The CERT Coordination Center (CERT/CC) disclosed two unpatched vulnerabilities in Kaltura's mwEmbed player library. The flaws, CVE-2026-19912 and CVE-2026-19913, allow remote code execution and arbitrary file read, respectively. CERT/CC was unable to reach Kaltura to coordinate disclosure and has published a vulnerability note with mitigation recommendations.