< Back to all clusters
[TECHNOLOGY] · Germany · 6 sources

Critical security flaws exploited in JTL‑Shop, Chrome, Langflow and SimpleHelp

A critical server‑side template injection vulnerability (CVE‑2026‑54390) in JTL‑Shop 5.x is being actively exploited. Attackers have compromised shops, exfiltrated database, FTP, SMTP and SSH credentials and uploaded malicious code. JTL has issued patches and advises shop owners to update immediately and rotate all access credentials.

Google released Chrome version 150.0.7871 (46‑47‑63) that closes 382 security bugs, 15 of them rated critical. The patches were generated largely with AI‑assisted vulnerability discovery. Users should verify that the latest version is installed on all platforms.

Langflow’s unauthenticated remote‑code‑execution flaw (CVE‑2026‑33017, CVSS 9.3) is being used to load a Monero miner on publicly reachable AI‑workflow instances. The exploit targets exposed installations and can also serve as a foothold for further attacks. Operators are urged to apply the vendor’s fix and restrict internet exposure.

SimpleHelp suffered an authentication bypass (CVE‑2026‑48558) rated CVSS 10. The bug allows forged identity tokens to bypass signature checks, granting full technician access and enabling the deployment of the Djinn stealer, which harvests credentials for AI development tools. The vulnerability is patched in version 5.5.16 and 6.0 RC2; affected installations should update without delay.