CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. https://radar.offseq.com/threat/cve-2026-66897-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-b6ae23dfc47f5562 #OffSeq #LXD #CVE #Linux
OffSequence
OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.
CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. https://radar.offseq.com/threat/cve-2026-78168-improper-authentication-in-efm-iptime-t24000m-bfa2e716a3fcf0b6 #OffSeq #CVE #IoTSecurity #Exploit
4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-78211-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-91902877a695e366 #OffSeq #CVE202678211 #Vuln #BlueTeam
CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. https://radar.offseq.com/threat/cve-2026-78169-stack-based-buffer-overflow-in-utt-hiper-1250gw-b9697a669a575a95 #OffSeq #CVE #Infosec #IoT
CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. https://radar.offseq.com/threat/cve-2026-16149-cwe-269-improper-privilege-management-in-marc4-security-hardener-a438d1f2a5360b5c #OffSeq #WordPress #Vulnerability #Infosec
CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files & export entire container filesystems via Docker API. Restrict access, check vendor guidance. https://radar.offseq.com/threat/cve-2026-78122-insufficient-granularity-of-access-control-in-tecnativa-docker-socket-proxy-6e8e6aaf03a19cce #OffSeq #Docker #Infosec #Vuln
CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. https://radar.offseq.com/threat/cve-2026-77995-cwe-639-authorization-bypass-through-user-controlled-key-in-miniorangecom-miniorange-0e8da876ce4c7e51 #OffSeq #Joomla #Vuln #OAuth
CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. https://radar.offseq.com/threat/cve-2026-78568-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-52b70f977190d0ba #OffSeq #WordPress #SQLi #Vuln
CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. https://radar.offseq.com/threat/cve-2026-78267-cwe-266-incorrect-privilege-assignment-in-cozmoslabs-translatepress-ba0caba45d17d814 #OffSeq #WordPress #Vuln #PrivilegeEscalation
CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. https://radar.offseq.com/threat/cve-2026-78265-cwe-502-deserialization-of-untrusted-data-in-nexcess-the-events-calendar-3dd3af18547313e0 #OffSeq #WordPress #Infosec #CVE2026_78265
KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. https://radar.offseq.com/threat/cve-2026-78570-cwe-269-improper-privilege-management-in-klbtheme-total-donations-fcfd73df270b6d37 #OffSeq #WordPress #CVE #Vuln
CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. https://radar.offseq.com/threat/cve-2026-77994-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-d508026cac86e490 #OffSeq #Joomla #SQLInjection #Infosec
CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! https://radar.offseq.com/threat/cve-2026-78251-cwe-798-use-of-hard-coded-credentials-in-dji-neo-98f2d4e34b35b2e0 #OffSeq #CVE2026_78251 #DJI #DroneSec
CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE
CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. https://radar.offseq.com/threat/cve-2026-8445-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-42aabed1c30bf24b #OffSeq #XSS #AppSec #CVE20268445
CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: https://radar.offseq.com/threat/cve-2026-7808-improper-input-validation-in-emilstenstrom-justhtml-86dd54d29e0645e9 #OffSeq #CVE20267808 #infosec #XSS
CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https://radar.offseq.com/threat/cve-2026-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe #OffSeq #CVE202678676 #git #infosec
Privilege escalation vuln (CRITICAL, CVSS 9.8) in MVPThemes Jawn WordPress theme (≤1.4.2): CVE-2026-78477 lets unauth users elevate to admin. Review deployments & monitor for fixes. https://radar.offseq.com/threat/cve-2026-78477-cwe-266-incorrect-privilege-assignment-in-mvpthemes-jawn-ec6b466fa423dd3f #OffSeq #WordPress #Vuln #PrivilegeEscalation
CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. https://radar.offseq.com/threat/cve-2026-13214-memory-safety-in-zephyrproject-zephyr-042d724fd93f46c2 #OffSeq #Zephyr #CVE202613214 #IoTSec
CVE-2026-72702 | Grav CMS <2.0.16 | CRITICAL (CVSS 9.3): Origin validation bypass via weak Referer checks lets attackers defeat CSRF defenses. No fix confirmed — use extra controls, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-72702-origin-validation-error-in-getgrav-grav-4b8f0ff64f944a7c #OffSeq #CVE202672702 #GravCMS #WebSecurity