Elektrine lite

← Feed

OffSequence

offseq@infosec.exchange

<p>OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.</p>

Posts

  • Post #4573737

    CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener &amp;lt;=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. https://radar.offseq.com/threat/cve-2026-16149-cwe-269-improper-privilege-management-in-marc4-security-hardener-a438d1f2a5360b5c #OffSeq #WordPress #Vulnerability #Infosec

  • Post #4573736

    CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files &amp;amp; export entire container filesystems via Docker API. Restrict access, check vendor guidance. https://radar.offseq.com/threat/cve-2026-78122-insufficient-granularity-of-access-control-in-tecnativa-docker-socket-proxy-6e8e6aaf03a19cce #OffSeq #Docker #Infosec #Vuln

  • Post #4573735

    CVE-2026-8445: EmilStenstrom justhtml &amp;lt;=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. https://radar.offseq.com/threat/cve-2026-8445-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-42aabed1c30bf24b #OffSeq #XSS #AppSec #CVE20268445

  • Post #4573734

    CVE-2026-7808 | justhtml &amp;lt;1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: https://radar.offseq.com/threat/cve-2026-7808-improper-input-validation-in-emilstenstrom-justhtml-86dd54d29e0645e9 #OffSeq #CVE20267808 #infosec #XSS

  • Post #4573733

    CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access &amp;amp; monitor /goform/aspRemoteApConfTempSend traffic. https://radar.offseq.com/threat/cve-2026-78169-stack-based-buffer-overflow-in-utt-hiper-1250gw-b9697a669a575a95 #OffSeq #CVE #Infosec #IoT

  • Post #4573732

    4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access &amp;amp; monitor closely. https://radar.offseq.com/threat/cve-2026-78211-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-91902877a695e366 #OffSeq #CVE202678211 #Vuln #BlueTeam

  • Post #4573731

    CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. https://radar.offseq.com/threat/cve-2026-78168-improper-authentication-in-efm-iptime-t24000m-bfa2e716a3fcf0b6 #OffSeq #CVE #IoTSecurity #Exploit

  • Post #4573730

    CVE-2026-78251 (CRITICAL): DJI Neo &amp;amp; related drones have hard-coded FTP creds, letting attackers fill storage &amp;amp; disrupt logging/updates via network or USB. Patch required! https://radar.offseq.com/threat/cve-2026-78251-cwe-798-use-of-hard-coded-credentials-in-dji-neo-98f2d4e34b35b2e0 #OffSeq #CVE2026_78251 #DJI #DroneSec

  • Post #4573729

    CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. https://radar.offseq.com/threat/cve-2026-77994-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-d508026cac86e490 #OffSeq #Joomla #SQLInjection #Infosec

  • Post #4573728

    CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions &amp;amp; avoid untrusted images. Patch status unknown. https://radar.offseq.com/threat/cve-2026-66897-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-b6ae23dfc47f5562 #OffSeq #LXD #CVE #Linux

  • Post #4573727

    CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite &amp;lt;10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts &amp;amp; files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE

  • Post #4573726

    CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. https://radar.offseq.com/threat/cve-2026-77995-cwe-639-authorization-bypass-through-user-controlled-key-in-miniorangecom-miniorange-0e8da876ce4c7e51 #OffSeq #Joomla #Vuln #OAuth

  • Post #4573725

    CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress &amp;lt;=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. https://radar.offseq.com/threat/cve-2026-78267-cwe-266-incorrect-privilege-assignment-in-cozmoslabs-translatepress-ba0caba45d17d814 #OffSeq #WordPress #Vuln #PrivilegeEscalation

  • Post #4573724

    CRITICAL CVE-2026-78265: Nexcess The Events Calendar &amp;lt;=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. https://radar.offseq.com/threat/cve-2026-78265-cwe-502-deserialization-of-untrusted-data-in-nexcess-the-events-calendar-3dd3af18547313e0 #OffSeq #WordPress #Infosec #CVE2026_78265

  • Post #4573723

    CVE-2026-78676 | GitPython &amp;lt;3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https://radar.offseq.com/threat/cve-2026-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe #OffSeq #CVE202678676 #git #infosec

  • Post #4573722

    CVE-2026-72702 | Grav CMS &amp;lt;2.0.16 | CRITICAL (CVSS 9.3): Origin validation bypass via weak Referer checks lets attackers defeat CSRF defenses. No fix confirmed — use extra controls, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-72702-origin-validation-error-in-getgrav-grav-4b8f0ff64f944a7c #OffSeq #CVE202672702 #GravCMS #WebSecurity

  • Post #4573721

    Privilege escalation vuln (CRITICAL, CVSS 9.8) in MVPThemes Jawn WordPress theme (≤1.4.2): CVE-2026-78477 lets unauth users elevate to admin. Review deployments &amp;amp; monitor for fixes. https://radar.offseq.com/threat/cve-2026-78477-cwe-266-incorrect-privilege-assignment-in-mvpthemes-jawn-ec6b466fa423dd3f #OffSeq #WordPress #Vuln #PrivilegeEscalation

  • Post #4573720

    CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, &amp;gt;=4.3.0 &amp;lt;4.4.2. Restrict untrusted WebSocket access. Patch status pending. https://radar.offseq.com/threat/cve-2026-13214-memory-safety-in-zephyrproject-zephyr-042d724fd93f46c2 #OffSeq #Zephyr #CVE202613214 #IoTSec

  • Post #4573719

    CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. https://radar.offseq.com/threat/cve-2026-78568-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-52b70f977190d0ba #OffSeq #WordPress #SQLi #Vuln

  • Post #4573718

    KlbTheme Total Donations &amp;lt;=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin &amp;amp; monitor for advisories. https://radar.offseq.com/threat/cve-2026-78570-cwe-269-improper-privilege-management-in-klbtheme-total-donations-fcfd73df270b6d37 #OffSeq #WordPress #CVE #Vuln

  • Post #4491826

    CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access &amp; monitor activity. Details: https://radar.offseq.com/threat/cve-2026-13716-cwe-35-path-traversal-in-arcadia-technology-llc-crafty-controller-2cdd2d33980b3ceb #OffSeq #Vuln #CVE202613716

  • Post #4483631

    CVE-2026-16985: Squeeze WP plugin &lt;1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. https://radar.offseq.com/threat/cve-2026-16985-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-squeeze-a1de64d348b6591f #OffSeq #WordPress #CVE2026_16985 #infosec

  • Post #4445066

    CVE-2026-16594: WP Directory Kit &lt;1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles &amp; monitor logs. https://radar.offseq.com/threat/cve-2026-16594-cwe-200-information-exposure-in-wp-directory-kit-3d8a39f4c5fd7c8a #OffSeq #WordPress #CVE

  • Post #4440553

    CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin &lt;3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API &amp; admin privileges. Await patch. https://radar.offseq.com/threat/cve-2026-16955-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ai-72905be644e71053 #OffSeq #WordPress #CVE2026_16955 #Security

  • Post #4433076

    CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. https://radar.offseq.com/threat/cve-2026-54212-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-2e946f5b4b7b0ab5 #OffSeq #CVE #bufferOverflow #infosec

  • Post #4401648

    CRITICAL: Snowflake accounts hacked — no MFA, stolen creds from infostealer malware led to massive data theft (100M+ affected, $9.5M loss). All orgs: enforce MFA &amp; strong passwords. No CVE assigned. https://radar.offseq.com/threat/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks-21f9fb8717cf2802 #OffSeq #CloudSecurity #ThreatIntel

  • Post #4390619

    Kadence Memberships (stellarwp) ≤4.0.0 suffers CRITICAL vuln (CVE-2026-9273, CVSS 9.3): attackers can hijack any account by poisoning password reset links. Restrict reset features &amp; monitor for patches. https://radar.offseq.com/threat/cve-2026-9273-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-stellarwp-membership-10c6cffc948a3c97 #OffSeq #WordPress #Vuln #Security

  • Post #4388427

    FlowiseAI Flowise (&lt;3.1.3) has a CRITICAL vuln (CVE-2026-70478): unauthenticated POST endpoint leaks refreshed OAuth tokens if credential ID is known. Upgrade to 3.1.3+ ASAP. https://radar.offseq.com/threat/cve-2026-70478-cwe-200-exposure-of-sensitive-information-to-an-unauthorized-actor-in-flowiseai-flowise-2c912baff770743c #OffSeq #CVE202670478 #OAuth #infosec

  • Post #4387535

    CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint &amp; monitor traffic until patched. Details: https://radar.offseq.com/threat/cve-2026-70553-improper-control-of-generation-of-code-code-injection-in-maxsite-maxsite-cms-5161bdfb2e6804e9 #OffSeq #CVE #websecurity #RCE

  • Post #4372501

    CVE-2026-14804: CRITICAL (CVSS 9.1) in HUMANIST Digital HR v26.0 🛡️ Hard-coded cryptographic key (CWE-321) allows data exposure &amp; integrity loss. No official fix — limit access &amp; track vendor updates. https://radar.offseq.com/threat/cve-2026-14804-cwe-321-use-of-hard-coded-cryptographic-key-in-bilin-software-and-informatics-7feb29c78f0c5d49 #OffSeq #Vulnerability #CVE202614804