Overview
- langflow-ai
- langflow
Description
Statistics
- 3 Posts
- 1 Interaction
Bluesky
Overview
- himmelblau-idm
- himmelblau
Description
Statistics
- 1 Post
- 11 Interactions
Overview
- Microsoft
- Windows 10 Version 21H2
Description
Statistics
- 1 Post
- 11 Interactions
Fediverse
This is my analysis (and PoC) for CVE-2026-20817, a privilege escalation in the Windows Error Reporting service.
👉 https://itm4n.github.io/cve-2026-20817-wersvc-eop/
Credit goes to Denis Faiustov and Ruslan Sayfiev for the discovery.
TL;DR A low privilege user could send an ALPC message to the WER service and coerce it to start a WerFault.exe process as SYSTEM with user-controlled arguments and options. I did not achieve arbitrary code execution, but perhaps someone knows how this can be done? 🤷♂️
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post
- 3 Interactions
Bluesky
Overview
- ConnectWise
- ScreenConnect
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
⚠️ HIGH severity: CVE-2026-4535 in Tenda FH451 (v1.0.0.9) — stack-based buffer overflow in /goform/WrlclientSet. Remote, unauthenticated code execution possible. Patch or mitigate now! https://radar.offseq.com/threat/cve-2026-4535-stack-based-buffer-overflow-in-tenda-8f2fc263 #OffSeq #vulnerability #IoT #bufferOverflow
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
⚠️ CRITICAL: Quest KACE vuln (CVE-2025-32975) under active exploitation, mainly in education. No patch yet — segment networks, monitor KACE activity, and restrict access. Global risk. Details: https://radar.offseq.com/threat/critical-quest-kace-vulnerability-potentially-expl-c5cd699f #OffSeq #Vulnerability #QuestKACE #Education
Overview
- tomdever
- wpForo Forum
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
wpForo Forum <= 2.4.14 - SQL Injection (CVE-2026-1581)
https://pentest-tools.com/vulnerabilities-exploits/wpforo-forum-2414-sql-injection_29049
Short summary: https://hackerworkspace.com/article/wpforo-forum-2-4-14-sql-injection-cve-2026-1581
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🔎 CVE-2026-4534 (HIGH, CVSS 8.7): Stack-based buffer overflow in Tenda FH451 (v1.0.0.9) lets remote attackers execute code. PoC exploit published. Patch/mitigate now — restrict access & monitor for attacks. Info: https://radar.offseq.com/threat/cve-2026-4534-stack-based-buffer-overflow-in-tenda-65a33e73 #OffSeq #Vulnerability #Tenda #InfoSec
Overview
- Wavlink
- WL-WN578W2
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
⚠️ CVE-2026-4543: Wavlink WL-WN578W2 (v221110) has a MEDIUM severity command injection flaw in /cgi-bin/firewall.cgi. No patch; public exploit exists. Isolate, restrict access, and monitor traffic urgently. https://radar.offseq.com/threat/cve-2026-4543-command-injection-in-wavlink-wl-wn57-50f96d33 #OffSeq #Infosec #Vulnerability #Router