CVSS 10 in Eclipse BaSyx, unauthenticated admin in OpenCTI, and a no-auth RCE in MeiG IoT
Five CVEs today, none exploited yet but three are unauthenticated and critical. Eclipse BaSyx Java Server SDK scores a perfect 10 via path traversal to RCE, OpenCTI 6.6-6.9.12 hands out admin API access with no credentials, and MeiG FORGE_SLT711 devices allow OS command injection over HTTP. Also: a libssh2 integer overflow (CVSS 7.3) and a Realtek Wi-Fi kernel driver that ships debug ioctls with zero access control (CVSS 7.7).
Five fresh CVEs today, none exploited in the wild yet, but the severity scores are loud. The headliner is CVE-2026-7411: a CVSS 10.0 unauthenticated RCE in Eclipse BaSyx Java Server SDK that lets anyone write files anywhere on your filesystem via path traversal. Right behind it, OpenCTI and MeiG Smart devices both have unauth bugs north of 9.0. Nothing on fire yet, but if any of these face the internet, don't wait.
Today's CVEs
Sorted by urgencyCVE-2026-36356
NVDAn attacker can run arbitrary OS commands on MeiG Smart FORGE_SLT711 devices without any authentication by hitting the /action/SetRemoteAccessCfg endpoint on the built-in GoAhead web server. No credentials, no user interaction, just a crafted HTTP request gives full command execution. If these devices are reachable from the internet, you're already exposed.
- Affected estate
- Anyone running MeiG Smart FORGE_SLT711 devices with firmware MDM9607.LE.1.0-00110-STD.PROD-1
- How to check
- Scan your network for devices exposing the /action/SetRemoteAccessCfg endpoint on GoAhead, or check device firmware version via the management interface.
- Included because
- unauthenticated; internet-facing potential; command injection; CVSS 9.1
- Action
- Apply vendor firmware update if available. If not, isolate the device from untrusted networks and block HTTP/HTTPS access to the management interface.
- Why it matters
- Unauthenticated command injection at CVSS 9.1 means any reachable device can be fully compromised remotely with zero interaction.
Evidence trail
- NVD: View source
CVE-2026-7598
MSRCAn integer overflow in libssh2's password authentication code could let an attacker corrupt memory during SSH authentication. Exploitation isn't trivial, but a successful attack could lead to code execution or a crash in any application that uses libssh2 for SSH connections. This affects libssh2 packages on Azure Linux 3.0 and CBL Mariner 2.0, including nmap builds that bundle it.
- Affected estate
- Teams running Azure Linux 3.0 or CBL Mariner 2.0 systems with libssh2 or nmap installed
- How to check
- Run `rpm -q libssh2 nmap` or `tdnf list installed libssh2 nmap` to confirm installed versions.
- Included because
- common library; memory corruption; CVSS 7.3; low EPSS indicates limited near-term exploitation risk
- Action
- Run `tdnf update libssh2 nmap` to pull patched packages.
- Why it matters
- Memory corruption during SSH auth could crash or compromise any tool using libssh2, including automated scanning and management scripts.
- Source
- NVD
Evidence trail
- NVD: View source
CVE-2026-36355
NVDThe Realtek rtl8192cd Wi-Fi kernel driver ships debug ioctl handlers (read_mem and write_mem) in production builds with zero access control. A local attacker can use these to read or write arbitrary kernel memory, which is a straight path to privilege escalation or full device compromise. This affects all known versions of the Realtek rtl819x Jungle SDK through v3.4.14B, which means a huge number of consumer and embedded routers and access points.
- Affected estate
- Anyone managing routers, access points, or embedded devices built on the Realtek rtl819x Jungle SDK (v3.4.14B and earlier)
- How to check
- Identify devices using Realtek Wi-Fi chipsets in your inventory. Check firmware release notes or contact the device OEM to confirm whether the rtl819x Jungle SDK is in use.
- Included because
- kernel-level memory access; no access control; widespread embedded use; CVSS 7.7
- Action
- Apply vendor firmware updates when available. If no patch exists, limit local access and segment these devices away from sensitive networks.
- Why it matters
- Kernel memory read/write with no access control gives a local attacker full control of the device, and exploitation requires only local access with no special privileges.
Evidence trail
- NVD: View source
CVE-2026-7411
NVDAn unauthenticated attacker can upload files to any location on the filesystem by abusing a path traversal bug in the Eclipse BaSyx Java Server SDK's Submodel HTTP API. A crafted fileName parameter during file upload lets the attacker write outside the intended directory, which leads directly to remote code execution. This is a CVSS 10.0: no authentication, no user interaction, full system compromise.
- Affected estate
- Anyone running Eclipse BaSyx Java Server SDK prior to version 2.0.0-milestone-10
- How to check
- Check your BaSyx deployment version in the application's pom.xml, build manifest, or container image tag. Any version before 2.0.0-milestone-10 is vulnerable.
- Included because
- unauthenticated; remote code execution; path traversal; CVSS 10.0; no user interaction
- Action
- Upgrade to Eclipse BaSyx Java Server SDK 2.0.0-milestone-10 or later. If you cannot upgrade immediately, restrict network access to the Submodel API endpoint.
- Why it matters
- Unauthenticated arbitrary file write equals remote code execution. CVSS 10.0 with no interaction required means any exposed instance is trivially compromisable.
Evidence trail
- NVD: View source
CVE-2026-27960
NVDOpenCTI versions 6.6.0 through 6.9.12 have a privilege escalation bug that lets an unauthenticated attacker query the API as any existing user, including the default admin account. No credentials needed. If your OpenCTI instance is reachable, an attacker gets full admin access to your threat intelligence platform.
- Affected estate
- Anyone running OpenCTI 6.6.0 through 6.9.12
- How to check
- Check your OpenCTI version in the web UI footer or via the API. Any version from 6.6.0 to 6.9.12 inclusive is vulnerable.
- Included because
- unauthenticated; privilege escalation to admin; CVSS 9.8; common security tool
- Action
- Upgrade to OpenCTI 6.9.13. If you can't upgrade right now, set APP__ADMIN__EXTERNALLY_MANAGED to disable the default admin account.
- Why it matters
- Unauthenticated API access as admin means full control of your threat intelligence data, including the ability to read, modify, or delete everything in the platform.
Evidence trail
- NVD: View source
One email, every Wednesday morning.
SubscribeFrom this beat
Read the rest of the field notes โ