Patch Now: Android RCE, cPanel Auth Bypass, MOVEit, Copy Fail LPE, and Weaver E-cology — May 2026

Emergency patch advisory covering 5 critical vulnerabilities requiring immediate patching across enterprise servers.

Security patches and vulnerability management
📌
Security Roundup Series: Week of May 7, 2026 • 4 min read deep dive

This article is part of our Week of May 7, 2026 Security Roundup.

Alongside the major stories this week, five high-severity vulnerabilities are either actively exploited or carry significant exploitation risk. Here is a focused breakdown with remediation guidance for each.

Android CVE-2026-0073 — Critical RCE, No User Interaction Required

Google patched a critical remote code execution vulnerability in Android's System component in the May 2026 security bulletin. CVE-2026-0073 can be exploited remotely without any user interaction — no click, no tap, no attachment to open. The vulnerability affects a wide range of Android versions. Apply the May 2026 security update immediately on all managed Android devices. If your organization runs an Android patch management program, treat this as Priority 1.

cPanel CVE-2026-41940 — Auth Bypass, Actively Exploited

A critical authentication vulnerability in the Captive Portal service of cPanel is being actively exploited in the wild. If you manage web hosting infrastructure running cPanel, this needs to be patched today — active exploitation means attackers are already scanning for and hitting vulnerable instances. Update to the latest cPanel version and verify that the patch has been applied. Check your access logs for unexpected authentication bypass attempts.

MOVEit Automation — Critical Authentication Bypass

Progress Software patched a critical authentication bypass in MOVEit Automation. Given MOVEit's history — the 2023 zero-day exploitation affected thousands of organizations and resulted in mass data theft by the Cl0p ransomware group — any MOVEit vulnerability should be treated as urgent regardless of your normal patch cadence. Apply the patch immediately and audit recent file transfer activity for anomalies.

Copy Fail CVE-2026-31431 — Linux LPE, Actively Exploited

CVE-2026-31431, dubbed Copy Fail, is a local privilege escalation vulnerability on Linux being actively exploited to gain root access. LPE vulnerabilities are particularly dangerous in shared hosting environments, container breakout scenarios, and any context where an attacker has already gained low-privilege code execution. Check your kernel version and apply the available patch.

# Check your kernel version
uname -r

# On Debian/Ubuntu — apply security updates
sudo apt update && sudo apt upgrade

# On RHEL/CentOS/AlmaLinux
sudo dnf update kernel

# Verify CVE-2026-31431 patch is applied
sudo rpm -q --changelog kernel | grep -i 'CVE-2026-31431'
# or check your distro's security advisory tracker

Weaver E-cology CVE-2026-22679 — Unauthenticated RCE, Exploited Since March

CVE-2026-22679 in Weaver E-cology allows unauthenticated remote command execution through an exposed debug API. Active exploitation has been observed since March 2026 — meaning this vulnerability has been actively attacked for over two months. If your organization runs Weaver E-cology for enterprise workflow management, assume you may already be compromised if unpatched, and prioritize both patching and incident investigation.

Mandiant's M-Trends 2026 report provides the sobering context for all of the above: 28.3% of CVEs are now being exploited within 24 hours of public disclosure. Mean time from patch release to active exploitation is now 44 days — down from 700 days in 2020. The window to patch before active exploitation begins is measured in hours to days, not weeks. Treat every critical and high-severity patch as urgent by default.


References: Google Android security bulletin | SecurityWeek cPanel coverage | Progress MOVEit advisory | Mandiant M-Trends 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther