Attackers can bypass or abuse login processing and extract data.
- Affected Systems: itsourcecode Online Admission System Project 1.0
- Immediate Action: Restrict access to login endpoints immediately.
- Mitigation: Upgrade or patch the login handler and rotate database secrets.
- CVE-2026-105185: Online Admission System examinee SQL injection
- Impact: Remote SQL injection against the examinee management function.
- Affected Systems: itsourcecode Online Admission System 1.0
- Immediate Action: Monitor for suspicious requests to
/admin/examinee.php. - Mitigation: Apply vendor fixes and add WAF rules for injection patterns.
- CVE-2026-105167: food-waste-management-system donate SQL injection
- Impact: Attackers can query or alter donation records remotely.
- Affected Systems: kishor-23 food-waste-management-system rolling releases
- Immediate Action: Limit exposure of donation endpoints.
- Mitigation: Patch the
admin/donate.phphandler and log all SQL errors.
- CVE-2026-105169: food-waste-management-system delivery SQL injection
- Impact: Remote attackers can tamper with order and delivery assignments.
- Affected Systems: kishor-23 food-waste-management-system rolling releases
- Immediate Action: Disable direct internet access to delivery endpoints.
- Mitigation: Fix query handling in
delivery/delivery.php.
- CVE-2026-105170: food-waste-management-system missing authentication
- Impact: Attackers may create admin accounts without proper authentication.
- Affected Systems: kishor-23 food-waste-management-system rolling releases
- Immediate Action: Audit for unauthorized admin signups now.
- Mitigation: Patch
admin/signup.phpand invalidate suspicious accounts.
- CVE-2026-105172: Online Admission System login SQL injection
- Impact: Remote attackers can manipulate login processing.
- Affected Systems: itsourcecode Online Admission System 1.0
- Immediate Action: Apply emergency filtering at the edge if patching is delayed.
- Mitigation: Fix
/login1.phpand rotate credentials.
- CVE-2026-105175: Drug Recommendation System student registration SQL injection
- Impact: Attackers can inject SQL through registration parameters.
- Affected Systems: SourceCodester Drug Recommendation System 1.0
- Immediate Action: Take the registration form offline if internet-facing.
- Mitigation: Patch
/Auth/add_student.phpand validate inputs.
- CVE-2026-105182: Online Reviewer Management System activity update SQL injection
- Impact: Remote attackers can alter assessment activity records.
- Affected Systems: SourceCodester Online Reviewer Management System 1.0
- Immediate Action: Block suspicious activity update requests.
- Mitigation: Fix
btn_functions.php?action=updateand sanitizeTitle.
- CVE-2026-105183: Online Admission System schedule SQL injection
- Impact: Attackers can manipulate scheduling records remotely.
- Affected Systems: itsourcecode Online Admission System 1.0
- Immediate Action: Review exposed admin endpoints for exploitation attempts.
- Mitigation: Patch
/admin/confirm.phpand rotate DB credentials.
- CVE-2026-105184: Online Admission System criteria SQL injection
- Impact: Remote SQL injection can expose or corrupt admissions criteria.
- Affected Systems: itsourcecode Online Admission System 1.0
- Immediate Action: Restrict access to administrative pages immediately.
- Mitigation: Fix
/admin/creteria.phpand deploy WAF protections.
- CVE-2026-105166: food-waste-management-system food donation SQL injection
- Impact: Remote attackers can manipulate donation form data and database content.
- Affected Systems: kishor-23 food-waste-management-system rolling releases
- Immediate Action: Monitor and block malformed donation submissions.
- Mitigation: Patch
fooddonateform.phpand inspect for abuse.
- CVE-2026-105229: food-waste-management-system user registration SQL injection
- Impact: Attackers can inject SQL through registration fields.
- Affected Systems: kishor-23 food-waste-management-system rolling releases
- Immediate Action: Temporarily disable public registration if possible.
- Mitigation: Patch
signup.phpand add server-side query binding.
- CVE-2026-105230: food-waste-management-system delivery SQL injection
- Impact: Remote attackers can alter delivery assignment data.
- Affected Systems: kishor-23 food-waste-management-system rolling releases
- Immediate Action: Watch for unusual delivery ID patterns in requests.
- Mitigation: Patch
delivery/deliverymyord.phpand review logs.
- CVE-2026-105231: food-waste-management-system admin signup SQL injection
- Impact: Remote attackers can inject SQL during admin registration.
- Affected Systems: kishor-23 food-waste-management-system rolling releases
- Immediate Action: Audit admin accounts created recently.
- Mitigation: Fix
admin/signup.phpand invalidate suspicious sessions.
- CVE-2026-104407: PowerPress CSRF
- Impact: An attacker can trick an authenticated admin into changing plugin settings.
- Affected Systems: Blubrry Podcasting PowerPress Podcasting through 11.17.9
- Immediate Action: Require re-authentication for admin actions where possible.
- Mitigation: Upgrade PowerPress and verify nonce protections.
Previously Alerted
- CVE-2026-105284: CVE-2026-105284 Security Alert: CRITICAL Vulnerability
What to Do Now
- Patch or isolate internet-facing systems running any affected product, starting with Totolink, Papermerge, Legcord, Twine, and all public PHP apps.
- Disable risky features such as auto-update, file import, upload endpoints, and admin registration until fixes are confirmed.
- Rotate secrets if you use any vulnerable TLS-bypassing libraries or exposed API integrations.
- Review logs for SQL injection patterns, unusual file writes, unexpected outbound requests, and new admin accounts.
- Block exploit paths with WAF rules, network ACLs, and temporary maintenance pages where patching is delayed.
Verification steps: confirm installed versions, compare against the affected ranges above, and check whether any exposed instance is reachable from the internet. Validate that fixes actually remove the vulnerable code path, not just the UI entry point.
Monitoring recommendations: alert on spikes in 4xx/5xx responses, database errors, new files in web roots or package directories, outbound connections to unfamiliar hosts, and repeated requests to the listed vulnerable endpoints.
Related Resources
- Internal blog post on emergency vulnerability triage and public exploit response — to be published.
- Internal blog post on hardening web apps against SQL injection and SSRF — to be published.
- Official vendor advisories and release notes for Totolink, Zephyr, Papermerge, Legcord, Twine, GitAhead, PowerPress, and the affected PHP applications.