Text to Speech for WP plugin ≤1.9.8 has HIGH severity flaw: hardcoded MySQL creds allow attackers write access to telemetry DB. Disable or restrict until patched. radar.offseq.com/threat/cve-2026-1233-cwe... #OffSeq #WordPress #Vuln
Export All URLs WP plugin <5.1: HIGH severity info exposure. CSV exports with private URLs can be brute-forced — no auth needed. Restrict uploads dir & upgrade ASAP. radar.offseq.com/threat/cve-2026-2696-cwe... #OffSeq #WordPress #Vuln
NSA Ghidra <12.0.3 hit by HIGH severity OS command injection. Malicious binaries can execute code if analysts click crafted UI annotations. Upgrade to 12.0.3+ ASAP. Details: radar.offseq.com/threat/cve-2026-4946-cwe... #OffSeq #Ghidra #Vuln
ISC Kea DHCP flaw (CVE-2026-3608, HIGH) lets remote attackers crash services via crafted messages. Audit deployments, restrict API/HA access, and monitor for threats. More: radar.offseq.com/threat/cve-2026-3608-cwe... #OffSeq #Vuln #DHCP
Tenda FH451 v1.0.0.9 hit by HIGH severity stack overflow (CVE-2026-4534). Remote attackers can execute code. Patch ASAP or restrict access to /goform/WrlExtraSet. PoC exploit is public. More: radar.offseq.com/threat/cve-2026-4534-sta... #OffSeq #Vuln...
CRITICAL XSS in parallax jsPDF (<4.2.1): Exploitable via crafted PDF options — scripts run in victim's browser on open. Upgrade to 4.2.1+ now! radar.offseq.com/threat/cve-2026-31938-cw... #OffSeq #XSS #Vuln
GLPI 'fields' plugin <1.23.3 has a CRITICAL flaw — privileged users can run arbitrary PHP code. Upgrade to 1.23.3+ & audit permissions now! radar.offseq.com/threat/cve-2026-23489-cw... #OffSeq #GLPI #vuln
dagu <2.2.4 faces a CRITICAL path traversal (CVE-2026-31886) — attackers can delete /tmp & disrupt systems. Upgrade to 2.2.4+ or patch input validation ASAP! radar.offseq.com/threat/cve-2026-31886-cw... #OffSeq #dagu #vuln
CRITICAL: DeltaWW COMMGR2 hit by stack buffer overflow (CVE-2026-3630, CVSS 9.8). Remote RCE possible, no patch yet. Segment networks & monitor now! radar.offseq.com/threat/cve-2026-3630-cwe... #OffSeq #ICS #Vuln
CRITICAL: WWBN AVideo < 24.0 hit by SQL Injection via JSON POST (catName). Unauthenticated exploit risks full DB compromise. Upgrade to v24.0+ or add WAF rules now! radar.offseq.com/threat/cve-2026-28501-cw... #OffSeq #Vuln #SQLInjection
OpenSTAManager <=2.9.8 faces a CRITICAL bug: CVE-2026-27012 allows attackers to gain admin rights by bypassing authentication. Restrict access & monitor activity until patched! radar.offseq.com/threat/cve-2026-27012-cw... #OffSeq #vuln #CVE202627012
WeGIA <3.6.5 hit by CRITICAL OS command injection (CVSS 10). RCE possible via backup restore + admin access (auth bypass possible). Upgrade to 3.6.5 now for protection! radar.offseq.com/threat/cve-2026-28409-cw... #OffSeq #vuln #CVE202628409
🚨 CRITICAL: Xerox FreeFlow Core (≤8.0.7) hit by RCE flaw (CVE-2026-2251). Path traversal enables unauthenticated attacks. Upgrade to 8.1.0 now! radar.offseq.com/threat/cve-2026-2251-cwe... #OffSeq #Vuln #PrintSecurity
Tenda AC8 routers (16.03.34.06) face HIGH severity stack buffer overflow — public exploit out. Restrict access, monitor /cgi-bin/UploadCfg, and prep for patches. 🔒 radar.offseq.com/threat/cve-2026-3044-sta... #OffSeq #RouterSecurity #Vuln
CRITICAL: Pterodactyl Panel <1.12.1 allows node token abuse for full server access & deletion. Upgrade to 1.12.1 & secure your tokens now! 🚨 radar.offseq.com/threat/cve-2026-26016-cw... #OffSeq #Pterodactyl #Vuln
HIGH severity alert: Windows Admin Center 1809.0 flaw (CVE-2026-26119) lets authorized users escalate privileges. No patch yet — restrict access & monitor for abuse. radar.offseq.com/threat/cve-2026-26119-cw... #OffSeq #WindowsAdminCenter #Vuln
🚨 HIGH-severity SSRF bug in NETAPP StorageGRID — SSO + Entra ID lets authenticated users disrupt configs or access. Upgrade or disable SSO ASAP! radar.offseq.com/threat/cve-2026-22048-91... #OffSeq #NETAPP #Vuln
OpenS100 CRITICAL vuln: RCE via Lua in S-100 viewer. Malicious catalogues can run arbitrary code if imported. Block untrusted files, sandbox apps, patch ASAP. radar.offseq.com/threat/cve-2026-22208-cw... #OffSeq #CVE202622208 #vuln
SOLIDWORKS eDrawings 2025 – 2026 SP0: HIGH risk from CVE-2026-1333. Malicious EPRT files can trigger code execution. Patch, restrict file handling, and educate users. radar.offseq.com/threat/cve-2026-1333-cwe... #OffSeq #SOLIDWORKS #vuln
CRITICAL: JUNG eNet SMART HOME server (2.2.1, 2.3.1) vuln lets users escalate to admin via /jsonrpc/management. Restrict access & monitor for abuse until patch. radar.offseq.com/threat/cve-2026-26369-im... #OffSeq #SmartHome #Vuln
CRITICAL heap out-of-bounds write in ROS 2 navigation2 (≤1.3.11) via /initialpose lets attackers crash or exploit robots. Isolate DDS domains & monitor traffic. Patch when available! radar.offseq.com/threat/cve-2026-26011-cw... #OffSeq #ROS2 #vuln
CRITICAL: AdForest WordPress theme flaw (CVE-2026-1729) lets attackers bypass login as any user. No patch yet — disable vulnerable OTP, use WAF rules, and monitor closely. Details: radar.offseq.com/threat/cve-2026-1729-cwe... #OffSeq #WordPress #Vuln...
CRITICAL: CVE-2026-26009 in karutoil catalyst (<11980aaf3f46315b02777f325ba02c56b110165d) enables cluster-wide root RCE via template perms. Patch now & restrict access! 🚨 radar.offseq.com/threat/cve-2026-26009-cw... #OffSeq #vuln #karutoil
CRITICAL: frangoteam FUXA (<1.2.10) has a hard-coded key flaw (CVE-2026-25894) — remote attackers can get admin access & run code. Upgrade to 1.2.10+ and audit JWT secrets now! radar.offseq.com/threat/cve-2026-25894-cw... #OffSeq #ICS #Vuln
Leaking your private data from the cloud with CPU vulnerabilities
www.youtube.com/watch?v=_fPa...
#l1tf #halfspectre #vuln
It's been a busy couple of weeks for #AppSec; including ongoing named vulns like React2Shell and MongoBleed, because what's a #vuln without a Brand™? Also AdonisJS, RustFS, and the Shai-Hulud that didn't happen
📑 READ more: buff.ly/xbVornQ
#JavaScript #npm #MongoDB #React #Rust
Security threat visualization
CRITICAL: CVE-2025-14733 in WatchGuard Fireware OS VPNs (11.10.2–12.11.5, 2025.1–2025.1.3) allows remote code exec. Disable IKEv2 dynamic peers or limit exposure until patched. radar.offseq.com/threat/cve-2025-14733-cw... #OffSeq #WatchGuard #Vuln
Security threat visualization
Ninja Forms for WordPress hit by a HIGH severity flaw (CVE-2025-11924) exposing form data via REST API. Patch 3.13.1 is ineffective. Restrict API access & monitor tokens now! Details: radar.offseq.com/threat/cve-2025-11924-cw... #OffSeq #WordPress #Vuln