Category: News

Weekly roundups of homelab/self-hosted/sysadmin news from around the web

  • News Roundup: August 27–September 6, 2026

    A quieter week than the last one, but still a few things worth patching for: a fresh WordPress migration-plugin bug with a genuinely clever exploit chain, a MikroTik security release that’s light on details, and a heavy batch of critical Cisco advisories.

    • All-in-One WP Migration and Backup patches a second-order SQL injection (CVE-2026-19949, CVSS 8.8) affecting over 3 million sites. The exploit chain is worth knowing about even if you don’t run this plugin: an attacker submits two trackbacks containing a trailing backslash and a payload URL, which the plugin fails to sanitize; once an admin exports and re-imports a site archive, that unsanitized input gets promoted into executable SQL, leaking the plugin’s secret key into a public comment. From there, an unauthenticated attacker can import a crafted archive containing a malicious must-use plugin for full RCE. Multi-step, but entirely unauthenticated end to end.
    • MikroTik shipped RouterOS 7.24.2 (stable/testing), 7.23.4 (long-term), and 6.49.21 (legacy) on September 3 as “important security updates,” deliberately withholding vulnerability details for now to give admins time to patch. Worth noting: this release adds a “Flagged” device status that RouterOS will set automatically if it detects your device has already been compromised, check your Log for it after updating. Regardless of what the underlying bug turns out to be, this is a good week to confirm Winbox, SSH, and HTTP management access are firewalled to trusted hosts only.
    • Cisco’s September 2 advisory batch included two critical (CVSS 9.8) issues worth flagging if you’re running the affected gear: an IOS XR security hardening release covering seven CVEs, and a Nexus 9000 Series Silicon One remote code execution bug (CVE-2026-20212). Neither is reported as exploited in the wild yet, but a 9.8 on core routing/switching platforms isn’t one to defer.
    • WordPress 7.1.1 is scheduled as a bug-fix-only maintenance release for September 17, with RC1 landing September 10. No security fixes listed so far, so it’s a lower-priority update than the plugin issue above, but worth having on the calendar for the current WP 7.1 stack.
  • News Roundup: August 19–26, 2026

    News Roundup: August 19–26, 2026

    This week’s roundup leans heavily on WordPress plugin security — three separate critical bugs landed in the space of a few days — plus the usual crop of vendor releases for the stack this blog runs.

    • Elementor Pro 4.2.2 fixes an unauthenticated RCE (CVE-2026-32475, CVSS 9.0) in the File Upload form module — any site with a published Elementor form containing a file upload field could have a PHP file dropped and executed with no login and no nonce. The researcher reported it in mid-July and Elementor had a fix ready within a day, but sat on the release for over a month. If you run Elementor Pro forms, don’t assume “recently patched” means “recently disclosed.”
    • Everest Forms patched an unauthenticated file-upload RCE (CVE-2026-19598) affecting over 100,000 sites — a second forms plugin with essentially the same class of bug as Elementor’s this week. If you’re running any form plugin with file-upload fields, this is a good week to audit which ones are actually still needed on your site.
    • TranslatePress 3.3.2 closes a critical, unauthenticated privilege-escalation bug (CVE-2026-19632, CVSS 9.8) that let attackers hijack administrator accounts outright. Combined with the two form-plugin bugs above, it’s been a rough week for WordPress plugin security specifically — worth a pass through your installed plugins if you haven’t updated in a while.
    • WordPress core 7.0.4 is a security-only release fixing an authenticated Author+ remote code execution bug (CVE-2026-65640) on sites running Imagick with Ghostscript. Narrower than the plugin bugs above, but nastier if you accept uploads from non-admin users — don’t wait on auto-updates for this one.
    • nginx 1.31.4 (mainline) / 1.30.4 (stable) patch a heap buffer overflow in the map directive’s regex handling (CVE-2026-42533) and a memory-disclosure bug in ngx_http_slice_module (CVE-2026-60005). Routine but not optional if nginx is sitting in front of anything.
    • Proxmox VE 8 reaches end of life on August 31 — no more security patches after that date, so this is the week to schedule the upgrade to VE 9 if you haven’t already. Separately, Proxmox VE 9.2 shipped official Arm64 support with full KVM/LXC/ZFS/Ceph parity, worth a look if you’re running or considering Arm homelab hardware.
    • Linux 7.2 is out, one of the busier kernel cycles on record at nearly 600,000 lines changed. Also worth noting: Fedora is taking the first concrete step toward restricting AF_ALG, the kernel’s userspace crypto API that’s been the source of several serious bugs this year — check whether anything on your boxes touches it directly before it starts getting locked down upstream.
    • MikroTik shipped RouterOS 7.24.1 stable, a maintenance release with bridge MLAG fixes on CRS8xx switches, VRRP-on-bridge stability improvements, and container host isolation hardening. If your MikroTik box is doing edge routing, it’s an easy hour of maintenance with real payoff.
    • InfluxDB 3.8 (Core and Enterprise) is about operational maturity rather than new query features — proper systemd units on the deb/rpm packages and an official Helm chart for running Enterprise on Kubernetes. Relevant if you’re on the TICK stack for homelab metrics and haven’t looked at the 3.x line yet.