Overview
Description
Statistics
- 1 Post
- 5 Interactions
Overview
- supsysticcom
- Contact Form by Supsystic
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL: CVE-2026-4257 in Contact Form by Supsystic (all versions) enables unauth RCE via SSTI (Twig). No patch yet. Disable plugin or block endpoints ASAP. Details: https://radar.offseq.com/threat/cve-2026-4257-cwe-94-improper-control-of-generatio-c9e2f160 #OffSeq #WordPress #CVE20264257 #SSTI #RCE
Overview
- Microsoft
- Windows 10 Version 21H2
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
- GIGABYTE
- Gigabyte Control Center
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2026-4415 (CRITICAL, CVSS 9.2) hits Gigabyte Control Center: unauth’d remote attackers can write files anywhere if pairing is enabled. No patch yet — disable pairing & monitor for anomalies. https://radar.offseq.com/threat/cve-2026-4415-cwe-23-relative-path-traversal-in-gi-d148431b #OffSeq #Vuln #Gigabyte #Infosec
Overview
- pyca
- cryptography
Description
Statistics
- 1 Post
Overview
- OneUptime
- oneuptime
Description
Statistics
- 1 Post
Overview
- baserproject
- basercms
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2026-21861: CRITICAL OS command injection in baserCMS < 5.2.3. Admins can execute arbitrary system commands via core update. Patch to 5.2.3+ ASAP to prevent full compromise. https://radar.offseq.com/threat/cve-2026-21861-cwe-78-improper-neutralization-of-s-7b86deef #OffSeq #baserCMS #CVE2026_21861 #infosec #patching
Overview
Description
Statistics
- 1 Post
Fediverse
🔒 Security Advisory: OWASP CRS file upload extension checks could be bypassed using whitespace padding in filenames (e.g. shell. php). CVE-2026-33691, Moderate severity.
Upgrade to CRS v4.25.0 or v3.3.9.
Thanks @HackingRepo for the report!
https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w