started · updated
Critical Vulnerabilities Found in JTL Shop, Cisco ISE and Ubiquiti UniFi OS
A server‑side template injection (SSTI) flaw identified as CVE‑2026‑54390 affects JTL Shop versions 5.2.0 through 5.7.1. The vulnerability can be exploited without authentication, allowing attackers to inject Smarty template code, read database credentials and potentially install a web shell. Vendors advise immediate upgrading to a non‑vulnerable release.
Cisco disclosed two high‑severity bugs in its Identity Services Engine (ISE): CVE‑2026‑20181 enables remote code execution when an authenticated administrator sends a crafted HTTP request, while CVE‑2026‑20190 permits unauthenticated information disclosure of hashed credentials. All ISE and ISE‑PIC versions are impacted. Patches are available in ISE 3.3 Patch 11, 3.4 Patch 6 and a forthcoming 3.5 Patch 4; no work‑arounds exist.
Researchers at Bishop Fox revealed a chain of three vulnerabilities in Ubiquiti UniFi OS (CVE‑2026‑34908, CVE‑2026‑34909, CVE‑2026‑34910) that together grant unauthenticated root access on UniFi OS Server 5.0.6 and earlier. The exploit bypasses access controls, performs path‑traversal and command injection, giving full control over network‑management appliances and any connected physical security devices. The issue was patched in UniFi OS 5.0.8, and a detection script has been released for administrators.