<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Vulnerability Bulletins on Aretiq AI</title><link>https://aretiq.ai/bulletins/</link><description>Recent content in Vulnerability Bulletins on Aretiq AI</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 25 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://aretiq.ai/bulletins/index.xml" rel="self" type="application/rss+xml"/><item><title>Vulnerability Bulletin — May 25, 2026</title><link>https://aretiq.ai/bulletins/2026-05-25/</link><pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/bulletins/2026-05-25/</guid><description>&lt;p>&lt;strong>4 vulnerabilities&lt;/strong> scored HIGH or above on May 25, 2026.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>HIGH&lt;/strong>: 4&lt;/li>
&lt;/ul>
&lt;h3 id="high-crocoblockjetengine">[HIGH] crocoblock/jetengine&lt;/h3>
&lt;p>&lt;strong>CVE-2026-42774&lt;/strong> | CVSS 9.3&lt;/p>
&lt;p>Crocoblock JetEngine plugin version 3.8.8.1 and earlier contains a SQL injection vulnerability (CVE-2026-42774, CVSS 9.3) that allows attackers to execute arbitrary SQL commands. Website administrators and organizations running WordPress with JetEngine should immediately update to the latest patched version to prevent potential database compromise. Given the theoretical availability of exploitation code, this update should be treated as high priority, particularly for instances handling sensitive data.&lt;/p></description></item><item><title>Vulnerability Bulletin — May 24, 2026</title><link>https://aretiq.ai/bulletins/2026-05-24/</link><pubDate>Sun, 24 May 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/bulletins/2026-05-24/</guid><description>&lt;p>&lt;strong>1 vulnerabilities&lt;/strong> scored HIGH or above on May 24, 2026.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>HIGH&lt;/strong>: 1&lt;/li>
&lt;/ul>
&lt;h3 id="high-totolinka8000ru">[HIGH] totolink/a8000ru&lt;/h3>
&lt;p>&lt;strong>CVE-2026-9386&lt;/strong> | CVSS 9.3&lt;/p>
&lt;p>Totolink A8000RU router users running firmware version 7.1cu.643_b20200521 should prioritize patching a remote OS command injection vulnerability (CVE-2026-9386, CVSS 9.3) in the web management interface. An attacker can exploit the setLanguageCfg function via the lang parameter in /cgi-bin/cstecgi.cgi to execute arbitrary commands without authentication, and public exploit code is available. Organizations using these devices should immediately update to the latest firmware version or restrict network access to the management interface until a patch is deployed.&lt;/p></description></item><item><title>Vulnerability Bulletin — May 23, 2026</title><link>https://aretiq.ai/bulletins/2026-05-23/</link><pubDate>Sat, 23 May 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/bulletins/2026-05-23/</guid><description>&lt;p>&lt;strong>2 vulnerabilities&lt;/strong> scored HIGH or above on May 23, 2026.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>HIGH&lt;/strong>: 2&lt;/li>
&lt;/ul>
&lt;h3 id="high-dolibarrdolibarr_erp_crm">[HIGH] dolibarr/dolibarr_erp_crm&lt;/h3>
&lt;p>&lt;strong>CVE-2018-25357&lt;/strong> | CVSS 9.3&lt;/p>
&lt;p>Dolibarr ERP CRM versions 7.0.3 and earlier are vulnerable to unauthenticated remote code execution through the installation script, with a CVSS score of 9.3. Attackers can inject arbitrary PHP code via the db_name parameter in install/step1.php and execute commands through the check.php endpoint without authentication. Organizations running Dolibarr should immediately upgrade to patched versions, restrict web access to installation directories, and review access logs for exploitation attempts.&lt;/p></description></item><item><title>Vulnerability Bulletin — May 22, 2026</title><link>https://aretiq.ai/bulletins/2026-05-22/</link><pubDate>Fri, 22 May 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/bulletins/2026-05-22/</guid><description>&lt;p>&lt;strong>9 vulnerabilities&lt;/strong> scored HIGH or above on May 22, 2026.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>CRITICAL&lt;/strong>: 4&lt;/li>
&lt;li>&lt;strong>HIGH&lt;/strong>: 5&lt;/li>
&lt;/ul>
&lt;h3 id="-linuxlinux_kernel">&lt;strong>[CRITICAL]&lt;/strong> linux/linux_kernel&lt;/h3>
&lt;p>&lt;strong>CVE-2026-9054&lt;/strong> | CVSS 9.2&lt;/p>
&lt;p>The Linux kernel is vulnerable to a denial-of-service condition (CVE-2026-9054, CVSS 9.2 CRITICAL) where specially crafted TCP, IL, RUDP, or GRE packets with malformed headers can trigger a kernel panic. Network-facing Linux systems are at immediate risk, particularly those processing untrusted or internet-routed traffic. Administrators should apply kernel patches from the vendor advisory without delay and consider implementing network segmentation to limit exposure to potentially malicious packet sources.&lt;/p></description></item><item><title>Vulnerability Bulletin — May 21, 2026</title><link>https://aretiq.ai/bulletins/2026-05-21/</link><pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/bulletins/2026-05-21/</guid><description>&lt;p>&lt;strong>15 vulnerabilities&lt;/strong> scored HIGH or above on May 21, 2026.&lt;/p>
&lt;ul>
&lt;li>&lt;strong>CRITICAL&lt;/strong>: 1&lt;/li>
&lt;li>&lt;strong>HIGH&lt;/strong>: 14&lt;/li>
&lt;/ul>
&lt;h3 id="-googlechrome">&lt;strong>[CRITICAL]&lt;/strong> google/chrome&lt;/h3>
&lt;p>&lt;strong>CVE-2026-9111&lt;/strong> | CVSS 8.8&lt;/p>
&lt;p>Google Chrome versions prior to 148.0.7778.179 on Linux are affected by a critical use-after-free vulnerability in WebRTC that allows remote code execution through a crafted HTML page. CVSS 8.8. Organizations running Chrome on Linux systems should immediately update to version 148.0.7778.179 or later, as exploitation is difficult but feasible. Patch deployment should prioritize systems with direct internet access, particularly development workstations and Linux-based productivity environments.&lt;/p></description></item></channel></rss>