Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
📰 Ruby on Rails Patches Critical RCE Flaw (CVE-2026-66066)
Ruby on Rails patches critical RCE vulnerability CVE-2026-66066 (CVSS 9.5). The flaw in Active Storage allows arbitrary file read via crafted image uploads, leading to potential RCE. Update immediately. #RubyOnRails #CVE #CyberSecurity
Overview
- FreeRDP
- FreeRDP
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: https://radar.offseq.com/threat/freerdp-before-3290-contains-a-buffer-over-disclosure-vulnerability-in-the-gateway-websocket-transport-67044e0124c23808 #OffSeq #FreeRDP #CVE202667292 #AppSec
Overview
- pronamic
- Pronamic Pay
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-16635 - Privilege Escalation in Pronamic Pay WordPress plugin. Auth Subscriber+ can set any role via Gravity Forms. CVSS 8.8. Unpatched - disable or restrict until fix. #CVE #WordPress #infosec
Overview
- better-auth
- better-auth
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-67333 - High sev URL scheme bypass in Better-Auth. javascript: redirect_uri allows XSS on consent pages. CVSS 7.2. No patch yet, block untrusted clients now. #CVE #BetterAuth #infosec
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- wpchill
- Kali Forms — Contact Form & Drag-and-Drop Builder
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-16144 - Critical RCE in Kali Forms WordPress plugin. Unauthenticated code execution via call_user_func. CVSS 8.1. No patch available - disable plugin now. #CVE #WordPress #infosec
Overview
- better-auth
- scim
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-67331 - Critical auth flaw in Better-Auth SCIM. Unbound providers let attackers steal tokens, hijack SCIM API access. CVSS 8.3. Unpatched - update immediately if affected. #CVE #infosec #BetterAuth
Overview
Description
Statistics
- 1 Post
Overview
- better-auth
- better-auth
Description
Statistics
- 1 Post
Fediverse
CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ https://radar.offseq.com/threat/better-auth-versions-before-1611-contain-insecure-cryptographic-defaults-in-the-oidcprovider-and-mcp-eb22076a221f3a81 #OffSeq #CVE202667336 #OAuth #Security
Overview
Description
Statistics
- 1 Post