home.social

#vuln — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vuln, aggregated by home.social.

  1. CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

  2. CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

  3. CVE-2026-85681 (CRITICAL): WP Component plugin ≤2.2.4 allows unauthenticated option overwrites, risking full WordPress site takeover. Single-site installs are exposed. Check vendor advisory for mitigation steps: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #BlueTeam

  4. CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #TLS

  5. CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #TLS

  6. CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #TLS

  7. CVE-2026-86781: SSL Zen plugin (<4.7.40) has a CRITICAL auth flaw — any WP user can download TLS private key & certs, risking site impersonation. Patch to 4.7.40+ now. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #TLS

  8. CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202615013 #SAML #Vuln

  9. CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202615013 #SAML #Vuln

  10. CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202615013 #SAML #Vuln

  11. 🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #vuln #bruteforce

  12. 🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #vuln #bruteforce

  13. 🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #vuln #bruteforce

  14. 🛡️ HIGH severity in SignalK signalk-server <2.25.0 (CVE-2026-41893): WebSocket login bypasses rate limits, enabling fast brute force attacks. Patch to 2.25.0+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #vuln #bruteforce