Overview
Description
Statistics
- 4 Posts
Fediverse
⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data…
Bluesky
Overview
- vBulletin
- vBulletin
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
🚨 New advisory was just published!
An independent security researcher working with SSD Secure Disclosure has identified a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server. The vulnerability has been assigned CVE-2026-61511. Read our full advisory: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
🚨‼️ CVE-2026-61511: A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server.
CVSS: 9.8
Exploit: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
A public PoC now targets CVE-2026-61511, a vBulletin preauth RCE via runMaths eval. Patch to vBulletin 6.2.2 to block remote code execution.
#vBulletin #CVE202661511 #RCE #PreauthRCE #RemoteCodeExecution #PoC #WebSecurity #Cybersecurity
Overview
- Alibaba
- Fastjson
Description
Statistics
- 3 Posts
Fediverse
⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux https://www.it-connect.fr/refluxfs-cve-2026-64600-faille-xfs-acces-root-linux/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Linux
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-49176 is a Windows WalletService elevation of privilege flaw. Full details and a public PoC exploit are out, so patch Windows now.
#CVE202649176 #WalletService #Windows #PrivilegeEscalation #EoP #PoC #Microsoft
Overview
Description
Statistics
- 2 Posts
- 29 Interactions
Fediverse
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
Overview
Description
Statistics
- 2 Posts
- 29 Interactions
Fediverse
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Apache Software Foundation
- Apache Fory
- org.apache.fory:fory-core
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Apache Fory vulnerabilities hit Java, C++, and Rust deserialization, including CVE-2026-64606. Upgrade to Fory 1.4.0 to fix all four flaws.
#ApacheFory #Deserialization #Java #Rust #Cpp #Vulnerability #OpenSource #Cybersecurity
Overview
- Microsoft
- Microsoft Edge (Chromium-based)
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-57990 - High-severity information disclosure in Microsoft Edge (Chromium). Unauthorized access to files over network. CVSS 7.4. No patch yet—restrict network access. #CVE #Microsoft #edge