Overview
- openmrs
- openmrs-core
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL OpenMRS Core vuln: Path traversal (CVE-2026-40076, CVSS 9.4) lets auth users upload .omod files to gain RCE via crafted ZIPs. Affects ≤2.7.8, 2.8.0 – 2.8.5. Upgrade to 2.7.9/2.8.6+ now! https://radar.offseq.com/threat/cve-2026-40076-cwe-22-improper-limitation-of-a-pat-ec2c9c3f #OffSeq #OpenMRS #Vuln
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
- CODESYS
- Control RTE (SL)
Description
Statistics
- 1 Post
Fediverse
#OT #Advisory VDE-2026-005
ifm: Multiple Vulnerabilities in CR3171
The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.
#CVE CVE-2025-41659, CVE-2025-41691, CVE-2025-41658
https://certvde.com/en/advisories/vde-2026-005/
#CSAF https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-005.json
Overview
- CODESYS
- Control RTE (SL)
Description
Statistics
- 1 Post
Fediverse
#OT #Advisory VDE-2026-005
ifm: Multiple Vulnerabilities in CR3171
The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.
#CVE CVE-2025-41659, CVE-2025-41691, CVE-2025-41658
https://certvde.com/en/advisories/vde-2026-005/
#CSAF https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-005.json
Overview
- CODESYS
- Runtime Toolkit
Description
Statistics
- 1 Post
Fediverse
#OT #Advisory VDE-2026-005
ifm: Multiple Vulnerabilities in CR3171
The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.
#CVE CVE-2025-41659, CVE-2025-41691, CVE-2025-41658
https://certvde.com/en/advisories/vde-2026-005/
#CSAF https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-005.json
Overview
- Crafter Software
- Crafter CMS
Description
Statistics
- 1 Post
Fediverse
The Crafter CMS Groovy sandbox has been patched three times. CVE-2021-23259, CVE-2022-40635, CVE-2025-6384.
Our team went back in anyway and found 14 distinct RCE bypass techniques in v5.0.0: AST Transformations, SpelExpressionParser, GroovyShell, Template Engines, XStream, BeanShell, Jakarta EL, Commons Exec, Object Factories, MBeans, and more.
The sandbox wasn't broken in one place. It was porous.
CVE-2026-1770 (PTT-2025-022). Full PoC: https://pentest-tools.com/research
Overview
- CrafterCMS
- CrafterCMS
- Studio
Description
Statistics
- 1 Post
Fediverse
The Crafter CMS Groovy sandbox has been patched three times. CVE-2021-23259, CVE-2022-40635, CVE-2025-6384.
Our team went back in anyway and found 14 distinct RCE bypass techniques in v5.0.0: AST Transformations, SpelExpressionParser, GroovyShell, Template Engines, XStream, BeanShell, Jakarta EL, Commons Exec, Object Factories, MBeans, and more.
The sandbox wasn't broken in one place. It was porous.
CVE-2026-1770 (PTT-2025-022). Full PoC: https://pentest-tools.com/research
Overview
- CrafterCMS
- CrafterCMS
- Studio
Description
Statistics
- 1 Post
Fediverse
The Crafter CMS Groovy sandbox has been patched three times. CVE-2021-23259, CVE-2022-40635, CVE-2025-6384.
Our team went back in anyway and found 14 distinct RCE bypass techniques in v5.0.0: AST Transformations, SpelExpressionParser, GroovyShell, Template Engines, XStream, BeanShell, Jakarta EL, Commons Exec, Object Factories, MBeans, and more.
The sandbox wasn't broken in one place. It was porous.
CVE-2026-1770 (PTT-2025-022). Full PoC: https://pentest-tools.com/research
Overview
- Crafter Software
- Crafter CMS
Description
Statistics
- 1 Post
Fediverse
The Crafter CMS Groovy sandbox has been patched three times. CVE-2021-23259, CVE-2022-40635, CVE-2025-6384.
Our team went back in anyway and found 14 distinct RCE bypass techniques in v5.0.0: AST Transformations, SpelExpressionParser, GroovyShell, Template Engines, XStream, BeanShell, Jakarta EL, Commons Exec, Object Factories, MBeans, and more.
The sandbox wasn't broken in one place. It was porous.
CVE-2026-1770 (PTT-2025-022). Full PoC: https://pentest-tools.com/research