Threat Intelligence

Unpatched Flaws in Popular Video Player Software Could Let Hackers Steal Files and Run Code

The Hacker News · 26 Aug 2026
Key Takeaway If your website uses Kaltura's video embedding software, check with your web developer or hosting provider now to confirm whether you're affected and watch for a security patch to apply immediately.

The CERT Coordination Center (CERT/CC) has publicly disclosed two serious security flaws in Kaltura's mwEmbed HTML5 video player library, a widely used tool for embedding video content on websites. Tracked as CVE-2026-19913 and CVE-2026-19912, both vulnerabilities stem from the same underlying issue: unsafe handling of data in the player's mwEmbedLoader.php file.

What makes these flaws particularly concerning is that they can be exploited by a remote attacker with no login credentials or special access required. Successful exploitation could allow an attacker to read sensitive files stored on the affected server or, more seriously, run their own malicious code on it. This kind of access could lead to data theft, website defacement, or the server being used as a launching point for further attacks.

At the time of disclosure, no official patch was available to fix these vulnerabilities. Businesses that use Kaltura's video embedding tools, whether directly or through a third-party platform, should treat this as an urgent security matter and monitor for vendor updates closely.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.