Unpatched Kaltura mwEmbed Vulnerabilities Allow Remote File Read and Code Execution
CERT/CC discloses two CVEs tied to unsafe deserialization in mwEmbedLoader.php endpoint

Key Takeaways
- CERT/CC disclosed two unpatched CVEs in Kaltura's mwEmbed HTML5 video player library.
- Both flaws stem from unsafe deserialization in the mwEmbedLoader.php endpoint.
- A remote, unauthenticated attacker can read arbitrary files and execute code on the server.
- No patch is currently available; Kaltura has not released a fix as of the disclosure date.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


