#commandinjection — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #commandinjection, aggregated by home.social.
-
Digi DAL OS vulnerability CVE-2026-75937 (CVSS 9.4) lets attackers run root commands on Digi Accelerated Linux devices. Patch now.
#Digi #DALOS #CVE202675937 #CommandInjection #IoTSecurity #OTSecurity #Vulnerability
https://securityonline.info/digi-dal-os-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
Digi DAL OS vulnerability CVE-2026-75937 (CVSS 9.4) lets attackers run root commands on Digi Accelerated Linux devices. Patch now.
#Digi #DALOS #CVE202675937 #CommandInjection #IoTSecurity #OTSecurity #Vulnerability
https://securityonline.info/digi-dal-os-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
Digi DAL OS vulnerability CVE-2026-75937 (CVSS 9.4) lets attackers run root commands on Digi Accelerated Linux devices. Patch now.
#Digi #DALOS #CVE202675937 #CommandInjection #IoTSecurity #OTSecurity #Vulnerability
https://securityonline.info/digi-dal-os-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
-
Attackers exploit CVE-2026-100382, a CVSS 10 unauthenticated MediaWiki RCE in External Data. PoC is public. Upgrade to 3.7 now.
#MediaWiki #ExternalData #CVE2026100382 #RCE #CommandInjection #ExploitedInTheWild #PoC
-
Attackers exploit CVE-2026-100382, a CVSS 10 unauthenticated MediaWiki RCE in External Data. PoC is public. Upgrade to 3.7 now.
#MediaWiki #ExternalData #CVE2026100382 #RCE #CommandInjection #ExploitedInTheWild #PoC
-
Attackers exploit CVE-2026-100382, a CVSS 10 unauthenticated MediaWiki RCE in External Data. PoC is public. Upgrade to 3.7 now.
#MediaWiki #ExternalData #CVE2026100382 #RCE #CommandInjection #ExploitedInTheWild #PoC
-
Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shells, root access, and key theft.
#Zimbra #CVE202673570 #CommandInjection #WebShell #EmailSecurity #MailServer #Microsoft #CyberSecurity
https://securityonline.info/zimbra-cve-2026-73570-2/?utm_source=mastodon&utm_medium=jetpack_social
-
Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shells, root access, and key theft.
#Zimbra #CVE202673570 #CommandInjection #WebShell #EmailSecurity #MailServer #Microsoft #CyberSecurity
https://securityonline.info/zimbra-cve-2026-73570-2/?utm_source=mastodon&utm_medium=jetpack_social
-
Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shells, root access, and key theft.
#Zimbra #CVE202673570 #CommandInjection #WebShell #EmailSecurity #MailServer #Microsoft #CyberSecurity
https://securityonline.info/zimbra-cve-2026-73570-2/?utm_source=mastodon&utm_medium=jetpack_social
-
Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shells, root access, and key theft.
#Zimbra #CVE202673570 #CommandInjection #WebShell #EmailSecurity #MailServer #Microsoft #CyberSecurity
https://securityonline.info/zimbra-cve-2026-73570-2/?utm_source=mastodon&utm_medium=jetpack_social
-
CISA flagged CVE-2026-22755, a command injection in VIVOTEK's upload_map.cgi allowing unauthenticated OS command execution. Dozens of camera models are affected, creating persistence and lateral movement risk in enterprise and critical infrastructure networks. #Vivotek #CommandInjection #NetworkSecurity
https://cyberworldops.eu/en/vivotek-camera-flaw-exposes-dozens-of-models-to-unauthenticated
-
CISA flagged CVE-2026-22755, a command injection in VIVOTEK's upload_map.cgi allowing unauthenticated OS command execution. Dozens of camera models are affected, creating persistence and lateral movement risk in enterprise and critical infrastructure networks. #Vivotek #CommandInjection #NetworkSecurity
https://cyberworldops.eu/en/vivotek-camera-flaw-exposes-dozens-of-models-to-unauthenticated
-
CISA flagged CVE-2026-22755, a command injection in VIVOTEK's upload_map.cgi allowing unauthenticated OS command execution. Dozens of camera models are affected, creating persistence and lateral movement risk in enterprise and critical infrastructure networks. #Vivotek #CommandInjection #NetworkSecurity
https://cyberworldops.eu/en/vivotek-camera-flaw-exposes-dozens-of-models-to-unauthenticated
-
CVE-2026-88771 is a Citrix NetScaler command injection exploited in the wild. Details and a PoC are public. Patch NetScaler to 14.1-73.37 now.
#Citrix #NetScaler #CVE202688771 #CommandInjection #ZeroDay #ExploitedInTheWild #PoC #PatchNow
-
CVE-2026-88771 is a Citrix NetScaler command injection exploited in the wild. Details and a PoC are public. Patch NetScaler to 14.1-73.37 now.
#Citrix #NetScaler #CVE202688771 #CommandInjection #ZeroDay #ExploitedInTheWild #PoC #PatchNow
-
CVE-2026-88771 is a Citrix NetScaler command injection exploited in the wild. Details and a PoC are public. Patch NetScaler to 14.1-73.37 now.
#Citrix #NetScaler #CVE202688771 #CommandInjection #ZeroDay #ExploitedInTheWild #PoC #PatchNow
-
A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now.
#Dokploy #CommandInjection #CVE202672878 #Cybersecurity #PaaS
-
A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now.
#Dokploy #CommandInjection #CVE202672878 #Cybersecurity #PaaS
-
A critical Dokploy OS command injection flaw (CVE-2026-72878) exposes servers to root takeover via backups. Patch this Dokploy OS command injection now.
#Dokploy #CommandInjection #CVE202672878 #Cybersecurity #PaaS
-
Details and PoC for CVE-2026-84372 are publicly disclosed. This Predis command injection flaw via CRLF smuggling allows complete cluster compromise.
#Predis #CommandInjection #CVE202684372 #Cybersecurity #Vulnerability
-
Details and PoC for CVE-2026-84372 are publicly disclosed. This Predis command injection flaw via CRLF smuggling allows complete cluster compromise.
#Predis #CommandInjection #CVE202684372 #Cybersecurity #Vulnerability
-
Details and PoC for CVE-2026-84372 are publicly disclosed. This Predis command injection flaw via CRLF smuggling allows complete cluster compromise.
#Predis #CommandInjection #CVE202684372 #Cybersecurity #Vulnerability
-
Advantech WISE-6610-NB (v1.2.1_20251110) faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-79698). Remote exploit is public. Patch by upgrading to 1.2.4_20260821. https://radar.offseq.com/threat/cve-2026-79698-command-injection-in-advantech-wise-6610-nb-dbc89cbd83837238 #OffSeq #ICS #Vuln #CommandInjection
-
Advantech WISE-6610-NB (v1.2.1_20251110) faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-79698). Remote exploit is public. Patch by upgrading to 1.2.4_20260821. https://radar.offseq.com/threat/cve-2026-79698-command-injection-in-advantech-wise-6610-nb-dbc89cbd83837238 #OffSeq #ICS #Vuln #CommandInjection
-
Advantech WISE-6610-NB (v1.2.1_20251110) faces a CRITICAL (CVSS 9.4) command injection flaw (CVE-2026-79698). Remote exploit is public. Patch by upgrading to 1.2.4_20260821. https://radar.offseq.com/threat/cve-2026-79698-command-injection-in-advantech-wise-6610-nb-dbc89cbd83837238 #OffSeq #ICS #Vuln #CommandInjection
-
TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities enable code execution.
#TeamViewer #CommandInjection #CVE202619042 #PathTraversal #RCE #InfoSec
-
TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities enable code execution.
#TeamViewer #CommandInjection #CVE202619042 #PathTraversal #RCE #InfoSec
-
TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities enable code execution.
#TeamViewer #CommandInjection #CVE202619042 #PathTraversal #RCE #InfoSec
-
Dell patched 5 Cloud Disaster Recovery flaws. The top bug, CVE-2026-70419 (CVSS 9.1), allows command execution. Update to CDR 20.3 now.
#Dell #CyberSecurity #CVE202670419 #CommandInjection #Infosec
-
Dell patched 5 Cloud Disaster Recovery flaws. The top bug, CVE-2026-70419 (CVSS 9.1), allows command execution. Update to CDR 20.3 now.
#Dell #CyberSecurity #CVE202670419 #CommandInjection #Infosec
-
Dell patched 5 Cloud Disaster Recovery flaws. The top bug, CVE-2026-70419 (CVSS 9.1), allows command execution. Update to CDR 20.3 now.
#Dell #CyberSecurity #CVE202670419 #CommandInjection #Infosec
-
Ubiquiti patched 22 UniFi flaws. Three hit CVSS 10.0, including command injection CVE-2026-77537. Update UniFi Protect, OS, and Talk now.
#Ubiquiti #UniFi #CyberSecurity #CommandInjection #CVE202677537
-
Ubiquiti patched 22 UniFi flaws. Three hit CVSS 10.0, including command injection CVE-2026-77537. Update UniFi Protect, OS, and Talk now.
#Ubiquiti #UniFi #CyberSecurity #CommandInjection #CVE202677537
-
Ubiquiti patched 22 UniFi flaws. Three hit CVSS 10.0, including command injection CVE-2026-77537. Update UniFi Protect, OS, and Talk now.
#Ubiquiti #UniFi #CyberSecurity #CommandInjection #CVE202677537
-
Ubiquiti patched 22 UniFi flaws. Three hit CVSS 10.0, including command injection CVE-2026-77537. Update UniFi Protect, OS, and Talk now.
#Ubiquiti #UniFi #CyberSecurity #CommandInjection #CVE202677537
-
274 Zimbra Servers Hacked as CISA Patch Deadline Expires
At least 274 internet-facing Zimbra instances confirmed compromised via CVE-2026-73570 as CISA three-day remediation deadline for federal agencies expires.
https://pulseofnations.lol/274-zimbra-servers-hacked/
#CISA #CommandInjection #Cve202673570 #EmailSecurity #Patch #Vulnerability #Zimbra
-
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
-
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
-
TP-Link patched an unauthenticated OS command injection flaw (CVE-2026-9254) and other risks like CVE-2026-16348 and CVE-2026-78541 in Archer routers.
-
TP-Link patches CVE-2026-75616, an Archer C20 command injection flaw that can lead to full device compromise. Update firmware now.
#TPLink #ArcherC20 #CommandInjection #CVE #RouterSecurity #InfoSec #PatchNow
-
TP-Link patches CVE-2026-75616, an Archer C20 command injection flaw that can lead to full device compromise. Update firmware now.
#TPLink #ArcherC20 #CommandInjection #CVE #RouterSecurity #InfoSec #PatchNow
-
TP-Link patches CVE-2026-75616, an Archer C20 command injection flaw that can lead to full device compromise. Update firmware now.
#TPLink #ArcherC20 #CommandInjection #CVE #RouterSecurity #InfoSec #PatchNow
-
CISA Mandates Emergency Patching for Exploited Zimbra Flaw
A critical Zimbra flaw, CVE-2026-73570, allows hackers to inject malicious code, and the CISA is mandating emergency patching to prevent devastating attacks - don't wait, get protected now!
#Cve202673570 #Zimbra #CommandInjection #RemoteCodeExecution #Snmp
-
CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. https://radar.offseq.com/threat/cve-2026-77683-command-injection-in-comfast-cf-n1-s-c0a0594c5aac367d #OffSeq #CVE202677683 #IoTSecurity #CommandInjection
-
CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. https://radar.offseq.com/threat/cve-2026-77683-command-injection-in-comfast-cf-n1-s-c0a0594c5aac367d #OffSeq #CVE202677683 #IoTSecurity #CommandInjection
-
CVE-2026-77683: CRITICAL command injection in Comfast CF-N1-S (2.6.0.1) via /cgi-bin/mbox-config timestr parameter. Public exploit available, remote exploitation possible. Patch unavailable. https://radar.offseq.com/threat/cve-2026-77683-command-injection-in-comfast-cf-n1-s-c0a0594c5aac367d #OffSeq #CVE202677683 #IoTSecurity #CommandInjection
-
CVE-2026-19586 (CVSS 9.3) is a pre-authentication OS command injection flaw in Omada gateways. TP-Link has released fixed firmware.
#Omada #TPLink #CVE202619586 #CommandInjection #OpenVPN #NetworkSecurity
-
CVE-2026-19586 (CVSS 9.3) is a pre-authentication OS command injection flaw in Omada gateways. TP-Link has released fixed firmware.
#Omada #TPLink #CVE202619586 #CommandInjection #OpenVPN #NetworkSecurity
-
CVE-2026-19586 (CVSS 9.3) is a pre-authentication OS command injection flaw in Omada gateways. TP-Link has released fixed firmware.
#Omada #TPLink #CVE202619586 #CommandInjection #OpenVPN #NetworkSecurity
-
D-Link fixes 15 flaws in the DWR-M961 router, including D-Link router command injection and buffer overflow bugs like CVE-2026-71958. Update firmware now.
#DLink #DWRM961 #CommandInjection #BufferOverflow #RouterSecurity #CVE #InfoSec #CyberSecurity
-
D-Link fixes 15 flaws in the DWR-M961 router, including D-Link router command injection and buffer overflow bugs like CVE-2026-71958. Update firmware now.
#DLink #DWRM961 #CommandInjection #BufferOverflow #RouterSecurity #CVE #InfoSec #CyberSecurity
-
A single public GitHub issue could trigger commands inside Snowflake’s GitHub Actions environment—and expose a Jira API token.
Wiz confirmed the flaw during an authorized security test, while Snowflake says it found no signs of unauthorized access.
How did an ordinary issue become a potential entry point, and what could the token actually reveal?
https://en.hacks.gr/pos-i-wiz-anakalypse-keno-asfaleias-sto-github-tis-snowflake/
#Cybersecurity #CommandInjection #GitHubActions #Snowflake #CredentialExposure
-
TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection.
#TPLink #RouterSecurity #CVE #AuthBypass #CommandInjection #IoT #Cybersecurity
-
TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection.
#TPLink #RouterSecurity #CVE #AuthBypass #CommandInjection #IoT #Cybersecurity
-
TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection.
#TPLink #RouterSecurity #CVE #AuthBypass #CommandInjection #IoT #Cybersecurity
-
PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.
-
PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.
-
CVE-2026-9044 is a command injection flaw in TP-Link Archer AXE75 OpenVPN, CVSS 8.5. Update to firmware 1.5.6 Build 20260623 now.
#TPLink #CVE20269044 #CommandInjection #OpenVPN #RouterSecurity #CyberSecurity
-
CVE-2026-9044 is a command injection flaw in TP-Link Archer AXE75 OpenVPN, CVSS 8.5. Update to firmware 1.5.6 Build 20260623 now.
#TPLink #CVE20269044 #CommandInjection #OpenVPN #RouterSecurity #CyberSecurity
-
Mitel patched a MiCollab command injection flaw rated CVSS 9.8 and an OpenScape UC vulnerability rated CVSS 8.0. No CVE IDs are assigned yet.