home.social

#vuln — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vuln, aggregated by home.social.

  1. mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #CVE202617457

  2. mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #CVE202617457

  3. mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #CVE202617457

  4. mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #CVE202617457

  5. SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #mfyang

  6. SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #mfyang

  7. SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #mfyang

  8. SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #mfyang

  9. CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

  10. CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

  11. CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

  12. CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

  13. CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

  14. Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SSRF #Microsoft #CyberSec

  15. Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SSRF #Microsoft #CyberSec

  16. Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SSRF #Microsoft #CyberSec

  17. CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #HealthcareSecurity #Vuln #CVE202648021

  18. CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #HealthcareSecurity #Vuln #CVE202648021

  19. CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #HealthcareSecurity #Vuln #CVE202648021

  20. CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #HealthcareSecurity #Vuln #CVE202648021

  21. CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSecurity

  22. CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSecurity

  23. CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSecurity

  24. CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSecurity

  25. CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202656191 #ExchangeOnline #Vuln

  26. CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202656191 #ExchangeOnline #Vuln

  27. CVE-2026-42933: CRITICAL unintended proxy vuln (CVSS 10) in Pronetiqs Panduit Intravue ≤3.2.1a14 lets attackers bypass OT segmentation. No patch yet — restrict access & monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #OTSecurity #Vuln #CVE202642933

  28. CVE-2026-65907: CRITICAL RCE in JetBrains TeamCity (CVSS 9.1). Affects <2026.1.2, <2025.11.6. Exploitable via Git VCS roots — no patch yet. Restrict access, minimize Git user privileges. More info: radar.offseq.com/threat/cve-20 #OffSeq #TeamCity #Vuln #RCE

  29. CRITICAL: CVE-2026-65471 enables unauthenticated CSRF attacks in Avada Core <=5.15.6. No mitigation yet — review your deployment status and monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #CSRF #AvadaCore #Vuln

  30. CVE-2026-46738: Dell PowerProtect Data Manager <20.2.0.0 faces a CRITICAL REST API input validation vuln. High privileged remote attackers can escalate privileges. Restrict API access & monitor privileged accounts. radar.offseq.com/threat/dell-p #OffSeq #Dell #CVE202646738 #Vuln

  31. CVE-2026-65603: HIGH severity privilege escalation in Grav Login plugin (<=3.8.11). Low-priv users can gain super-admin & RCE. Patch to v3.8.12 ASAP! radar.offseq.com/threat/cve-20 #OffSeq #GravCMS #Vuln #PrivilegeEscalation

  32. CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #RCE #Vuln

  33. CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #RCE #Vuln

  34. CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #RCE #Vuln

  35. CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #RCE #Vuln

  36. Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. radar.offseq.com/threat/gitea- #OffSeq #Gitea #Vuln #CVE202658443

  37. Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. radar.offseq.com/threat/gitea- #OffSeq #Gitea #Vuln #CVE202658443

  38. Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. radar.offseq.com/threat/gitea- #OffSeq #Gitea #Vuln #CVE202658443

  39. Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. radar.offseq.com/threat/gitea- #OffSeq #Gitea #Vuln #CVE202658443

  40. CVE-2026-62549 (CRITICAL, CVSS 9.6) in Oracle HRMS (UK) 12.2.3 – 12.2.15 lets low-priv attackers compromise critical data & impact other Oracle apps. Patch status unclear — check radar.offseq.com/threat/cve-20 & restrict network access. #OffSeq #Oracle #CVE2026_62549 #Vuln

  41. CVE-2026-16412: CRITICAL memory safety issues in Firefox ESR 140.12 & 152 allow code execution, sandbox escape, info disclosure. Public exploits exist, but no in-the-wild attacks. Patch to 153/ESR 140.13. radar.offseq.com/threat/cve-20 #OffSeq #Firefox #Vuln #Security

  42. Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). radar.offseq.com/threat/critic #OffSeq #PANOS #Ransomware #Vuln

  43. Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). radar.offseq.com/threat/critic #OffSeq #PANOS #Ransomware #Vuln

  44. Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). radar.offseq.com/threat/critic #OffSeq #PANOS #Ransomware #Vuln

  45. Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). radar.offseq.com/threat/critic #OffSeq #PANOS #Ransomware #Vuln

  46. Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. radar.offseq.com/threat/zimbra #OffSeq #Zimbra #InfoSec #Vuln

  47. Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. radar.offseq.com/threat/zimbra #OffSeq #Zimbra #InfoSec #Vuln

  48. Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. radar.offseq.com/threat/zimbra #OffSeq #Zimbra #InfoSec #Vuln

  49. Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. radar.offseq.com/threat/zimbra #OffSeq #Zimbra #InfoSec #Vuln

  50. FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202653595 #infosec #vuln