DAILY BRIEFING
Ubiquiti patches three max severity security vulnerabilities
Today's briefing covers patched Ubiquiti vulnerabilities, active exploitation of a Gitea flaw, unpatched Kaltura remote code execution bugs, and Windows 11 privacy controls.
5 stories2 min read

Critical infrastructure and web applications face immediate risk today as threat actors actively exploit a critical Gitea flaw, while unpatched vulnerabilities in Kaltura's video player library leave servers exposed to remote code execution and arbitrary file access.
Security teams should prioritize applying Ubiquiti's security patches for three maximum-severity flaws and securing external access to Kaltura's mwEmbedLoader.php endpoint while waiting for an official patch.
Ubiquiti patches three max severity security vulnerabilities
Ubiquiti released security patches addressing three maximum-severity vulnerabilities that allow unauthenticated remote attackers to exploit systems without privileges.
Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
CERT/CC disclosed two unpatched unsafe deserialization flaws (CVE-2026-19913 and CVE-2026-19912) in Kaltura's mwEmbed library allowing remote arbitrary file reads and code execution.
- Why it matters
- Unauthenticated attackers can exploit the mwEmbedLoader.php endpoint remotely without account access or session tokens.
- What to do
- Restrict public network access to mwEmbedLoader.php and restrict the ServiceUrl parameter using a strict allow-list.
Hackers now exploit critical Gitea flaw in code injection attacks
CISA confirmed active exploitation of a critical-severity code injection vulnerability impacting self-hosted Gitea Git instances.
- What to do
- Update self-hosted Gitea instances to the latest secure version immediately.
Microsoft tests new privacy controls for Windows 11 desktop apps
Microsoft has begun testing updated Windows 11 privacy settings enabling users to grant or block desktop app access to location, camera, and microphone.
- What to do
- Review application permissions once the updated Windows 11 controls are deployed.
Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine
Security operations are shifting from queue-based manual alert triage toward agentic AI models designed to execute hypothesis-driven investigations faster.
Key takeaways
- Ubiquiti released patches for three maximum-severity security vulnerabilities actionable remotely without privileges.
- CISA warned that attackers are actively exploiting a critical-severity vulnerability in the Gitea self-hosted Git service.
- CERT/CC disclosed unpatched flaws CVE-2026-19913 and CVE-2026-19912 in Kaltura's mwEmbed player library allowing arbitrary file read and code execution.
- Microsoft started testing Windows 11 privacy controls allowing users to manage desktop application access to camera, microphone, and precise location.