[Verse 1] GL-iNet router, model MT3000 Running firmware up to four point four point five Two functions sitting in the native plugin code Quietly waiting to compromise your drive The first one handles OpenVPN configuration Fetching recommended settings through a broken gate The second echoes packets server-to-server Both carrying CVSS scores of nine point eight [Chorus] CVE-2026-18602 and 18614 Two holes in the GL-iNet, exploitation's at the door Manipulation of arguments, no safe ground to stand Remote code execution waiting close at hand Patch your router, patch it now, don't deliberate Nine point eight out of ten — that's a critical weight [Verse 2] Now picture OpenEMR, the medical record suite Version eight point two point oh, where patient data sleeps An authenticated admin finds a document tree A library class called Tree dot class dot php They craft a payload through the category structure Arbitrary code runs inside the server walls Nine point one on the scale — still catastrophic pressure When healthcare software answers the wrong calls [Chorus] CVE-2026-39932, doctors take note Remote code execution, attacker stays afloat Admin credentials give them everything they need Library-class manipulation plants the seed Patch your OpenEMR before the wound goes septic The damage to your patients would be apoplectic [Bridge] Here's a word worth holding — *perfidious* Meaning treacherous, faithfully concealing harm That's what these vulnerabilities embody A smiling interface with an alarm Krayin CRM, version two point two point four The installer middleware forgot to check the badge An unauthenticated stranger at the door Can overwrite your primary admin in a flash [Verse 3] CVE-2026-41452, another nine point eight No login? No problem — the middleware waves you through A crafted request rewrites the administrator Handing crown and keys to someone no one knew Four CVEs today, three products standing naked GL-iNet twice, then OpenEMR, then Krayin's flaw The collective weight of these scores is staggering Vendors, issue patches — this is not a minor thaw [Verse 4] Consider every network where these products live The home lab, the clinic, the startup's wiring closet An unpatched device is a debt you cannot forgive When the attacker comes to collect and deposit Defenders must move faster than the exploit code Subscription feeds and patch notes read them every day The window between disclosure and attack is narrow Don't let a known CVE be the one that got away [Outro] So audit every version, cross-check every plugin The perfidious attack hides where the code forgets to ask August ninth, 2026 — four critical warnings Security's never finished, always the next task Check 18602, 39932 41452 and 18614 Four numbers to remember, four systems to remediate Before an adversary turns your network into bait
← Critical CVEs (2 of 3) — August 09, 2026 | IT Security News — August 09, 2026 →