Overview
- Apache Software Foundation
- Apache Storm Client
- org.apache.storm:storm-client
Description
Statistics
- 1 Post
Fediverse
🔒 CRITICAL: CVE-2026-35337 in Apache Storm Client (<2.8.6) allows authenticated users to achieve RCE via unsafe deserialization in Nimbus/Worker JVMs. Upgrade to 2.8.6 or restrict deserialization classes now! Details: https://radar.offseq.com/threat/cve-2026-35337-cwe-502-deserialization-of-untruste-675b4697 #OffSeq #ApacheStorm #Vuln
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
- Totolink
- A7100RU
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL: Totolink A7100RU 7.4cu.2313_b20191024 exposed to OS command injection via UploadFirmwareFile in /cgi-bin/cstecgi.cgi. Public exploit available — restrict access & monitor now. CVE-2026-6140 https://radar.offseq.com/threat/cve-2026-6140-os-command-injection-in-totolink-a71-8e1c7584 #OffSeq #Vulnerability #IoTSecurity
Overview
- Apache Software Foundation
- Apache Traffic Server
Description
Statistics
- 1 Post
Overview
- Rapid7
- Insight Agent
Description
Statistics
- 2 Posts
Fediverse
So it's not something random attackers can exploit, but if someone compromises the backend, they could own every Linux system running the agent. It's a high-impact scenario that shows how security tools themselves can become attack vectors.
https://www.sentinelone.com/vulnerability-database/cve-2026-4837/
2/2
Overview
- Apache Software Foundation
- Apache ActiveMQ Broker
- org.apache.activemq:activemq-broker
Description
Statistics
- 1 Post
Bluesky
Overview
- Apache Software Foundation
- Apache Tomcat
Description
Statistics
- 1 Post
Overview
- Dolibarr
- Dolibarr ERP/CRM
Description
Statistics
- 1 Post
Overview
- Totolink
- A7100RU
Description
Statistics
- 1 Post
Fediverse
🛑 CRITICAL: Totolink A7100RU (v7.4cu.2313_b20191024) suffers from unauthenticated OS command injection (CVE-2026-6154). Public exploit out, no patch yet. Isolate devices & check vendor updates. https://radar.offseq.com/threat/cve-2026-6154-os-command-injection-in-totolink-a71-87e9e42c #OffSeq #CVE20266154 #router #infosec