HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. https://radar.offseq.com/threat/cve-2026-92965-cwe-862-missing-authorization-in-tiktok-38fbb3b8076a5adb #OffSeq #WordPress #Vuln #Security
About This Hashtag
#vuln
51 posts
Last used 3h
#vuln
51 posts· Last used 3h
CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-13716-cwe-35-path-traversal-in-arcadia-technology-llc-crafty-controller-2cdd2d33980b3ceb #OffSeq #Vuln #CVE202613716
Kadence Memberships (stellarwp) ≤4.0.0 suffers CRITICAL vuln (CVE-2026-9273, CVSS 9.3): attackers can hijack any account by poisoning password reset links. Restrict reset features & monitor for patches. https://radar.offseq.com/threat/cve-2026-9273-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-stellarwp-membership-10c6cffc948a3c97 #OffSeq #WordPress #Vuln #Security
CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. https://radar.offseq.com/threat/cve-2026-17561-cwe-94-improper-control-of-generation-of-code-code-injection-in-innotim-software-30d176d2929ded6e #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam
Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. https://radar.offseq.com/threat/improper-access-control-in-azure-cosmos-db-allows-an-unauthorized-attacker-to-execute-code-over-a-db3b78e9f6a886eb #OffSeq #Azure #Vuln #CyberSecurity
CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. https://radar.offseq.com/threat/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw-b5d2b338dff8d1eb
#OffSeq #Vuln #TeamCity #CVE202663077
Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! https://radar.offseq.com/threat/cve-2026-7849-cwe-77-improper-neutralization-of-special-elements-used-in-a-command-command-injection-8b9703c63834cb6a #OffSeq #ICS #Vuln #CVE2026_7849
CVE-2026-16727 (HIGH): Race condition in ASUS Armoury Crate 5.4.1 lets local users escalate privileges via improper synchronization. No patch available. Limit local access & monitor systems. https://radar.offseq.com/threat/cve-2026-16727-cwe-362-concurrent-execution-using-shared-resource-with-improper-synchronization-race-75a81e87495a29e2 #OffSeq #CVE202616727 #ASUS #Vuln
SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. https://radar.offseq.com/threat/cve-2026-17458-server-side-request-forgery-in-mf-yang-openclaw-cn-a8d78509307a6c7f #OffSeq #SSRF #Vuln #mfyang
Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: https://radar.offseq.com/threat/cve-2026-57106-cwe-918-server-side-request-forgery-ssrf-in-microsoft-microsoft-purview-data-governance-0983080847f54f67 #OffSeq #Vuln #SSRF #Microsoft #CyberSec
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: https://radar.offseq.com/threat/cve-2026-56191-cwe-287-improper-authentication-in-microsoft-microsoft-exchange-online-2fb5560625ca8222 #OffSeq #CVE202656191 #ExchangeOnline #Vuln
CVE-2026-42933: CRITICAL unintended proxy vuln (CVSS 10) in Pronetiqs Panduit Intravue ≤3.2.1a14 lets attackers bypass OT segmentation. No patch yet — restrict access & monitor vendor. https://radar.offseq.com/threat/cve-2026-42933-cwe-441-unintended-proxy-or-intermediary-confused-deputy-in-pronetiqs-panduit-intravue-95925181c2d7dbb4 #OffSeq #OTSecurity #Vuln #CVE202642933
CVE-2026-65907: CRITICAL RCE in JetBrains TeamCity (CVSS 9.1). Affects <2026.1.2, <2025.11.6. Exploitable via Git VCS roots — no patch yet. Restrict access, minimize Git user privileges. More info: https://radar.offseq.com/threat/cve-2026-65907-cwe-94-in-jetbrains-teamcity-0b7d157127b512e7 #OffSeq #TeamCity #Vuln #RCE
CVE-2026-46738: Dell PowerProtect Data Manager <20.2.0.0 faces a CRITICAL REST API input validation vuln. High privileged remote attackers can escalate privileges. Restrict API access & monitor privileged accounts. https://radar.offseq.com/threat/dell-powerprotect-data-manager-versions-prior-to-20200-contains-an-improper-input-validation-f763e60bc08bcc57 #OffSeq #Dell #CVE202646738 #Vuln
Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. https://radar.offseq.com/threat/gitea-public-only-repository-tokens-can-update-private-pr-head-branches-cve-2026-58443-d058444d84b9595a #OffSeq #Gitea #Vuln #CVE202658443
Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). https://radar.offseq.com/threat/critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware-gang-32a4cdf9eafc03de #OffSeq #PANOS #Ransomware #Vuln
FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: https://radar.offseq.com/threat/cve-2026-53595-cwe-178-improper-handling-of-case-sensitivity-in-freescout-help-desk-freescout-3a27bed6e9e122c1 #OffSeq #CVE202653595 #infosec #vuln
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln