Overview
- WordPress
- WordPress
Description
Statistics
- 4 Posts
- 12 Interactions
Fediverse
Another one of those WordPress pre-auth RCEs
This one's named XSS2Shell, CVE-2026-64638, found with AI, patched in v7.0.3, released on Thursday
Dans la suite de wp2shell, encore une jolie chaîne WordPress : #XSS2Shell — CVE-2026-64638.
Au départ, on a “juste” une Reflected XSS pré-auth sur wp-login.php.
Sauf qu’en la chaînant avec plusieurs briques déjà présentes dans WordPress, on arrive à quelque chose de beaucoup moins sympa :
XSS → contexte admin → Application Password → REST API → upload de plugin → RCE 🐚
⚠️ À noter quand même : ce n’est pas du pre-auth zero-click.
Il faut qu’un admin déjà connecté clique sur un lien contrôlé par l’attaquant.
Encore un bon rappel : une “simple XSS” peut devenir franchement méchante une fois mise dans la bonne chaîne.
🩹 Corrigé dans WordPress 7.0.3.
👇
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
En cas de doute sur une exploitation passée : petit coup d’œil aux Application Passwords, aux plugins récemment ajoutés et aux fichiers PHP inhabituels.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)"
👇
https://pwn.ai/blog/xss2shell
Overview
Description
Statistics
- 3 Posts
- 16 Interactions
Fediverse
The SCTPhantom vulnerability, CVE-2026-64564, affects Linux SCTP code and can be exploited for root access and container escape.
https://linuxiac.com/18-year-old-linux-kernel-vulnerability-enables-root-access-and-container-escape/
Overview
- MSI
- Radix AXE6600
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CVE-2026-71987: MSI Radix AXE6600 (v781521) suffers from a CRITICAL OS command injection vulnerability (CVSS 9.3). Remote, unauthenticated code execution possible with root privileges. Restrict device access and monitor! https://radar.offseq.com/threat/cve-2026-71987-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-injection-46b78b0439cf6545 #OffSeq #CVE202671987 #Infosec #RouterSecurity
Overview
Description
Statistics
- 2 Posts
Fediverse
📰 CISA Adds Progress Kemp LoadMaster Flaw to KEV Catalog After Exploits
🚨 CISA KEV ALERT: A critical command injection flaw in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) is actively exploited. Unauthenticated attackers can gain full control. Federal agencies must patch by Aug 10. #CVE #CISA #KEV #PatchNow
Overview
Description
Statistics
- 2 Posts
Fediverse
🚨 CRITICAL ADVISORY: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077). Attackers exploit flawed XStream deserialization under /app/agents/v1/ to execute arbitrary commands. Patch immediately!
https://denizhalil.com/2026/08/10/cve-2026-63077-jetbrains-teamcity-rce-analysis/
#CyberSecurity #RCE #DevSecOps
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- gstreamer1-plugins-ugly-free
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
GStreamer gst-plugins-ugly (asfdemux) in Red Hat Enterprise Linux 10 is affected by CVE-2026-19389 (HIGH, CVSS 7.1). Parsing crafted ASF/WMV/WMA files may lead to DoS or info leaks. No patch yet — avoid untrusted media. https://radar.offseq.com/threat/cve-2026-19389-integer-overflow-or-wraparound-in-red-hat-red-hat-enterprise-linux-10-8bd45ea7a574114c #OffSeq #Linux #CVE #GStreamer
Overview
- hapifhir
- org.hl7.fhir.core
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- wupsales
- AI Copilot – Content Generator
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-14526 - Critical auth bypass in AI Copilot WordPress plugin. Unauthenticated attackers can create admin accounts and take over sites. CVSS 9.8. Unpatched. Disable plugin now. #CVE #WordPress #infosec
Overview
- D-Link Corporation
- DWR-M961
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Dell
- OpenManage Server Administrator Managed Node (Patch) for Windows
Description
Statistics
- 1 Post
- 1 Interaction