Overview
- Tautulli
- Tautulli
Description
Statistics
- 1 Post
Fediverse
CVE-2026-49995 Tautulli stored XSS via newsletter cron field, CVSS 4.8. Admin opening the config modal triggers script execution. Patch under review, update to 2.17.2 when ready. https://www.valtersit.com/cve/CVE-2026-49995/ #CVE #infosec
Overview
- NetScaler
- ADC
Description
Statistics
- 1 Post
Fediverse
🚨 Critical Citrix NetScaler Vulnerability Disclosed
Citrix has disclosed CVE-2026-107406, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway, with a CVSS 4.0 score of 9.5.
The vulnerability could potentially allow remote code execution or denial of service on affected systems.
Exploitation requires specific SAML Service Provider or Identity Provider configurations, depending on the installed version.
#SecPoint #Citrix #NetScaler #CyberSecurity #VulnerabilityManagement
Overview
- TomWright
- dasel
Description
Statistics
- 1 Post
Fediverse
CVE-2026-62866 Dasel 3.0.0-3.11.2 (CVSS 6.2): a selector ending in whitespace passes an unchecked index in parseCurRune, causing an out-of-range panic that kills the process. Denial of service. Patched in 3.11.2, update now. https://www.valtersit.com/cve/CVE-2026-62866/ #CVE #infosec #Dasel
Overview
Description
Statistics
- 1 Post
Fediverse
CVE-2026-93012: Email::Sender::Transport::Sendmail before 2.602 lets envelope addresses reach the shell on Windows, enabling command execution. CVSS 9.8. Patch available. Update now. https://www.valtersit.com/cve/CVE-2026-93012/ #CVE #Perl #infosec
Overview
Description
Statistics
- 1 Post
Fediverse
CVE-2026-86717 (CRITICAL) targets Insurify WP plugin ≤1.0. Missing auth & nonce checks in AJAX lets unauth users delete WordPress options — site can be taken offline, user roles wiped. Disable or restrict plugin. https://radar.offseq.com/threat/cve-2026-86717-cwe-862-missing-authorization-in-insurify-d0d6b23b34928b39 #OffSeq #WordPress #CVE202686717 #infosec
Overview
- ThemeREX Group
- Let's Play
- playhockey
Description
Statistics
- 1 Post
Fediverse
CVE-2026-93935: ThemeREX Let's Play playhockey ≤1.1.15 affected by CRITICAL deserialization flaw (CWE-502). Enables remote object injection and full compromise. Patch pending — monitor vendor updates & restrict plugin use. https://radar.offseq.com/threat/deserialization-of-untrusted-data-vulnerability-in-themerex-group-lets-play-playhockey-allows-object-6b9f9ae91683af07 #OffSeq #CVE202693935 #WordPress #Infosec
Overview
- Axiomthemes
- Balance
- balance
Description
Statistics
- 1 Post
Fediverse
CVE-2026-93945: CRITICAL object injection via deserialization in Axiomthemes Balance (<=1.12.0). Full compromise risk — no patch yet. Check vendor guidance & mitigate if possible. https://radar.offseq.com/threat/deserialization-of-untrusted-data-vulnerability-in-axiomthemes-balance-balance-allows-object-f802d57a201c6245 #OffSeq #CVE202693945 #WordPress #Vuln #Infosec
Overview
- Qualcomm, Inc.
- Snapdragon
Description
Statistics
- 1 Post
Fediverse
CVE-2026-25254 Qualcomm improper auth leads to RCE via SocketIO. CVSS 9.8, patch status unknown. Treat as unpatched and restrict exposure now. https://www.valtersit.com/cve/CVE-2026-25254/ #CVE #infosec #Qualcomm
Overview
Description
Statistics
- 1 Post
Fediverse
Piotnet Forms <=1.0.30 impacted by HIGH severity stored XSS (CVE-2026-96227). Unauthenticated file uploads allow arbitrary JS execution. Restrict uploads & validate files. Await vendor patch. Details: https://radar.offseq.com/threat/cve-2026-96227-cwe-79-cross-site-scripting-xss-in-piotnet-forms-5a16ad1f17e57c01 #OffSeq #XSS #WordPress #Infosec
Overview
Description
Statistics
- 1 Post