Critical CVEs (3 of 3) — August 10, 2026

acoustic chicago blues algorave, intimate close-mic vocals, lo-fi bedroom production, melancholic and introspective, downtempo groove, rippling piano arpeggios · 5:03

Listen on 93

Lyrics

[Verse 1]
GL-iNet router, model MT three-thousand
Software version four-point-four-point-five
A function called ovpn-client dot get-recommend-config
Opens up a channel, lets the wrong ones inside
CVE-2026-18602, score of nine-point-eight
The native plugin sitting in the CGI gate
An attacker sends a crafted argument through
And the router executes whatever they want it to

[Chorus]
Nine-point-eight, nine-point-one, critical alarm
Patch the door before the intruder does harm
Routers, CRMs, medical records at stake
These aren't hypotheticals — something can break
Check your versions, cross-reference what you run
August tenth, twenty-twenty-six, the audit's begun

[Verse 2]
Same router, different function — s2s dot enable-echo-server
Another native plugin, another cracked seam
CVE-2026-18614, matching score of nine-point-eight
Manipulation of arguments makes the process scream
Two separate wounds in the same device, same firmware shelf
GL-iNet users — you cannot patch yourself by waiting
Vendors move slowly, attackers move faster
Knowing both entry points doubles the disaster

[Chorus]
Nine-point-eight, nine-point-one, critical alarm
Patch the door before the intruder does harm
Routers, CRMs, medical records at stake
These aren't hypotheticals — something can break
Check your versions, cross-reference what you run
August tenth, twenty-twenty-six, the audit's begun

[Bridge]
Now Krayin CRM, version two-point-two-point-four
Missing authentication at the installer door
No credentials needed — send a crafted request
Overwrite the admin, you own the nest
CVE-2026-41452, nine-point-eight again
An unauthenticated stranger becomes the one who reigns

And OpenEMR through eight-point-two-point-zero
Remote code execution — no one plays the hero
Authenticated admins, yes, but that bar is low
Document category tree lets arbitrary processes flow
CVE-2026-39932, nine-point-one on the scale
Medical system compromised — patient data frail

[Chorus]
Nine-point-eight, nine-point-one, critical alarm
Patch the door before the intruder does harm
Routers, CRMs, medical records at stake
These aren't hypotheticals — something can break
Check your versions, cross-reference what you run
August tenth, twenty-twenty-six, the audit's begun

[Outro]
Four CVEs, two devices, one urgent refrain
GL-iNet routers bleeding from two separate veins
Krayin CRM handing keys to the uninvited guest
OpenEMR letting code run wild inside the chest
Scores of nine-point-eight, nine-point-one — don't archive and forget
The window between disclosure and patching fills with threat

← Critical CVEs (2 of 3) — August 10, 2026 | IT Security News — August 10, 2026 →