Several critical vulnerabilities have been disclosed affecting a range of widely used software platforms, including the Linux InputPlumber component, Apache Uniffle, legacy Vivotek cameras, Ubuntu Linux Kernel, Apache Struts 2, and React Router. Each vulnerability presents unique risks, such as remote code execution, information disclosure, privilege escalation, and unauthorized access, potentially impacting both enterprise and consumer environments. Security advisories urge immediate attention to patching and mitigation, as attackers could exploit these flaws to compromise systems, intercept sensitive data, or disrupt operations.
The Ubuntu Linux Kernel advisory details multiple CVEs affecting various LTS versions, with potential impacts including denial of service, elevation of privilege, and information disclosure. Other reports highlight specific vulnerabilities: InputPlumber flaws could allow hijacking of Linux gaming sessions, Apache Uniffle and Struts 2 flaws expose clusters and data to eavesdropping and leakage, React Router's CVE-2025-61686 could lead to server file exposure, and unpatched Vivotek cameras are broadcasting live video feeds publicly. Organizations are advised to review vendor advisories and apply security updates promptly to mitigate these threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A report disclosed critical InputPlumber flaws that could expose Linux gamers to hijacking. The supplied reference did not provide technical details, affected versions, or mitigation guidance.
A vulnerability report identified CVE-2025-61686 as a critical React Router flaw that could expose server files. The provided content did not specify affected versions, exploitation status, or fixes.
HKCERT published a security bulletin covering multiple vulnerabilities affecting the Ubuntu Linux kernel. The supplied reference did not include vulnerability details or patch information.
A report disclosed that unpatched legacy Vivotek cameras were exposed in a way that allowed live video to be broadcast publicly. The reference did not include technical specifics, affected models, or remediation details.
A vulnerability identified as CVE-2025-68637 was reported as a critical flaw in Apache Uniffle that could expose clusters to eavesdropping. No further technical details, affected versions, or mitigations were provided in the reference.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcesecurityonline.info
Open sourcehkcert.org
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.