home.social

#vuln — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vuln, aggregated by home.social.

fetched live
  1. mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #InfoSec #CVE202617457

  2. SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #Vuln #mfyang

  3. CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

  4. CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

  5. Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SSRF #Microsoft #CyberSec

  6. CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #HealthcareSecurity #Vuln #CVE202648021

  7. CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vuln #CloudSecurity

  8. CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202656191 #ExchangeOnline #Vuln

  9. CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202656191 #ExchangeOnline #Vuln

  10. CVE-2026-42933: CRITICAL unintended proxy vuln (CVSS 10) in Pronetiqs Panduit Intravue ≤3.2.1a14 lets attackers bypass OT segmentation. No patch yet — restrict access & monitor vendor. radar.offseq.com/threat/cve-20 #OffSeq #OTSecurity #Vuln #CVE202642933

  11. CVE-2026-65907: CRITICAL RCE in JetBrains TeamCity (CVSS 9.1). Affects <2026.1.2, <2025.11.6. Exploitable via Git VCS roots — no patch yet. Restrict access, minimize Git user privileges. More info: radar.offseq.com/threat/cve-20 #OffSeq #TeamCity #Vuln #RCE

  12. CRITICAL: CVE-2026-65471 enables unauthenticated CSRF attacks in Avada Core <=5.15.6. No mitigation yet — review your deployment status and monitor for fixes. radar.offseq.com/threat/cve-20 #OffSeq #CSRF #AvadaCore #Vuln

  13. CVE-2026-46738: Dell PowerProtect Data Manager <20.2.0.0 faces a CRITICAL REST API input validation vuln. High privileged remote attackers can escalate privileges. Restrict API access & monitor privileged accounts. radar.offseq.com/threat/dell-p #OffSeq #Dell #CVE202646738 #Vuln

  14. CVE-2026-65603: HIGH severity privilege escalation in Grav Login plugin (<=3.8.11). Low-priv users can gain super-admin & RCE. Patch to v3.8.12 ASAP! radar.offseq.com/threat/cve-20 #OffSeq #GravCMS #Vuln #PrivilegeEscalation

  15. CVE-2026-63048 (CRITICAL, CVSS 9.4): joomlack.fr Page Builder CK for Joomla (v1.0.0 – 3.6.2) lets authenticated users upload arbitrary files, enabling RCE. No patch — restrict usage & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Joomla #RCE #Vuln

  16. Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. radar.offseq.com/threat/gitea- #OffSeq #Gitea #Vuln #CVE202658443

  17. CVE-2026-62549 (CRITICAL, CVSS 9.6) in Oracle HRMS (UK) 12.2.3 – 12.2.15 lets low-priv attackers compromise critical data & impact other Oracle apps. Patch status unclear — check radar.offseq.com/threat/cve-20 & restrict network access. #OffSeq #Oracle #CVE2026_62549 #Vuln

  18. CVE-2026-16412: CRITICAL memory safety issues in Firefox ESR 140.12 & 152 allow code execution, sandbox escape, info disclosure. Public exploits exist, but no in-the-wild attacks. Patch to 153/ESR 140.13. radar.offseq.com/threat/cve-20 #OffSeq #Firefox #Vuln #Security

  19. Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). radar.offseq.com/threat/critic #OffSeq #PANOS #Ransomware #Vuln

  20. Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. radar.offseq.com/threat/zimbra #OffSeq #Zimbra #InfoSec #Vuln

  21. FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202653595 #infosec #vuln

  22. CVE-2026-15901: CRITICAL use-after-free in Chrome <150.0.7871.128 allows remote heap corruption via crafted HTML. No active exploits, patch status unclear — monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Vuln #InfoSec

  23. CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: radar.offseq.com/threat/cve-20 #OffSeq #SQLi #Vuln #CVE202657309

  24. CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln

  25. CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. radar.offseq.com/threat/cve-20 #OffSeq #SQLInjection #AppSec #Vuln

  26. CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln

  27. CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #SSRF #CyberSecurity #Vuln

  28. guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. radar.offseq.com/threat/cve-20 #OffSeq #CVE202616217 #Vuln #Infosec

  29. CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #SimpleUI

  30. CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. radar.offseq.com/threat/cve-20 #OffSeq #ProFTPD #infosec #vuln

  31. CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #XSS #Vuln #InfoSec

  32. 7-Zip patched a CRITICAL RCE vulnerability — malicious archive files could allow attackers to execute code and fully compromise systems. Update to v26.02 ASAP. No CVE assigned. Full details: radar.offseq.com/threat/update #OffSeq #7zip #RCE #Vuln

  33. Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. radar.offseq.com/threat/critic #OffSeq #Vuln #PatchNow #BrowserSecurity

  34. CVE-2026-14570: HIGH severity in TIMLEGGE Crypt::DSA (<1.22) — insufficiently random values in DSA signing allow attackers to recover private keys using lattice attacks. Replace all affected keys and upgrade to 1.22+. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Perl #Crypto

  35. CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. radar.offseq.com/threat/cve-20 #OffSeq #Linux #Vuln #RedHat

  36. CVE-2026-13491: MEDIUM severity DoS flaw in 78 xiaozhi-esp32 (v2.2.0 – 2.2.6) via MQTT Goodbye Handler. Exploitable remotely with public exploit. Patch via commit e182471f8c5a. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoT #DoS

  37. CVE-2026-53753: CRITICAL code injection in unclecode crawl4ai (<0.8.7). Unauthenticated RCE via /crawl POST request due to insufficient AST validation. Patch to 0.8.7 ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202653753 #infosec #vuln

  38. 🔒 CRITICAL: CVE-2026-12441 in Chrome <149.0.7827.155 on Linux — use-after-free in File Input. Remote attacker can trigger heap corruption via crafted HTML. Update Chrome ASAP! radar.offseq.com/threat/cve-20 #OffSeq #Chrome #Linux #Vuln

  39. Nice, #Bumsrakete works on a #FreeBSD 15.0 system.

    TL;DR page cache #vuln in the #kernel, exploitable within seconds, privesc from normal user to #root

    17/10 can recommend ⭐🌟

    bumsrake.de/

  40. 🔒 CVE-2026-52726 (HIGH): jelmer dulwich <1.2.5 allows path traversal via malicious submodules — attackers can drop executables in .git/hooks for code execution. Upgrade to 1.2.5+ ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Infosec #Vuln #Python #Git

  41. 🚨 CRITICAL: CVE-2026-11499 in Tenda HG7HG9/HG10 (firmware 300001138_en_xpon) allows remote stack-based buffer overflow via blkDomain in formDOMAINBLK. No patch yet — restrict access and monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoT #CyberSecurity

  42. 🚨 CRITICAL: Joomla Content Editor (JCE) vuln (CVE-2026-48907) allows unauthenticated PHP upload & exec (v1.0.0 – 2.9.99.4). No patch yet — restrict or disable JCE & monitor systems. Details: radar.offseq.com/threat/cve-20 #OffSeq #Joomla #Vuln #InfoSec

  43. ⚠️ CVE-2026-10187 CRITICAL: Totolink N300RH (6.1c.1353_B20190305) is exposed to a remote stack-based buffer overflow in setWiFiBasicConfig. Exploit is public, no patch yet — restrict Web Management access! radar.offseq.com/threat/cve-20 #OffSeq #IoT #Infosec #Vuln

  44. ⚠️ CRITICAL: Actively exploited privilege escalation in LiteSpeed cPanel plugin (CVE-2026-48172) enables remote root access via lsws.redisAble. Patch plugin v2.3 – v2.4.4 now! CISA mandates 4-day deadline for U.S. agencies. radar.offseq.com/threat/cisa-g #OffSeq #vuln #patchnow

  45. ⚠️ HIGH severity: CVE-2026-48962 in PMQS IO::Compress (Perl <2.220) enables eval injection via crafted glob strings. Arbitrary Perl code may execute with process privileges. Restrict untrusted input & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Perl #Infosec

  46. 🚩 CVE-2026-42496: HIGH severity vuln in BINGOS Archive::Tar (<3.08). Symlinks in tar archives can escape extraction dir, risking unauthorized file access. No patch yet — avoid untrusted archives! radar.offseq.com/threat/cve-20 #OffSeq #vuln #Perl #infosec

  47. 🚨 CRITICAL: CVE-2026-23652 in Microsoft Power Pages enables remote, unauthenticated code execution (command injection, CVSS 10). Patch immediately to prevent full system compromise! Details & fix: radar.offseq.com/threat/cve-20 #OffSeq #Cybersecurity #Microsoft #Vuln

  48. 🚨 CRITICAL: CVE-2026-41090 in Microsoft 365 Copilot for iOS enables remote command injection (CVSS 9.3). Microsoft has patched server-side — verify your service is up to date. More info: radar.offseq.com/threat/cve-20 #OffSeq #Microsoft #Vuln #InfoSec

  49. 🔥 CVE-2026-33278: Critical use-after-free in NLnet Labs Unbound (1.19.1 – 1.25.0). DNSSEC validator flaw can lead to DoS or RCE if attacker controls DNS zone. Patch: upgrade to 1.25.1. radar.offseq.com/threat/cve-20 #OffSeq #DNSSEC #Vuln #Infosec

  50. @angst_ridden Oh, I am full on (30 year career in infosec and infra), #terraform , #ansible, #argocd, #gha (unfortunately because I hate it), #python and #golang Staff CloudOps Engineer.

    My OP was just me bitching about it.

    My cool task today is setting up a #capev2 server for #vuln and #mal testing.

  51. 🚨 CVE-2026-8507 (HIGH): Out-of-bounds write in Crypt::OpenSSL::PKCS12 <=1.94 for Perl. Parsing PKCS12 files with >=1GiB OCTET/BIT STRING may lead to RCE. Patch available for cloud-hosted service — update ASAP. No known exploits. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Perl

  52. 🚩 CRITICAL: CVE-2026-6722 in PHP SOAP (8.2 – 8.5) allows unauthenticated RCE via use-after-free. No patch confirmed — restrict SOAP access or disable if not needed. Details: radar.offseq.com/threat/cve-20 #OffSeq #PHP #Vuln #RCE #InfoSec

  53. Rien ne dit “bon week-end” comme trois CVE cPanel annoncées un vendredi, avec les détails techniques livrés pile au moment du patch -->c’est-à-dire à 18h, l’heure sacrée de l’apéro.

    Santé aux admins qui vont lancer /scripts/upcp avec une main sur le clavier et l’autre sur le verre.
    👇
    " To help protect customers prior to patch availability, technical details about vulnerabilities will be released alongside the patches. Full technical details will be published on our support page at the same time the patch is released. The CVE IDs are CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203.

    Patch & Affected Versions
    The patch will be available on May 08 at 12:00pm EST and will be distributed through the standard cPanel automatic update process and through the manual update process. We strongly recommend performing a manual update with /scripts/upcp once the patch is made available.
    "
    👇
    reddit.com/r/cpanel/comments/1

    #CpanelVulnerability #cpanel #CyberVeille #vuln #infosec

  54. 🌐 CVE-2026-42368 | CRITICAL privilege escalation in GeoVision GV-LPC2011/LPC2211 v1.10. Remote attackers can gain full control via crafted HTTP requests. No patch — restrict web interface access & monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoT #CyberSecurity

  55. 🚨 CVE-2026-39804 (HIGH): mtrudel bandit <1.11.0 allows remote DoS via memory exhaustion if WebSocket permessage-deflate is enabled. Disable compression to mitigate. Affects only non-default configs. Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #DoS #Elixir

  56. 🔥 HIGH severity: CVE-2026-7548 hits Totolink NR1800X (9.1.0u.6279_B20210910) — remote command injection via setUssd in /cgi-bin/cstecgi.cgi. Exploit is public, no patch yet. Disable remote management ASAP! radar.offseq.com/threat/cve-20 #OffSeq #infosec #vuln #IoT

  57. Copy Fail: Every distro from 2017 to 2026 is vulnerable. Gives a root shell.

    Stuff like this makes me upset about current tech. It would be better if OS codebases were smaller. They're unmanageably large nowadays.

    This was surfaced with , in reportedly about *an hour of scanning*! xint.io