#vuln — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vuln, aggregated by home.social.
-
mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. https://radar.offseq.com/threat/cve-2026-17457-information-disclosure-in-mf-yang-openclaw-cn-1d4fae9414fd0132 #OffSeq #Vuln #InfoSec #CVE202617457
-
SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. https://radar.offseq.com/threat/cve-2026-17458-server-side-request-forgery-in-mf-yang-openclaw-cn-a8d78509307a6c7f #OffSeq #SSRF #Vuln #mfyang
-
CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. https://radar.offseq.com/threat/cve-2026-16766-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-9e7c09567b0712f8 #OffSeq #infosec #perl #vuln
-
CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. https://radar.offseq.com/threat/cve-2026-16766-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-9e7c09567b0712f8 #OffSeq #infosec #perl #vuln
-
Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: https://radar.offseq.com/threat/cve-2026-57106-cwe-918-server-side-request-forgery-ssrf-in-microsoft-microsoft-purview-data-governance-0983080847f54f67 #OffSeq #Vuln #SSRF #Microsoft #CyberSec
-
CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: https://radar.offseq.com/threat/cve-2026-48021-cwe-295-improper-certificate-validation-in-med-united-epa4all-26e8e441c1a877ee #OffSeq #HealthcareSecurity #Vuln #CVE202648021
-
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
-
CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: https://radar.offseq.com/threat/cve-2026-56191-cwe-287-improper-authentication-in-microsoft-microsoft-exchange-online-2fb5560625ca8222 #OffSeq #CVE202656191 #ExchangeOnline #Vuln
-
CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: https://radar.offseq.com/threat/cve-2026-56191-cwe-287-improper-authentication-in-microsoft-microsoft-exchange-online-2fb5560625ca8222 #OffSeq #CVE202656191 #ExchangeOnline #Vuln
-
CVE-2026-42933: CRITICAL unintended proxy vuln (CVSS 10) in Pronetiqs Panduit Intravue ≤3.2.1a14 lets attackers bypass OT segmentation. No patch yet — restrict access & monitor vendor. https://radar.offseq.com/threat/cve-2026-42933-cwe-441-unintended-proxy-or-intermediary-confused-deputy-in-pronetiqs-panduit-intravue-95925181c2d7dbb4 #OffSeq #OTSecurity #Vuln #CVE202642933
-
CVE-2026-65907: CRITICAL RCE in JetBrains TeamCity (CVSS 9.1). Affects <2026.1.2, <2025.11.6. Exploitable via Git VCS roots — no patch yet. Restrict access, minimize Git user privileges. More info: https://radar.offseq.com/threat/cve-2026-65907-cwe-94-in-jetbrains-teamcity-0b7d157127b512e7 #OffSeq #TeamCity #Vuln #RCE
-
CRITICAL: CVE-2026-65471 enables unauthenticated CSRF attacks in Avada Core <=5.15.6. No mitigation yet — review your deployment status and monitor for fixes. https://radar.offseq.com/threat/cve-2026-65471-cwe-352-cross-site-request-forgery-csrf-in-avada-studio-avada-core-f1e19172d275ec0b #OffSeq #CSRF #AvadaCore #Vuln
-
CVE-2026-46738: Dell PowerProtect Data Manager <20.2.0.0 faces a CRITICAL REST API input validation vuln. High privileged remote attackers can escalate privileges. Restrict API access & monitor privileged accounts. https://radar.offseq.com/threat/dell-powerprotect-data-manager-versions-prior-to-20200-contains-an-improper-input-validation-f763e60bc08bcc57 #OffSeq #Dell #CVE202646738 #Vuln
-
CVE-2026-65603: HIGH severity privilege escalation in Grav Login plugin (<=3.8.11). Low-priv users can gain super-admin & RCE. Patch to v3.8.12 ASAP! https://radar.offseq.com/threat/cve-2026-65603-improper-privilege-management-in-getgrav-grav-12319d7ebec99910 #OffSeq #GravCMS #Vuln #PrivilegeEscalation
-
CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. https://radar.offseq.com/threat/cve-2026-63048-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-joomlackfr-page-builder-ck-3921dbf365864886 #OffSeq #Joomla #RCE #Vuln
-
Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. https://radar.offseq.com/threat/gitea-public-only-repository-tokens-can-update-private-pr-head-branches-cve-2026-58443-d058444d84b9595a #OffSeq #Gitea #Vuln #CVE202658443
-
CVE-2026-62549 (CRITICAL, CVSS 9.6) in Oracle HRMS (UK) 12.2.3 – 12.2.15 lets low-priv attackers compromise critical data & impact other Oracle apps. Patch status unclear — check https://radar.offseq.com/threat/cve-2026-62549-easily-exploitable-vulnerability-allows-low-privileged-attacker-with-network-access-via-2a35d285e3bf086c & restrict network access. #OffSeq #Oracle #CVE2026_62549 #Vuln
-
CVE-2026-16412: CRITICAL memory safety issues in Firefox ESR 140.12 & 152 allow code execution, sandbox escape, info disclosure. Public exploits exist, but no in-the-wild attacks. Patch to 153/ESR 140.13. https://radar.offseq.com/threat/cve-2026-16412-vulnerability-in-mozilla-firefox-4b126d3842b74077 #OffSeq #Firefox #Vuln #Security
-
Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). https://radar.offseq.com/threat/critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware-gang-32a4cdf9eafc03de #OffSeq #PANOS #Ransomware #Vuln
-
Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. https://radar.offseq.com/threat/zimbra-update-patches-critical-vulnerabilities-8b90415ad76d6649 #OffSeq #Zimbra #InfoSec #Vuln
-
FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: https://radar.offseq.com/threat/cve-2026-53595-cwe-178-improper-handling-of-case-sensitivity-in-freescout-help-desk-freescout-3a27bed6e9e122c1 #OffSeq #CVE202653595 #infosec #vuln
-
CVE-2026-15901: CRITICAL use-after-free in Chrome <150.0.7871.128 allows remote heap corruption via crafted HTML. No active exploits, patch status unclear — monitor advisories. https://radar.offseq.com/threat/cve-2026-15901-use-after-free-in-google-chrome-8afb124627400a01 #OffSeq #Chrome #Vuln #InfoSec
-
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
-
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. https://radar.offseq.com/threat/cve-2026-53994-heap-based-buffer-overflow-in-proftpd-project-proftpd-fe4dcd4d99eab6eb #OffSeq #ProFTPD #infosec #vuln
-
CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. https://radar.offseq.com/threat/cve-2026-12228-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-9a447d2fa5ce8bc8 #OffSeq #XSS #Vuln #InfoSec
-
7-Zip patched a CRITICAL RCE vulnerability — malicious archive files could allow attackers to execute code and fully compromise systems. Update to v26.02 ASAP. No CVE assigned. Full details: https://radar.offseq.com/threat/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives-0fd30e36bd704721 #OffSeq #7zip #RCE #Vuln
-
Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. https://radar.offseq.com/threat/critical-vulnerabilities-patched-with-fresh-chrome-e977806d68193e89 #OffSeq #Vuln #PatchNow #BrowserSecurity
-
CVE-2026-14570: HIGH severity in TIMLEGGE Crypt::DSA (<1.22) — insufficiently random values in DSA signing allow attackers to recover private keys using lattice attacks. Replace all affected keys and upgrade to 1.22+. https://radar.offseq.com/threat/cve-2026-14570-cwe-330-use-of-insufficiently-rando-539cd2ae349f5a7a #OffSeq #Vuln #Perl #Crypto
-
CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. https://radar.offseq.com/threat/cve-2026-13601-protection-mechanism-failure-in-red-844c9044ecdb0d62 #OffSeq #Linux #Vuln #RedHat
-
CVE-2026-13491: MEDIUM severity DoS flaw in 78 xiaozhi-esp32 (v2.2.0 – 2.2.6) via MQTT Goodbye Handler. Exploitable remotely with public exploit. Patch via commit e182471f8c5a. https://radar.offseq.com/threat/cve-2026-13491-denial-of-service-in-78-xiaozhi-esp-7a05af4bbbaaa50e #OffSeq #Vuln #IoT #DoS
-
CVE-2026-53753: CRITICAL code injection in unclecode crawl4ai (<0.8.7). Unauthenticated RCE via /crawl POST request due to insufficient AST validation. Patch to 0.8.7 ASAP. https://radar.offseq.com/threat/cve-2026-53753-cwe-94-improper-control-of-generati-9d9fc678b9a0404e #OffSeq #CVE202653753 #infosec #vuln
-
🔥🔥🔥 Cuevasanta, by Vuln
https://v-u-l-n.bandcamp.com/track/cuevasanta
#NowPlaying #Musique #Vuln -
🔒 CRITICAL: CVE-2026-12441 in Chrome <149.0.7827.155 on Linux — use-after-free in File Input. Remote attacker can trigger heap corruption via crafted HTML. Update Chrome ASAP! https://radar.offseq.com/threat/cve-2026-12441-use-after-free-in-google-chrome-643def61 #OffSeq #Chrome #Linux #Vuln
-
Nice, #Bumsrakete works on a #FreeBSD 15.0 system.
TL;DR page cache #vuln in the #kernel, exploitable within seconds, privesc from normal user to #root
17/10 can recommend ⭐🌟
-
🔒 CVE-2026-52726 (HIGH): jelmer dulwich <1.2.5 allows path traversal via malicious submodules — attackers can drop executables in .git/hooks for code execution. Upgrade to 1.2.5+ ASAP. https://radar.offseq.com/threat/cve-2026-52726-cwe-22-improper-limitation-of-a-pat-e09b90e1 #OffSeq #Infosec #Vuln #Python #Git
-
🚨 CRITICAL: CVE-2026-11499 in Tenda HG7HG9/HG10 (firmware 300001138_en_xpon) allows remote stack-based buffer overflow via blkDomain in formDOMAINBLK. No patch yet — restrict access and monitor traffic. https://radar.offseq.com/threat/cve-2026-11499-stack-based-buffer-overflow-in-tend-ca49c238 #OffSeq #Vuln #IoT #CyberSecurity
-
🚨 CRITICAL: Joomla Content Editor (JCE) vuln (CVE-2026-48907) allows unauthenticated PHP upload & exec (v1.0.0 – 2.9.99.4). No patch yet — restrict or disable JCE & monitor systems. Details: https://radar.offseq.com/threat/cve-2026-48907-cwe-284-improper-access-control-in--ff15bdc3 #OffSeq #Joomla #Vuln #InfoSec
-
⚠️ CVE-2026-10187 CRITICAL: Totolink N300RH (6.1c.1353_B20190305) is exposed to a remote stack-based buffer overflow in setWiFiBasicConfig. Exploit is public, no patch yet — restrict Web Management access! https://radar.offseq.com/threat/cve-2026-10187-stack-based-buffer-overflow-in-toto-571e12d5 #OffSeq #IoT #Infosec #Vuln
-
⚠️ CRITICAL: Actively exploited privilege escalation in LiteSpeed cPanel plugin (CVE-2026-48172) enables remote root access via lsws.redisAble. Patch plugin v2.3 – v2.4.4 now! CISA mandates 4-day deadline for U.S. agencies. https://radar.offseq.com/threat/cisa-gives-feds-4-days-to-patch-actively-exploited-ebc57663 #OffSeq #vuln #patchnow
-
⚠️ HIGH severity: CVE-2026-48962 in PMQS IO::Compress (Perl <2.220) enables eval injection via crafted glob strings. Arbitrary Perl code may execute with process privileges. Restrict untrusted input & monitor for patches. https://radar.offseq.com/threat/cve-2026-48962-cwe-95-improper-neutralization-of-d-a4f0eb17 #OffSeq #Vuln #Perl #Infosec
-
🚩 CVE-2026-42496: HIGH severity vuln in BINGOS Archive::Tar (<3.08). Symlinks in tar archives can escape extraction dir, risking unauthorized file access. No patch yet — avoid untrusted archives! https://radar.offseq.com/threat/cve-2026-42496-cwe-59-improper-link-resolution-bef-ae924259 #OffSeq #vuln #Perl #infosec
-
🚨 CRITICAL: CVE-2026-23652 in Microsoft Power Pages enables remote, unauthenticated code execution (command injection, CVSS 10). Patch immediately to prevent full system compromise! Details & fix: https://radar.offseq.com/threat/cve-2026-23652-cwe-77-improper-neutralization-of-s-b875b212 #OffSeq #Cybersecurity #Microsoft #Vuln
-
🚨 CRITICAL: CVE-2026-41090 in Microsoft 365 Copilot for iOS enables remote command injection (CVSS 9.3). Microsoft has patched server-side — verify your service is up to date. More info: https://radar.offseq.com/threat/cve-2026-41090-cwe-77-improper-neutralization-of-s-c8e983a4 #OffSeq #Microsoft #Vuln #InfoSec
-
🔥 CVE-2026-33278: Critical use-after-free in NLnet Labs Unbound (1.19.1 – 1.25.0). DNSSEC validator flaw can lead to DoS or RCE if attacker controls DNS zone. Patch: upgrade to 1.25.1. https://radar.offseq.com/threat/cve-2026-33278-cwe-416-use-after-free-in-nlnet-lab-c0de645d #OffSeq #DNSSEC #Vuln #Infosec
-
@angst_ridden Oh, I am full on (30 year career in infosec and infra), #terraform , #ansible, #argocd, #gha (unfortunately because I hate it), #python and #golang Staff CloudOps Engineer.
My OP was just me bitching about it.
My cool task today is setting up a #capev2 server for #vuln and #mal testing.
-
🚨 CVE-2026-8507 (HIGH): Out-of-bounds write in Crypt::OpenSSL::PKCS12 <=1.94 for Perl. Parsing PKCS12 files with >=1GiB OCTET/BIT STRING may lead to RCE. Patch available for cloud-hosted service — update ASAP. No known exploits. https://radar.offseq.com/threat/cve-2026-8507-cwe-787-out-of-bounds-write-in-jonas-652bf5a8 #OffSeq #Vuln #Perl
-
Rien ne dit “bon week-end” comme trois CVE cPanel annoncées un vendredi, avec les détails techniques livrés pile au moment du patch -->c’est-à-dire à 18h, l’heure sacrée de l’apéro.
Santé aux admins qui vont lancer /scripts/upcp avec une main sur le clavier et l’autre sur le verre.
👇
" To help protect customers prior to patch availability, technical details about vulnerabilities will be released alongside the patches. Full technical details will be published on our support page at the same time the patch is released. The CVE IDs are CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203.Patch & Affected Versions
The patch will be available on May 08 at 12:00pm EST and will be distributed through the standard cPanel automatic update process and through the manual update process. We strongly recommend performing a manual update with /scripts/upcp once the patch is made available. "
👇
https://www.reddit.com/r/cpanel/comments/1t6wf5n/cpanel_whm_security_update_cve202629201/ -
🌐 CVE-2026-42368 | CRITICAL privilege escalation in GeoVision GV-LPC2011/LPC2211 v1.10. Remote attackers can gain full control via crafted HTTP requests. No patch — restrict web interface access & monitor traffic. Details: https://radar.offseq.com/threat/cve-2026-42368-cwe-266-incorrect-privilege-assignm-b84e399c #OffSeq #Vuln #IoT #CyberSecurity
-
🚨 CVE-2026-39804 (HIGH): mtrudel bandit <1.11.0 allows remote DoS via memory exhaustion if WebSocket permessage-deflate is enabled. Disable compression to mitigate. Affects only non-default configs. Details: https://radar.offseq.com/threat/cve-2026-39804-cwe-770-allocation-of-resources-wit-b21fc525 #OffSeq #Vuln #DoS #Elixir
-
🔥 HIGH severity: CVE-2026-7548 hits Totolink NR1800X (9.1.0u.6279_B20210910) — remote command injection via setUssd in /cgi-bin/cstecgi.cgi. Exploit is public, no patch yet. Disable remote management ASAP! https://radar.offseq.com/threat/cve-2026-7548-command-injection-in-totolink-nr1800-9109fa5c #OffSeq #infosec #vuln #IoT
-
Copy Fail: Every #Linux distro from 2017 to 2026 is vulnerable. Gives a root shell.
Stuff like this makes me upset about current tech. It would be better if OS codebases were smaller. They're unmanageably large nowadays. #digitalMinimalism #KeepItSimpleAndStupid
This #vuln was surfaced with #AI , in reportedly about *an hour of scanning*! https://xint.io #XInt