Overview
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
New vulnerability disclosure from
@chocapikk_:
CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K or so based on the team's ASM queries. Good stuff as always from Valentin.
https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
Description
Statistics
- 2 Posts
- 5 Interactions
Bluesky
Overview
- Wishlist Member
- Wishlist Member
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
CVE-2026-12949 - Critical Account Takeover in Wishlist Member WordPress plugin. Insufficient verification allows attacker to merge accounts. CVSS 9.8. Unpatched. Update immediately. #CVE #WordPress #infosec
Overview
- Microsoft
- Microsoft Configuration Manager
Description
Statistics
- 2 Posts
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🚨 THREAT ALERT: CVE-2026-20349
Active exploitation verified on Cisco ASA & FTD firewalls via a high-severity heap inspection flaw. IT leadership must enforce immediate patch protocols and audit perimeter logs.
https://thecybermind.co/z7x3
👉 Watch breakdown: https://www.youtube.com/shorts/xzFNHt3De3I
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post
Fediverse
Certighost: cuando un usuario de dominio puede acabar obteniendo un certificado de un Domain Controller (CVE-2026-54121)
Si durante los últimos años ha habido una tecnología de Active Directory que ha pasado de ser la gran olvidada a convertirse en uno de los objetivos favoritos de Red Teams y atacantes reales, esa es Active Directory Certificate Services (AD CS).
https://www.hackplayers.com/2026/07/certighost-cuando-un-usuario-de-dominio.html
Overview
- Go standard library
- net
- net
Description
Statistics
- 1 Post
Overview
- Go standard library
- encoding/xml
- encoding/xml
Description
Statistics
- 1 Post
Overview
- getgrav
- grav
Description
Statistics
- 1 Post
Fediverse
Grav API plugin <1.0.13 has a CRITICAL flaw (CVE-2026-72830): scoped API keys can inject arbitrary commands into scheduler config, leading to remote code execution. Patch now! https://radar.offseq.com/threat/cve-2026-72830-improper-privilege-management-in-getgrav-grav-96262eb7a2b2ec89 #OffSeq #CVE202672830 #Grav #RCE #Infosec