Overview
Description
Statistics
- 9 Posts
- 2 Interactions
Fediverse
WordPress Patch Became Exploit Blueprint: CVE-2026-87902 Webshells Hit 350K Sites
https://www.techtimes.com/articles/328042/20260925/wordpress-patch-became-exploit-blueprint-cve-2026-87902-webshells-hit-350k-sites.htm?utm_source=flipboard&utm_medium=activitypub
Posted into Cybersecurity Today @cybersecurity-today-rhudaur
Ciberatacantes aprovechan la vulnerabilidad CVE-2026-87902 de WordPress pocas horas después de su publicación
https://blog.elhacker.net/2026/09/ciberatacantes-aprovechan-la.html
Seguridad: Vulnerabilidad CVE-2026-87902 en WordPress
Si tienes wordpress, te estás tardando en actualizar. Llévalo a la versión 7.1.2, pues es una situación crítica de seguridad.
https://interlan.ec/blog/2026/09/25/seguridad-vulnerabilidad-cve-2026-87902-en-wordpress/
📰 Critical WordPress Path Traversal Flaw Actively Exploited (CVE-2026-87902)
🚨 CRITICAL VULNERABILITY: WordPress Core is being actively exploited via CVE-2026-87902 (CVSS 9.2). The unauthenticated path traversal flaw can lead to RCE. Affects versions 4.7.0-7.1.1. Update to 7.1.2 immediately! #WordPress #CVE #CyberSecurity #P...
Bluesky
Overview
Description
Statistics
- 9 Posts
- 5 Interactions
Fediverse
Love the energy 😅
>Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
Discover the critical F5 BIG-IP zero-day vulnerability CVE-2026-94127. Learn why CISA demands immediate patching for this actively exploited APM flaw.
An exploited F5 BIG-IP RCE vulnerability (CVE-2026-94127) is under active attack. Discover how the PoC works and patch your APM proxies immediately.
#F5Networks #CVE202694127 #Cybersecurity #Infosec #ZeroDay #Vulnerability
📰 F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE
F5 BIG-IP APM is being actively exploited via a critical RCE zero-day (CVE-2026-94127). CISA has added it to the KEV catalog, mandating an urgent patch. The flaw affects systems with a specific OAuth config. #F5 #BIGIP #CyberSecurity #RCE
Bluesky
Overview
- Roundcube
- Webmail
Description
Statistics
- 7 Posts
- 3 Interactions
Fediverse
Learn how hackers are exploiting the CVE-2026-48842 Roundcube SQL injection vulnerability. Understand the risk and how to patch your webmail server immediately.
#Roundcube #CyberSecurity #SQLInjection #DataBreach #TechNews
🚨 Roundcube SQL injection flaw actively exploited months after patches were released
The Canadian Centre for Cyber Security has warned that CVE-2026-48842, a high-severity vulnerability in Roundcube Webmail, is being exploited in the wild.
⠀
Roundcube is an open-source webmail application that lets people access email through a browser.
The flaw affects its virtuser_query plugin and allows SQL injection before authentication.
⠀
Key details:
• CVSS score: 8.1
• No attacker credentials required
• No user interaction required
• Affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1
⠀
Roundcube released the original fixes on May 24, 2026. Canada added the exploitation warning to its advisory on September 21, citing open-source reporting.
The advisory does not identify the attackers, victims or scale of exploitation.
⠀
Administrators should update affected installations promptly. Newer security releases, 1.6.19 and 1.7.4, also address additional vulnerabilities.
Source: https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503
Bluesky
Overview
Description
Statistics
- 5 Posts
- 3 Interactions
Fediverse
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-5430 – WSO2 Multiple Products Path Traversal Vulnerability
Analyze the technical mechanics of CVE-2026-5430 with our WSO2 TSUITE brief, covering directory traversal vectors, unrestricted file uploads, and endpoint hardening....
"CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks"
"[...] The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2."
CISA added two exploited CISA KEV vulnerabilities to its catalog. Patch WSO2 and Adobe Commerce to secure systems against active attacks.
#CISA #KEV #CVE20265430 #CVE202671362 #WSO2 #AdobeCommerce #Cybersecurity
Overview
Description
Statistics
- 5 Posts
- 11 Interactions
Fediverse
Go hunt on your SharePoint shit.
Update September 25th, 2026: The exploitation creates a webshell backdoor named: "/_layouts/15/sphealth.aspx"
An exploited SharePoint RCE vulnerability is under attack. Technical details for this SharePoint RCE vulnerability are public. Patch CVE-2026-65660 now.
#SharePoint #CVE202665660 #RCE #Cybersecurity #Infosec #ZeroDay
Bluesky
Overview
- Avast
- (Free/Premiium/Ultimeat) Antivirus
Description
Statistics
- 9 Posts
Bluesky
Overview
- Eufy
- Omni C20
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CVE-2026-93291 (CRITICAL): Eufy Omni C20 (<1.6.4) fails certificate validation, exposing devices to MITM and arbitrary code execution. Patch status unknown — use strong network protections. https://radar.offseq.com/threat/cve-2026-93291-cwe-295-improper-certificate-validation-in-eufy-omni-c20-63bb60225f0bad8d #OffSeq #CVE202693291 #IoTSecurity #Vuln #Infosec
Critical Eufy robot vacuum vulnerabilities expose the Omni C20 and X10 Pro to OS command injection. Patch CVE-2026-93289 and CVE-2026-93291 immediately.
#Eufy #CVE202693289 #CVE202693291 #IoT #Cybersecurity #Vulnerability
Overview
- pgpartman
- pg_partman
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
CVE-2026-61821 pg_partman: drop_partition_id/time allow privilege escalation to superuser via retention_schema. CVSS 8.5, unpatched. patch to 5.5.0 now https://www.valtersit.com/cve/CVE-2026-61821/ #CVE #infosec #PostgreSQL
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Japan's Digital Agency was breached through a VPN flaw that was public before the attack. Data on ~246,000 officials and contractors may be exposed.
The agency won't name the product. Japanese researcher piyolog points to CVE-2026-0257 (PAN-OS GlobalProtect), added to CISA KEV on May 29. Detection to disclosure: eleven weeks, with no CVE or IOCs in the notice.
Our take on patching by CVSS, "zero trust" as a label, and Japan's disclosure culture:
https://japancyberwatch.com/articles/japan-digital-agency-gss-breach-2026
#infosec #Japan #DataBreach #VulnerabilityManagement #PaloAlto