CISA issues alert on OpenCart directory traversal in extension installer
OpenCart v4.2.0.0 extension installer mishandles ZIP paths, enabling file writes to webroot and remote code execution; CVE-2026-18412.
Signals are individual enterprise-technology developments, captured as they happen: product launches, funding, partnerships, executive moves, vulnerabilities, and announcements across cloud infrastructure, networking, security, and AI. Looking for the synthesis? See Briefs
Decision Insights Threat Desk • August 23, 2026
OpenCart v4.2.0.0 extension installer mishandles ZIP paths, enabling file writes to webroot and remote code execution; CVE-2026-18412.
Decision Insights Threat Desk • August 23, 2026
AT&T ARRIS BGW210-700 firmware versions 2.7.7 and earlier allow unauthenticated LAN users to read Wi-Fi keys and change settings. CVE-2026-16771.
Decision Insights Threat Desk • August 23, 2026
foreUP REST API flaws disclose Finix merchant credentials and allow IDOR access to other customers’ profiles, tokens, and billing history.
Decision Insights Threat Desk • August 23, 2026
VPS.org one-click templates use static credentials: Supabase exposes PostgreSQL on 0.0.0.0:5432 and Zulip enables session forgery.
Decision Insights Threat Desk • August 23, 2026
Develar app-builder zipx.Unzip can allow arbitrary file overwrite on macOS via APFS Unicode normalization and symlink following.
Decision Insights Threat Desk • August 23, 2026
Analog Way Picturall Quad Compact Mark II version 3.5.8 has CVE-2026-14985 enabling root via a maintenance script. Fixed in 3.5.9.
Decision Insights Threat Desk • August 23, 2026
GNU Wget versions 1.25.0 and earlier can redirect FTP passive mode data connections using unvalidated PASV IPs, exposing internal responses.
Decision Insights Threat Desk • August 23, 2026
SGLang CVE-2026-14890 allows unauthenticated remote code execution via pickle deserialization when the expert-parallel backup subsystem is enabled.
Decision Insights Threat Desk • August 23, 2026
CVE-2026-59762, CVE-2026-59173 and CVE-2026-44909 describe an HTTP/2 DoS via stalled flow control buffering.
Decision Insights Threat Desk • August 23, 2026
Alinto SOGo versions prior to 5.12.8 contain an XSS flaw in how they render ICS (iCalendar) DESCRIPTION content, allowing an SVG payload with JavaScript to execute in the webmail interface and potentially expose mailbox data. The advisory identifies the issue as CVE-2026-8496.
Decision Insights Signals • August 21, 2026
Carahsoft will co-host its fourth annual 5G Summit with FedInsider in Reston, Virginia, on Aug. 25, 2026. The agenda covers Open RAN, ISAC for sensing applications, and using AI to extend 5G investments while preparing for 6G. Sessions, featured speakers, partner sponsors, and attendee CPE eligibility are listed.
Decision Insights Signals • August 20, 2026
In his latest blog, Baron Fung examines how DRAM inflation and rising HBM complexity are reshaping server economics and making memory efficiency critical to AI infrastructure growth through 2030. The post The Growing Memory Tax on AI Infrastructure appeared first on Dell'Oro Group.
Decision Insights Signals • August 20, 2026
Dell’Oro Group reports Optical Transport revenue rose 15% year-over-year, fueled by DCI growth, cloud provider demand, and North American AI infrastructure investment in 2Q 2026. Learn more: The post Optical Transport Equipment Market Grew 15 Percent Year-over-Year in 2Q 2026, According to Dell’Oro Group appeared first on Dell'Oro Group.
Decision Insights Signals • August 20, 2026
Cloudera said it enabled native GPU acceleration for Apache Spark 4.1 in Cloudera Data Engineering using NVIDIA CUDA-X and cuDF.
Decision Insights Signals • August 20, 2026
ABI Research said tracked industrial AI developments rose to more than 210 in 2025, led by partnerships, generative AI, and physical AI.
Decision Insights Signals • August 20, 2026
Carahsoft said it was named NightDragon’s 2025 Channel Partner of the Year, citing its role as Master Government Aggregator since 2021 and related event and engagement activities.
Decision Insights Signals • August 19, 2026
Cribl acquired Radiant Security AI SOC technology to autonomously triage, investigate, and resolve alerts using its telemetry platform.
Decision Insights Signals • August 19, 2026
RegScale and Microsoft collaborated to support FedRAMP readiness on Microsoft Azure using compliance automation and continuous controls monitoring.
Decision Insights Signals • August 19, 2026
Third Circuit held Pindrop qualifies as a financial institution under Illinois BIPA via GLBA, exempting it from BIPA consent requirements.
Decision Insights Signals • August 19, 2026
Cloudera launched Cloudera Anywhere Cloud for building and scaling production data and AI apps across multi-cloud and on-premises. It supports unified governance.
A synthesis of what changed across the vendors, projects and technologies tracked here. Published every two weeks. Subscribing creates a free Decision Insights account.