Executive assessment
Today's brief leads with utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket. All 3 selected findings retain their own technical scope, action, observed status, and evidence limits.
Finding 01 — utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket
What changed: CVE coverage: CVE-2026-12210, CVE-2026-44661. (Unconfirmed, single-source.)
Technical evidence: CVE-2026-12210; CVSS v4.0 5.3; weakness ['CWE-918']; technical confidence Medium.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-12210 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: github.com](<https://github.com/advisories/GHSA-ppx3-28rw-8fpf>)
Finding 02 — Multiple vulnerabilities in ESRI Portal for ArcGIS
What changed: An attacker can exploit multiple vulnerabilities in ESRI Portal for ArcGIS to carry out cross-site scripting and HTML injection attacks, bypass authentication or disclose confidential information. CVE coverage: CVE-2026-69224, CVE-2026-69225, CVE-2026-69228, CVE-2026-69229, CVE-2026-69230, CVE-2026-69231, CVE-2026-69232, CVE-2026-69233, CVE-2026-69234, CVE-2026-69235, CVE-2026-69236, CVE-2026-69237, CVE-2026-69238, WID-SEC-2026-2966.
Technical evidence: CVE-2026-69224; CVSS v3.1 5.9; weakness ['CWE-200']; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-69224 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2966>)
Finding 03 — Multiple vulnerabilities in ImageMagick
What changed: An attacker can exploit multiple vulnerabilities in ImageMagick to bypass security controls, manipulate data, disclose confidential information or trigger a denial-of-service condition. CVE coverage: WID-SEC-2026-2967.
Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.
Evidence limits: grounded severity unavailable
exploitation status unknown
fixed version or patch state unknown
affected product not structured
[Evidence source: wid.cert-bund.de](<https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2967>)