Back to all news
Security

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The Hacker News·August 26, 2026·1 min read
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

CERT/CC disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library, tracked as CVE-2026-19913 and CVE-2026-19912, that allow a remote, unauthenticated attacker to read arbitrary files and execute code. Both flaws stem from unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store