Overview
Description
Statistics
- 4 Posts
Fediverse
⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data…
Bluesky
Overview
- vBulletin
- vBulletin
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
🚨 New advisory was just published!
An independent security researcher working with SSD Secure Disclosure has identified a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server. The vulnerability has been assigned CVE-2026-61511. Read our full advisory: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
🚨‼️ CVE-2026-61511: A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server.
CVSS: 9.8
Exploit: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
A public PoC now targets CVE-2026-61511, a vBulletin preauth RCE via runMaths eval. Patch to vBulletin 6.2.2 to block remote code execution.
#vBulletin #CVE202661511 #RCE #PreauthRCE #RemoteCodeExecution #PoC #WebSecurity #Cybersecurity
Overview
- Alibaba
- Fastjson
Description
Statistics
- 3 Posts
Fediverse
⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.
Bluesky
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 3 Posts
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux https://www.it-connect.fr/refluxfs-cve-2026-64600-faille-xfs-acces-root-linux/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Linux
Overview
Description
Statistics
- 3 Posts
Fediverse
(CISA TS-SOC) CVE-2025-68686 – Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Severity: MEDIUM Impact Summary: Exposure of sensitive information to unauthorized actors due to patch bypass, potentially leaking data after prior compromise....
An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS.
KEV confirmed.
CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.
#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-49176 is a Windows WalletService elevation of privilege flaw. Full details and a public PoC exploit are out, so patch Windows now.
#CVE202649176 #WalletService #Windows #PrivilegeEscalation #EoP #PoC #Microsoft
Overview
Description
Statistics
- 2 Posts
- 31 Interactions
Fediverse
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
Overview
Description
Statistics
- 2 Posts
- 31 Interactions
Fediverse
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
Overview
Description
Statistics
- 1 Post
- 1 Interaction