HackerFeeds

CyberSecurity News

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The Hacker News
· August 26, 2026

AI summary

The CERT Coordination Center has disclosed two vulnerabilities in Kaltura's HTML5 video player library. These flaws allow a remote attacker to read arbitrary files from a server and execute code on it without needing authentication. The vulnerabilities are the result of unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player. They have been assigned the identifiers CVE-2026-19913 and CVE-2026-19912. The issues are currently unpatched.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.