Multiple critical security defects across enterprise payment processing software present severe operational risks to modern financial architectures. The underlying platform handles high-volume electronic payment routing and transaction workflows, making these vulnerabilities high-value targets for malicious actors. Software updates address a combined set of security flaws, with the highest CVSS base score reaching 9.9. These vulnerabilities allow remote attackers to bypass identity verification, execute arbitrary system commands, manipulate AI-driven operational tools, and read sensitive system files. Failure to remediate these weaknesses exposes critical financial infrastructure to potential transaction manipulation, unauthorized data exfiltration, and complete container compromise, although active exploitation in the wild has not yet been observed.
CVE-2026-18169: Carrying a critical CVSS score of 9.9, this vulnerability stems from improper path traversal handling via symbolic links. The weakness affects file management utilities within the underlying container deployment, allowing unauthenticated attackers to read arbitrary files from the file system. Exploitation enables severe data exposure, including the retrieval of sensitive system files, application credentials, and internal configuration parameters.[/subscribe_to_unlock_form]
Multiple critical security defects across enterprise payment processing software present severe operational risks to modern financial architectures. The underlying platform handles high-volume electronic payment routing and transaction workflows, making these vulnerabilities high-value targets for malicious actors. Software updates address a combined set of security flaws, with the highest CVSS base score reaching 9.9. These vulnerabilities allow remote attackers to bypass identity verification, execute arbitrary system commands, manipulate AI-driven operational tools, and read sensitive system files. Failure to remediate these weaknesses exposes critical financial infrastructure to potential transaction manipulation, unauthorized data exfiltration, and complete container compromise, although active exploitation in the wild has not yet been observed.
CVE-2026-18169: Carrying a critical CVSS score of 9.9, this vulnerability stems from improper path traversal handling via symbolic links. The weakness affects file management utilities within the underlying container deployment, allowing unauthenticated attackers to read arbitrary files from the file system. Exploitation enables severe data exposure, including the retrieval of sensitive system files, application credentials, and internal configuration parameters.[emaillocker id="1283"]
CVE-2026-18163: This critical flaw features a CVSS score of 9.8 and is caused by unsafe deserialization of untrusted data inputs. It resides within core Java communication interfaces used for payment processing components, permitting remote attackers to craft malicious serialized objects. Successful exploitation yields unauthenticated remote code execution with elevated application context privileges across the target platform.
CVE-2026-18162: Assigned a CVSS score of 9.8, this flaw involves improper control of code generation within the JavaScript runtime environment. The defect allows remote threat actors to inject arbitrary code into the system's function execution flow without pre-authentication. Exploitation risks include complete execution control, unauthorized platform manipulation, and persistent system compromise.
CVE-2026-17635:
Evaluating at a CVSS score of 9.1, this vulnerability arises from missing authentication mechanisms for critical function endpoints. The affected components fail to enforce access constraints, allowing remote attackers to invoke internal system routines without establishing a valid session. Exploitation can lead to unauthorized access, administrative interface control, and security control bypasses.
CVE-2026-17645: Rated at a CVSS score of 9.1, this security defect reflects improper privilege management within application operational roles. Lower-privileged actors can manipulate system calls to escalate permissions to administrative levels. Successful exploitation allows attackers to alter system logs, tamper with active transaction workflows, and override security controls.
CVE-2026-17644: Carrying a CVSS score of 8.8, this flaw involves hardcoded cryptographic secrets embedded within component sources. An attacker capable of discovering these fixed credentials can easily bypass mutual TLS authentication and cryptographic validation layers. Exploitation risk focuses on session hijacking, network communication interception, and unauthorized transaction authorization.
CVE-2026-17637: Assigned a CVSS score of 8.8, this issue is linked to untrusted deserialization weaknesses within secondary remote method modules. Attackers operating on adjacent networks can transmit tailored payloads to trigger object execution on target application servers. Exploitation allows arbitrary command execution and complete control over regional payment processing nodes.
CVE-2026-17643: With a CVSS score of 8.8, this flaw involves cleartext storage of sensitive information in administrative memory stores. Remote actors with network visibility can extract cleartext credentials and authorization tokens from active system memory streams. Exploitation provides persistent credentials necessary to perform lateral movement and unauthorized operator-level payment modifications.
Prompt implementation of vendor-supplied software upgrades remains essential to secure financial transaction routing engines against potential disruption or integrity failure. Applying official security patches ensures all deserialization flaws, improper access controls, and path traversal vectors are fully eradicated from production clusters. In addition, isolating container management interfaces and restricting network traffic to internal payment networks prevents unauthorized remote access.
The following reports contain further technical details:
[/emaillocker]