Overview
- Roundcube
- Webmail
Description
Statistics
- 7 Posts
- 3 Interactions
Fediverse
Learn how hackers are exploiting the CVE-2026-48842 Roundcube SQL injection vulnerability. Understand the risk and how to patch your webmail server immediately.
#Roundcube #CyberSecurity #SQLInjection #DataBreach #TechNews
🚨 Roundcube SQL injection flaw actively exploited months after patches were released
The Canadian Centre for Cyber Security has warned that CVE-2026-48842, a high-severity vulnerability in Roundcube Webmail, is being exploited in the wild.
⠀
Roundcube is an open-source webmail application that lets people access email through a browser.
The flaw affects its virtuser_query plugin and allows SQL injection before authentication.
⠀
Key details:
• CVSS score: 8.1
• No attacker credentials required
• No user interaction required
• Affects Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1
⠀
Roundcube released the original fixes on May 24, 2026. Canada added the exploitation warning to its advisory on September 21, citing open-source reporting.
The advisory does not identify the attackers, victims or scale of exploitation.
⠀
Administrators should update affected installations promptly. Newer security releases, 1.6.19 and 1.7.4, also address additional vulnerabilities.
Source: https://www.cyber.gc.ca/en/alerts-advisories/roundcube-security-advisory-av26-503
Roundcube Webmail Under Attack: 523,000 Instances Exposed Online https://www.esecurityplanet.com/threats/news-roundcube-cve-2026-48842-active-exploitation/
Bluesky
Overview
Description
Statistics
- 8 Posts
- 2 Interactions
Fediverse
WordPress Patch Became Exploit Blueprint: CVE-2026-87902 Webshells Hit 350K Sites
https://www.techtimes.com/articles/328042/20260925/wordpress-patch-became-exploit-blueprint-cve-2026-87902-webshells-hit-350k-sites.htm?utm_source=flipboard&utm_medium=activitypub
Posted into Cybersecurity Today @cybersecurity-today-rhudaur
Ciberatacantes aprovechan la vulnerabilidad CVE-2026-87902 de WordPress pocas horas después de su publicación
https://blog.elhacker.net/2026/09/ciberatacantes-aprovechan-la.html
Seguridad: Vulnerabilidad CVE-2026-87902 en WordPress
Si tienes wordpress, te estás tardando en actualizar. Llévalo a la versión 7.1.2, pues es una situación crítica de seguridad.
https://interlan.ec/blog/2026/09/25/seguridad-vulnerabilidad-cve-2026-87902-en-wordpress/
📰 Critical WordPress Path Traversal Flaw Actively Exploited (CVE-2026-87902)
🚨 CRITICAL VULNERABILITY: WordPress Core is being actively exploited via CVE-2026-87902 (CVSS 9.2). The unauthenticated path traversal flaw can lead to RCE. Affects versions 4.7.0-7.1.1. Update to 7.1.2 immediately! #WordPress #CVE #CyberSecurity #P...
Bluesky
Overview
Description
Statistics
- 7 Posts
- 5 Interactions
Fediverse
Love the energy 😅
>Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
Discover the critical F5 BIG-IP zero-day vulnerability CVE-2026-94127. Learn why CISA demands immediate patching for this actively exploited APM flaw.
📰 F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE
F5 BIG-IP APM is being actively exploited via a critical RCE zero-day (CVE-2026-94127). CISA has added it to the KEV catalog, mandating an urgent patch. The flaw affects systems with a specific OAuth config. #F5 #BIGIP #CyberSecurity #RCE
Bluesky
Overview
Description
Statistics
- 6 Posts
- 11 Interactions
Fediverse
Go hunt on your SharePoint shit.
Update September 25th, 2026: The exploitation creates a webshell backdoor named: "/_layouts/15/sphealth.aspx"
An exploited SharePoint RCE vulnerability is under attack. Technical details for this SharePoint RCE vulnerability are public. Patch CVE-2026-65660 now.
#SharePoint #CVE202665660 #RCE #Cybersecurity #Infosec #ZeroDay
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Bluesky
Overview
Description
Statistics
- 4 Posts
- 7 Interactions
Fediverse
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-5430 – WSO2 Multiple Products Path Traversal Vulnerability
Analyze the technical mechanics of CVE-2026-5430 with our WSO2 TSUITE brief, covering directory traversal vectors, unrestricted file uploads, and endpoint hardening....
"CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks"
"[...] The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2."
Overview
- SolarWinds
- Observability Self-Hosted
Description
Statistics
- 2 Posts
Fediverse
📰 SolarWinds Patches Critical Unauthenticated RCE Flaws in Observability Platform
SolarWinds patches two unauthenticated RCE vulnerabilities in its Observability Self-Hosted platform. CVE-2026-28324 is rated critical (CVSS 9.8). Customers are urged to update to version 2026.2.3 immediately. #SolarWinds #CVE #RCE #PatchTuesday
SolarWinds Critical Vulnerability: RCE Flaw Patched
#SolarWinds #Vulnerability #Cybersecurity #CVE202628324 #InfoSec A monitoring system engineered to oversee corporate infrastructure can inadvertently pave the way for an attacker to breach the network. SolarWinds has rectified a critical vulnerability within Observability Self-Hosted that permitted unauthenticated remote code execution. Tracked as CVE-2026-28324, this flaw achieved a staggering CVSS severity score of 9.8 out of 10. Exploitation requires neither system privileges nor user interaction, and the attack complexity is deemed low.
Overview
- Avast
- (Free/Premiium/Ultimeat) Antivirus
Description
Statistics
- 9 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
🚨 ShinyHunters resumes mass exploitation of critical Oracle PeopleSoft flaw using simple WAF bypass.
Mandiant and Google Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240, also known as ShinyHunters.
⠀
The critical vulnerability allows unauthenticated remote code execution in Oracle PeopleSoft PeopleTools and carries a CVSS score of 9.8.
Oracle released an emergency patch on June 10.
⠀
The new campaign targets organizations that attempted to mitigate the flaw using web application firewall rules but did not install the patch.
ShinyHunters bypassed rules blocking the vulnerable /PSEMHUB/ endpoint by encoding a single character and sending requests to /%50SEMHUB/.
⠀
Google says web shells were deployed on dozens of systems worldwide across:
• Higher education
• Technology
• IT services
• Healthcare
• Agriculture
• Transportation
• Government
⠀
The actors deployed web shells, the SIDEEYE backdoor, Neo-reGeorg tunneling tools and MeshAgent for persistent remote access.
Around one-quarter of the observed commands executed with root or SYSTEM privileges.
⠀
Organizations running PeopleSoft should patch immediately, disable or remove the Environment Management Hub where possible and investigate encoded variants of /PSEMHUB/ in access logs.
WAF rules alone are not sufficient.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Japan's Digital Agency was breached through a VPN flaw that was public before the attack. Data on ~246,000 officials and contractors may be exposed.
The agency won't name the product. Japanese researcher piyolog points to CVE-2026-0257 (PAN-OS GlobalProtect), added to CISA KEV on May 29. Detection to disclosure: eleven weeks, with no CVE or IOCs in the notice.
Our take on patching by CVSS, "zero trust" as a label, and Japan's disclosure culture:
https://japancyberwatch.com/articles/japan-digital-agency-gss-breach-2026
#infosec #Japan #DataBreach #VulnerabilityManagement #PaloAlto