Critical Vulnerabilities in Kaltura HTML5 Player Expose Organizations to Attacks
ID: 0e82da64-f573-53c8-b237-40289dc15914
STIX ID: report--0e82da64-f573-53c8-b237-40289dc15914
Feed Name: ThreatCluster
Threat Score
Two critical vulnerabilities in the Kaltura HTML5 Player (CVE-2026-19912 and CVE-2026-19913) enable unauthenticated remote code execution and file disclosure via mwEmbedLoader.php due to unsafe deserialization and improper handling of user-controlled parameters; over 600 internet-facing instances are reported exposed, proof-of-concept exploit code is available, and no official patches exist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
