Critical CVEs (3 of 3) — August 09, 2026

r&b gospel, soulful vocals, gritty distorted mix, laid-back and groovy, midtempo, warm strummed acoustic guitar · 4:12

Listen on 93

Lyrics

[Verse 1]
GL-iNet router, model MT3000
Running firmware up to four point four point five
Two functions sitting in the native plugin code
Quietly waiting to compromise your drive
The first one handles OpenVPN configuration
Fetching recommended settings through a broken gate
The second echoes packets server-to-server
Both carrying CVSS scores of nine point eight

[Chorus]
CVE-2026-18602 and 18614
Two holes in the GL-iNet, exploitation's at the door
Manipulation of arguments, no safe ground to stand
Remote code execution waiting close at hand
Patch your router, patch it now, don't deliberate
Nine point eight out of ten — that's a critical weight

[Verse 2]
Now picture OpenEMR, the medical record suite
Version eight point two point oh, where patient data sleeps
An authenticated admin finds a document tree
A library class called Tree dot class dot php
They craft a payload through the category structure
Arbitrary code runs inside the server walls
Nine point one on the scale — still catastrophic pressure
When healthcare software answers the wrong calls

[Chorus]
CVE-2026-39932, doctors take note
Remote code execution, attacker stays afloat
Admin credentials give them everything they need
Library-class manipulation plants the seed
Patch your OpenEMR before the wound goes septic
The damage to your patients would be apoplectic

[Bridge]
Here's a word worth holding — *perfidious*
Meaning treacherous, faithfully concealing harm
That's what these vulnerabilities embody
A smiling interface with an alarm
Krayin CRM, version two point two point four
The installer middleware forgot to check the badge
An unauthenticated stranger at the door
Can overwrite your primary admin in a flash

[Verse 3]
CVE-2026-41452, another nine point eight
No login? No problem — the middleware waves you through
A crafted request rewrites the administrator
Handing crown and keys to someone no one knew
Four CVEs today, three products standing naked
GL-iNet twice, then OpenEMR, then Krayin's flaw
The collective weight of these scores is staggering
Vendors, issue patches — this is not a minor thaw

[Verse 4]
Consider every network where these products live
The home lab, the clinic, the startup's wiring closet
An unpatched device is a debt you cannot forgive
When the attacker comes to collect and deposit
Defenders must move faster than the exploit code
Subscription feeds and patch notes read them every day
The window between disclosure and attack is narrow
Don't let a known CVE be the one that got away

[Outro]
So audit every version, cross-check every plugin
The perfidious attack hides where the code forgets to ask
August ninth, 2026 — four critical warnings
Security's never finished, always the next task
Check 18602, 39932
41452 and 18614
Four numbers to remember, four systems to remediate
Before an adversary turns your network into bait

← Critical CVEs (2 of 3) — August 09, 2026 | IT Security News — August 09, 2026 →