Overview
Description
Statistics
- 2 Posts
Fediverse
📝 New article by a CrowdSec Ambassador, Killian Prin-Abeil! 🎉
In this deep dive, Killian breaks down React2Shell (CVE-2025-55182), from how the RCE works in React Server Components to why Next.js apps are vulnerable by default.
He also explores how the community reacted in hours, with CrowdSec shipping a virtual patch and threat intel to reduce exposure immediately.
👉Read it here: https://crowdsec.net/blog/react2shell-overly-spicy-side-of-react-19
#react #NextJS #AppSec #opensourcesecurity #react2shell #CVE
Overview
Description
Statistics
- 2 Posts
Fediverse
Aktuelle Neuigkeiten: Aktuelle Angriffswelle gegen CVE-2025-59718, Patches unzureichend
https://www.cert.at/de/aktuelles/2026/1/aktuelle-angriffswelle-gegen-cve-2025-59718-patch-unzureichend
https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/
/via @Hetti
#Fortinet
Overview
- Oracle Corporation
- Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in
Description
Statistics
- 2 Posts
Fediverse
🔴 CVE-2026-21962 - Critical (10)
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-21962/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
📰 Oracle Issues Critical Patch for CVSS 10.0 Auth Bypass in WebLogic Server
🚨 CRITICAL PATCH: Oracle's January 2026 update fixes 337 flaws, including a CVSS 10.0 auth bypass (CVE-2026-21962) in WebLogic Server. This is remotely exploitable with no user interaction. Patch immediately! ⚠️ #Oracle #PatchTuesday #CVE
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
Our January 2026 maintenance releases of BIND 9 are available and can be downloaded from the links below. Packages and container images provided by ISC will be updated later today.
In addition to bug fixes and feature improvements, these releases also contain fixes for a security vulnerability. More information can be found in the following Security Advisory:
https://kb.isc.org/docs/cve-2025-13878
Download software and release notes at: https://www.isc.org/download/
Overview
- TP-Link Systems Inc.
- VIGI InSight Sx45 Series (S245/S345/S445)
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
Eine kritische Sicherheitslücke CVE-2026-0629 erlaubt es Angreifern, Admin-Zugriff auf zahlreiche #TPLink Vigi-Überwachungskameras per Fernzugriff zu erlangen. https://www.golem.de/specials/tp-link/
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
🟠 CVE-2026-0899 - High (8.8)
Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-0899/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🔴 CVE-2026-0907 - Critical (9.8)
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-0907/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- hwk-fr
- Advanced Custom Fields: Extended
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
‼️CVE-2025-14533: The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1, exposing 100,000 sites.
CVSS: 9.8
CVE Published: January 20th, 2026
Bounty: $975.00
Advisory: https://github.com/advisories/GHSA-jm76-5g2j-p4hp
Description: The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can register. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can only be exploited if 'role' is mapped to the custom field.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🔴 CVE-2026-0610 - Critical (9.8)
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-0610/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack