Critical CVE-2026-20253, CVE-2026-5430, CVE-2026-72529, CVE-2026-72530, CVE-2026-9586, CVE-2026-12569, CVE-2026-28318 — A roundup of exploited 2026 vulnerabilities in business platforms: an unauthenticated Splunk file write, a WSO2 JWT algorithm bypass (CVSS 10), TrueConf video server RCE, Switchvox phone-system SQL injection, PTC Windchill RCE used by ransomware, and a Serv-U crash bug.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Seven more exploited bugs in software businesses run on-premises, most with no login needed: Splunk Enterprise 10.x file create/truncate, WSO2 API Manager accepting JWTs signed with the wrong algorithm, TrueConf Server sandbox escape over port 4307, Switchvox SQL injection to RCE, PTC Windchill/FlexPLM deserialization RCE (ransomware), and a Serv-U crash. Fixed versions below.
| CVE-2026-20253 | Splunk Enterprise 10.2 < 10.2.4, 10.0 < 10.0.7: unauthenticated file create/truncate via PostgreSQL sidecar endpoint. CVSS 9.8 |
|---|---|
| CVE-2026-5430 | WSO2 API Manager, Universal Gateway, Traffic Manager, API Control Plane: JWT algorithm mismatch → account takeover. CVSS 10 |
| CVE-2026-72529 / 72530 | TrueConf Server ≤ 5.5.5: undocumented function runs scripts; sandbox escape → host code execution. Port 4307/TCP |
| CVE-2026-9586 | Sangoma Switchvox SMB 8.3: unauthenticated SQL injection via /pa → RCE. Fixed 8.4.0.2 |
| CVE-2026-12569 | PTC Windchill PDMLink / FlexPLM: deserialization RCE. Known ransomware use |
| CVE-2026-28318 | SolarWinds Serv-U ≤ 15.5.4: unauthenticated crash via deflate POST. Fixed in 15.5.4 Hotfix 1 |
Splunk Enterprise 10.x runs a PostgreSQL sidecar service whose endpoint had no authentication, so anyone who can reach it over the network can create or truncate arbitrary files. Truncating the right file breaks Splunk; creating the right one can lead further. Affected: 10.2 below 10.2.4 and 10.0 below 10.0.7. Splunk 9.4 and earlier are not affected. Upgrade, and keep Splunk management ports (8089 etc.) off untrusted networks.
WSO2’s JWT authentication accepted tokens signed with algorithms other than the configured one, so an attacker can craft a token that validates, up to and including administrative accounts. Affects API Manager 4.1–4.5, Universal Gateway, Traffic Manager and API Control Plane 4.5/4.6. Apply the WSO2 updates from advisory WSO2-2026-5328 (e.g. API Manager 4.5.0.57+, 4.4.0.72+, 4.3.0.108+; Universal Gateway 4.6.0.21+) via the WSO2 Update Tool.
TrueConf is an on-premises video conferencing server. An unauthenticated attacker who can reach port 4307/TCP can call an undocumented function to run a script (72529), and a crafted script can then break out of the isolated environment to run code on the host (72530). Affected: versions before 5.3, 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5. Update to the latest release from TrueConf and firewall 4307 to trusted networks only.
Switchvox SMB phone systems process Polycom phone XML at the /pa endpoint, and the PhoneIP value went straight into PostgreSQL queries. Unauthenticated SQL injection there leads to remote code execution on the PBX, and from there to toll fraud, call interception and a foothold in the office network. Update to Switchvox 8.4.0.2 (July 14, 2026) or later, and never expose the Switchvox web/provisioning interface to the internet.
A deserialization flaw in Windchill PDMLink and FlexPLM, the product-lifecycle systems that hold manufacturers’ CAD files and designs, allows remote code execution. CISA lists known ransomware use. It affects a wide range of releases (11.0 M030 and earlier through 13.0.2.0, plus all CPS versions). Apply the fix from PTC article CS473270 and restrict Windchill to internal networks/VPN.
A crafted POST request with Content-Encoding: deflate crashes Serv-U file transfer servers without authentication. Version 15.5.4 and earlier are affected. Install 15.5.4 Hotfix 1, or follow the mitigation in SolarWinds’ Trust Center if you can’t update yet.
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.