Executive assessment
Today's brief leads with Multiple vulnerabilities in Google Chrome. All 7 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — Multiple vulnerabilities in Google Chrome
What changed: An attacker can exploit multiple vulnerabilities in Google Chrome to escalate privileges, bypass security measures, execute arbitrary code or cause denial-of-service conditions. CVE coverage: CVE-2026-76017, CVE-2026-76018, CVE-2026-76019, CVE-2026-76020, CVE-2026-76021, CVE-2026-76022, CVE-2026-76023, WID-SEC-2026-2953.
Technical evidence: CVE-2026-76017; CVSS v3.1 8.8; weakness ['CWE-416']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-76017 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2953>)
Finding 02 — A flaw was found in the clusterclaims-controller component of multicluster engine (MCE).
What changed: A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the spec.namespace field.
Technical evidence: CVE-2026-73267; CVSS v3.1 7.7; weakness ['CWE-602']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-73267 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-73267>)
Finding 03 — Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header.
What changed: Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that it parse with an http or https scheme and a hostname, and returns it for use as the upstream base; _select_passthrough_base_url in headroom/providers/proxy_routes.py reads the same header for the.
Technical evidence: CVE-2026-77775; CVSS v3.1 8.6; weakness ['CWE-918']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-77775 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-77775>)
Finding 04 — to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links.
What changed: to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison performed by is_path_trusted in scripts/iib/api.py while pointing outside that directory, and FileResponse follows the link when serving the response, so a link created in an image.
Technical evidence: CVE-2026-77815; CVSS v4.0 8.7; weakness ['CWE-59']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-77815 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-77815>)
Finding 05 — UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly.
What changed: UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with eval. Attackers can exploit this by crafting malicious filenames or artifact definitions containing shell metacharacters such as command substitution.
Technical evidence: CVE-2026-41450; CVSS v4.0 8.5; weakness ['CWE-78']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-41450 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-41450>)
Finding 06 — UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories.
What changed: UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can inject shell metacharacters such as command substitution syntax or semicolons through crafted usernames or home.
Technical evidence: CVE-2026-41451; CVSS v4.0 8.5; weakness ['CWE-78']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-41451 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-41451>)
Finding 07 — The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check.
What changed: The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options on the WordPress site.
Technical evidence: CVE-2026-19883; CVSS v3.1 8.8; weakness ['CWE-269']; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-19883 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-19883>)