Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Business Software Exploited in 2026: Splunk, WSO2, TrueConf, Sangoma Switchvox, PTC Windchill, Serv-U

Critical CVE-2026-20253, CVE-2026-5430, CVE-2026-72529, CVE-2026-72530, CVE-2026-9586, CVE-2026-12569, CVE-2026-28318 — A roundup of exploited 2026 vulnerabilities in business platforms: an unauthenticated Splunk file write, a WSO2 JWT algorithm bypass (CVSS 10), TrueConf video server RCE, Switchvox phone-system SQL injection, PTC Windchill RCE used by ransomware, and a Serv-U crash bug.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Seven more exploited bugs in software businesses run on-premises, most with no login needed: Splunk Enterprise 10.x file create/truncate, WSO2 API Manager accepting JWTs signed with the wrong algorithm, TrueConf Server sandbox escape over port 4307, Switchvox SQL injection to RCE, PTC Windchill/FlexPLM deserialization RCE (ransomware), and a Serv-U crash. Fixed versions below.

CVE-2026-20253Splunk Enterprise 10.2 < 10.2.4, 10.0 < 10.0.7: unauthenticated file create/truncate via PostgreSQL sidecar endpoint. CVSS 9.8
CVE-2026-5430WSO2 API Manager, Universal Gateway, Traffic Manager, API Control Plane: JWT algorithm mismatch → account takeover. CVSS 10
CVE-2026-72529 / 72530TrueConf Server ≤ 5.5.5: undocumented function runs scripts; sandbox escape → host code execution. Port 4307/TCP
CVE-2026-9586Sangoma Switchvox SMB 8.3: unauthenticated SQL injection via /pa → RCE. Fixed 8.4.0.2
CVE-2026-12569PTC Windchill PDMLink / FlexPLM: deserialization RCE. Known ransomware use
CVE-2026-28318SolarWinds Serv-U ≤ 15.5.4: unauthenticated crash via deflate POST. Fixed in 15.5.4 Hotfix 1

Splunk Enterprise: CVE-2026-20253

Splunk Enterprise 10.x runs a PostgreSQL sidecar service whose endpoint had no authentication, so anyone who can reach it over the network can create or truncate arbitrary files. Truncating the right file breaks Splunk; creating the right one can lead further. Affected: 10.2 below 10.2.4 and 10.0 below 10.0.7. Splunk 9.4 and earlier are not affected. Upgrade, and keep Splunk management ports (8089 etc.) off untrusted networks.

WSO2 API Manager and gateways: CVE-2026-5430

WSO2’s JWT authentication accepted tokens signed with algorithms other than the configured one, so an attacker can craft a token that validates, up to and including administrative accounts. Affects API Manager 4.1–4.5, Universal Gateway, Traffic Manager and API Control Plane 4.5/4.6. Apply the WSO2 updates from advisory WSO2-2026-5328 (e.g. API Manager 4.5.0.57+, 4.4.0.72+, 4.3.0.108+; Universal Gateway 4.6.0.21+) via the WSO2 Update Tool.

TrueConf Server: CVE-2026-72529 and 72530

TrueConf is an on-premises video conferencing server. An unauthenticated attacker who can reach port 4307/TCP can call an undocumented function to run a script (72529), and a crafted script can then break out of the isolated environment to run code on the host (72530). Affected: versions before 5.3, 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5. Update to the latest release from TrueConf and firewall 4307 to trusted networks only.

Sangoma Switchvox: CVE-2026-9586

Switchvox SMB phone systems process Polycom phone XML at the /pa endpoint, and the PhoneIP value went straight into PostgreSQL queries. Unauthenticated SQL injection there leads to remote code execution on the PBX, and from there to toll fraud, call interception and a foothold in the office network. Update to Switchvox 8.4.0.2 (July 14, 2026) or later, and never expose the Switchvox web/provisioning interface to the internet.

PTC Windchill / FlexPLM: CVE-2026-12569

A deserialization flaw in Windchill PDMLink and FlexPLM, the product-lifecycle systems that hold manufacturers’ CAD files and designs, allows remote code execution. CISA lists known ransomware use. It affects a wide range of releases (11.0 M030 and earlier through 13.0.2.0, plus all CPS versions). Apply the fix from PTC article CS473270 and restrict Windchill to internal networks/VPN.

SolarWinds Serv-U: CVE-2026-28318

A crafted POST request with Content-Encoding: deflate crashes Serv-U file transfer servers without authentication. Version 15.5.4 and earlier are affected. Install 15.5.4 Hotfix 1, or follow the mitigation in SolarWinds’ Trust Center if you can’t update yet.

For all of these

  • Keep a list of on-prem business software and who’s responsible for patching each one. These products don’t update themselves.
  • Only expose what customers or remote staff truly need, and put the rest behind a VPN.
  • After patching anything that was internet-facing on a vulnerable version, review admin accounts, logs and new files for signs someone got in first.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories