Overview
Description
Statistics
- 1 Post
Fediverse
โ ๏ธ HIGH-severity: CVE-2026-12197 in Ruijie EG105G-P v2.340 enables remote command injection via /cgi-bin/luci/api/diagnose. No patch, exploit code public. Restrict access & monitor for updates. https://radar.offseq.com/threat/cve-2026-12197-command-injection-in-ruijie-eg105g--9776681e #OffSeq #Infosec #CVE #Vulnerability
Overview
- driftregion
- iso14229
Description
Statistics
- 1 Post
Fediverse
๐จ CVE-2026-54413 (HIGH, CVSS 7.8): Integer underflow in driftregion iso14229 โค0.9.0 lets remote attackers crash automotive, IoT, and industrial UDS servers via crafted 0x27 requests. Validate input, monitor traffic, and restrict access. https://radar.offseq.com/threat/cve-2026-54413-cwe-191-integer-underflow-wrap-or-w-c8e3fde3 #OffSeq #vuln #UDS #infosec
Overview
- multer
- multer
Description
Statistics
- 2 Posts
Fediverse
๐จ Medium-severity security fix in multer@2.2.0 and multer@3.0.0-alpha.2 just released!
Patches CVE-2026-5038. multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads.
https://github.com/expressjs/multer/security/advisories/GHSA-3p4h-7m6x-2hcm
Overview
- Apache Software Foundation
- Apache HTTP Server
Description
Statistics
- 1 Post
Fediverse
Overview
- OpenSolution
- Quick.CMS
Description
Statistics
- 1 Post
Fediverse
โ ๏ธ CVE-2026-11860 (HIGH): OpenSolution Quick.CMS vulnerable to deserialization of untrusted data over HTTP. Remote code execution possible if admin accesses panel. Upgrade to v6.8+ to enforce HTTPS and mitigate risk. https://radar.offseq.com/threat/cve-2026-11860-cwe-502-deserialization-of-untruste-3d43127c #OffSeq #infosec #vuln #php
Overview
Description
Statistics
- 1 Post
Fediverse
๐ HIGH severity: Buffer overflow in GALAYOU Y4 v1.0.0 (CVE-2026-12192). Exploitable via local network โ no patch or vendor response yet. Restrict network access & monitor for updates. https://radar.offseq.com/threat/cve-2026-12192-buffer-overflow-in-galayou-y4-555d7b50 #OffSeq #Vuln #IoTSecurity #BufferOverflow
Overview
Description
Statistics
- 1 Post
Fediverse
The Linux 6.18.35 longterm stable update gathers around 70 backported fixes. The headline is a patch for CVE-2026-43500 in rxrpc, which corrected pagecache corruption from in-place decryption of locally transmitted DATA packets via splice(). It also carries AMDGPU and AMDKFD memory-leak and NULL-pointer fixes, plus arm64 TLB-flush corrections. None of it is dramatic, which is how a longterm kernel should read. How do you decide when a point release is worth a reboot?
#Linux #kernel
Overview
- team-alembic
- ash_authentication
- ash_authentication
Description
Statistics
- 1 Post
Fediverse
๐จ CRITICAL: CVE-2026-49757 in ash_authentication lets attackers bypass auth by spoofing email in OAuth2/OIDC, risking local account takeover. Patch status unconfirmed โ check vendor advisory. Affected: v0.1.0, 5.0.0-rc.0. https://radar.offseq.com/threat/cve-2026-49757-cwe-290-authentication-bypass-by-sp-5df5a500 #OffSeq #CVE202649757 #OAuth2 #infosec
Overview
Description
Statistics
- 1 Post
Fediverse
I would say https://bumsrake.de/ / #CVE-2026-45257 / FreeBSD-SA-26:26.kTLS. sets a new standard in everything local priv esc bug website. period. I think even @GossiTheDog could appreciate it :D #hypetrain #infosec #freebsd #bugs
Overview
Description
Statistics
- 1 Post