CERT Polska disclosed two vulnerabilities in Simple SA's Wirtualna Uczelnia software, including CVE-2026-34906, a server-side template injection flaw that can let an unauthenticated attacker achieve remote code execution through the redirectToUrl endpoint and its redirectUrlParameter parameter. The issue affects versions up to and including wu#2016.437.295#0#20260327_105545, and public vulnerability records describe network-based exploitation with low attack complexity, no required privileges, and no user interaction. The flaw is classified as CWE-1336 and could allow arbitrary template expressions to execute on the server, including commands that establish a reverse shell.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
CISA added Oracle WebLogic flaw CVE-2024-21182 to its Known Exploited Vulnerabilities catalog after it was found to be actively exploited in attacks. Federal agencies were ordered to patch by June 4 under Binding Operational Directive 22-01, and private-sector defenders were urged to remediate quickly.
CVE-2026-34906 was recorded by cvd@cert.pl on June 2, 2026. The entry describes an unauthenticated SSTI in the redirectToUrl endpoint's redirectUrlParameter that can lead to remote code execution, including reverse shell access.
CERT Polska disclosed CVE-2026-34906 and CVE-2026-34907 affecting Simple SA's Wirtualna Uczelnia on 2026-06-02. The issues are an unauthenticated SSTI leading to remote code execution and a reflected XSS flaw, affecting versions through wu#2016.437.295#0#20260327_105545; Dawid Bakaj of VIPentest was credited with reporting them.
Oracle patched CVE-2024-21182 in July 2024. The high-severity Oracle WebLogic Server vulnerability affects versions 12.2.1.4.0 and 14.1.1.0.0 and can be exploited remotely without authentication over T3 or IIOP.
IBM disclosed CVE-2026-8644, an identity spoofing vulnerability in WebSphere Application Server, and rated it CVSS 9.1. IBM said affected users should apply interim fix APAR PH71422 or upgrade to fixed releases 9.0.5.29 or 8.5.5.30 and later, with no workarounds available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcebleepingcomputer.com
Open sourceibm.com
Open sourcecert.pl
Open sourcecert.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.