Back to the blog
vulnerabilityFebruary 8, 2026 5 min read

Vulnerability Roundup: Critical SQLi and Remote Exploits (February 2026)

A review of recent critical vulnerabilities, including SQL injection flaws and remote code execution risks, that highlight the ongoing need for robust, zero-knowledge security architectures.

By SecureIDsafe Threat Team · SecureIDsafe Threat Research#data-exposure

Recent security disclosures have highlighted a persistent trend: web applications and infrastructure components remain highly susceptible to remote exploitation. From SQL injection flaws in content management systems to memory corruption in network infrastructure, these vulnerabilities provide clear pathways for attackers to compromise sensitive data. Understanding these risks is the first step toward implementing more resilient security models.

What happened

PHP Melody (CVE-2021-47915)

Researchers identified a remote SQL injection vulnerability in the video edit module of PHP Melody version 3.0. By manipulating the 'vid' parameter, an authenticated attacker can execute arbitrary database queries, potentially leading to full database compromise [https://nvd.nist.gov/vuln/detail/CVE-2021-47915].

EDITOR: Add a brief explanation of how an attacker might chain this SQLi to escalate privileges or dump user tables.

Simple CMS (CVE-2021-47918)

Simple CMS 2.1 contains a remote SQL injection vulnerability within its users module. Attackers can exploit unvalidated input parameters in the admin.php file to inject malicious SQL commands, compromising the underlying database management system [https://nvd.nist.gov/vuln/detail/CVE-2021-47918].

Free5GC (CVE-2026-1739)

A null pointer dereference vulnerability was discovered in Free5GC pcf up to 1.4.1. The flaw exists in the HandleCreateSmPolicyRequest function within the smpolicy.go file. This remote exploit allows attackers to trigger a crash or potentially manipulate system state [https://nvd.nist.gov/vuln/detail/CVE-2026-1739].

EFM ipTIME A8004T (CVE-2026-1742)

Version 14.18.2 of the EFM ipTIME A8004T router is affected by an unrestricted file upload vulnerability in the VPN Service component. By targeting the commit_vpncli_file_upload function in timepro.cgi, remote attackers can upload arbitrary files to the device [https://nvd.nist.gov/vuln/detail/CVE-2026-1742].

JeecgBoot (CVE-2026-1746)

JeecgBoot 3.9.0 contains a remote SQL injection vulnerability in the Online Report API. The flaw is triggered by manipulating the 'keyword' argument in the loadDictItemByKeyword function, allowing unauthorized database access [https://nvd.nist.gov/vuln/detail/CVE-2026-1746].

Why this matters

These vulnerabilities demonstrate that even standard administrative modules and infrastructure components can serve as entry points for data exfiltration. When an application is compromised via SQL injection or remote file upload, the attacker often gains the same level of access as the application itself, putting all stored user data at risk of exposure.

How zero-knowledge changes this

SecureIDsafe’s architecture is designed to neutralize the impact of these types of breaches. Because we utilize AES-256 client-side encryption, the data stored on our servers is never readable by the application or the database management system. Even if an attacker successfully exploits an SQL injection or gains administrative access to the server, they would only encounter encrypted ciphertext. Because the device-derived keys are never held by the provider and recovery is managed through a non-bypassable 24-word BIP-39 seed, the attacker lacks the necessary keys to decrypt the stolen data, rendering the breach effectively useless.

Editor's checklist

  • Add a brief explanation of how an attacker might chain the PHP Melody SQLi to escalate privileges.
  • Verify if there are any public proof-of-concept scripts for the JeecgBoot vulnerability to include as a reference.
  • Add a screenshot or diagram illustrating the difference between server-side storage and SecureIDsafe's client-side encrypted storage.
  • Confirm the current patch status for the Free5GC vulnerability to ensure the advice is up to date.
vulnerabilitycvesqlizero-knowledgesecurity

Build your Fortress of Sovereignty.

Single users, business teams and enterprise perimeters — the same non-bypassable security, scaled to your vault.