Security researchers identified six critical vulnerabilities (CVSS 9.0–10.0) across Alibaba Fastjson, Avada Core, industrial control systems, Joomla plugins, Schneider Electric SCADA, and VaahCMS, all exploitable under default configurations with no patches available yet.
26 social postsother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
CVE-2026-12981: CRITICAL vuln in CAFEHAUS API plugin ≤1.0.0 (WordPress). No authentication on password updates — attackers can reset any user password, including admins. Remove/disable plugin until fixed. https:// radar.offseq.com/threat/cve-20 26-12981-cwe-269-improper-privilege-management-in-cafehaus-api-47b92cb62ac9c312 # OffSeq # WordPress # Vulnerability # PrivilegeEscalation
CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. https:// radar.offseq.com/threat/cve-20 26-10818-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpforms-wpforms-pro-98bc8d14f7da8c03 # OffSeq # WordPress # Infosec # CVE202610818
🔴 New security advisory: CVE-2026-16812 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www. yazoul.net/advisory/cve/cve-20 26-16812-vco-orchestator-unauth-access-exploited # Cybersecurity # SecurityPatchin
🔴 New security advisory: CVE-2026-55579 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www. yazoul.net/advisory/cve/cve-20 26-55579-pheditor-hardcoded-admin-rce-poc # InfoSec # ZeroDay # ThreatIntel
CVE-2026-16610: ASE Pro plugin (≤8.9.0) for WordPress suffers CRITICAL RCE via recursive_html. Unauth attackers can execute code if [post_cf_form] is public. Update/disable plugin ASAP. https:// radar.offseq.com/threat/cve-20 26-16610-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-ase-admin-and-site-9666b4d559bc4aea # OffSeq # WordPress # CVE2026_16610 # Security
CRITICAL SSRF vuln (CVE-2026-14529) in IBM WebSphere App Server 9.0, 8.5, and Liberty 17.0.0.3 – 26.0.0.8 if SIP (sipServlet-1.1) is enabled. Review SIP use, disable if possible. Details: https:// radar.offseq.com/threat/ibm-we bsphere-application-server-90-and-85-and-ibm-websphere-application-server-liberty-17003-through-99257a570e2e63d4 # OffSeq # IBM # WebSphere # SSRF # CVE202614529
CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. https:// radar.offseq.com/threat/cve-20 26-47876-cwe-787-out-of-bounds-write-in-vmware-cloud-foundation-111066eb743eb8c6 # OffSeq # VMware # InfoSec # CVE202647876