Six critical zero-day vulnerabilities disclosed without patches

Security researchers identified six critical vulnerabilities (CVSS 9.0–10.0) across Alibaba Fastjson, Avada Core, industrial control systems, Joomla plugins, Schneider Electric SCADA, and VaahCMS, all exploitable under default configurations with no patches available yet.

26 social postsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

CVE-2026-16723: CRITICAL RCE in Alibaba Fastjson 1.2.68. Exploitable under default config — no patch yet. Avoid 1.2.68 & monitor vendor updates for mitigation. CVSS 9.0. https:// radar.offseq.com/thre

mastodon:infosec-exchangeother68d ago kagi ↗

CVE-2026-16723: CRITICAL RCE in Alibaba Fastjson 1.2.68. Exploitable under default config — no patch yet. Avoid 1.2.68 & monitor vendor updates for mitigation. CVSS 9.0. https:// radar.offseq.com/threat/cve-20 26-16723-cwe-20-improper-input-validation-in-alibaba-fastjson-939ed165aac7ce81 # OffSeq # infosec # CVE202616723 # remotecodeexecution

CRITICAL: CVE-2026-65471 enables unauthenticated CSRF attacks in Avada Core <=5.15.6. No mitigation yet — review your deployment status and monitor for fixes. https:// radar.offseq.com/threat/cve-20 2

mastodon:infosec-exchangeother68d ago kagi ↗

CRITICAL: CVE-2026-65471 enables unauthenticated CSRF attacks in Avada Core <=5.15.6. No mitigation yet — review your deployment status and monitor for fixes. https:// radar.offseq.com/threat/cve-20 26-65471-cwe-352-cross-site-request-forgery-csrf-in-avada-studio-avada-core-f1e19172d275ec0b # OffSeq # CSRF # AvadaCore # Vuln

CVE-2026-42933: CRITICAL unintended proxy vuln (CVSS 10) in Pronetiqs Panduit Intravue ≤3.2.1a14 lets attackers bypass OT segmentation. No patch yet — restrict access & monitor vendor. https:// radar.

mastodon:infosec-exchangeother68d ago kagi ↗

CVE-2026-42933: CRITICAL unintended proxy vuln (CVSS 10) in Pronetiqs Panduit Intravue ≤3.2.1a14 lets attackers bypass OT segmentation. No patch yet — restrict access & monitor vendor. https:// radar.offseq.com/threat/cve-20 26-42933-cwe-441-unintended-proxy-or-intermediary-confused-deputy-in-pronetiqs-panduit-intravue-95925181c2d7dbb4 # OffSeq # OTSecurity # Vuln # CVE202642933

CVE-2026-12981: CRITICAL vuln in CAFEHAUS API plugin ≤1.0.0 (WordPress). No authentication on password updates — attackers can reset any user password, including admins. Remove/disable plugin until fi

mastodon:infosec-exchangeother67d ago kagi ↗

CVE-2026-12981: CRITICAL vuln in CAFEHAUS API plugin ≤1.0.0 (WordPress). No authentication on password updates — attackers can reset any user password, including admins. Remove/disable plugin until fixed. https:// radar.offseq.com/threat/cve-20 26-12981-cwe-269-improper-privilege-management-in-cafehaus-api-47b92cb62ac9c312 # OffSeq # WordPress # Vulnerability # PrivilegeEscalation

CVE-2026-24727 (CRITICAL, CVSS 9.3): SUNNET Corporate Training Mgmt System v10.3 allows admins to upload ZIP files with executable code, enabling server command execution. No patch yet — restrict admi

mastodon:infosec-exchangeother67d ago kagi ↗

CVE-2026-24727 (CRITICAL, CVSS 9.3): SUNNET Corporate Training Mgmt System v10.3 allows admins to upload ZIP files with executable code, enabling server command execution. No patch yet — restrict admin access & monitor uploads. https:// radar.offseq.com/threat/cve-20 26-24727-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-sunnet-technology-co-ltd-fe23deeb060f5b6d # OffSeq # CVE20262472

CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: https:// radar.offseq.com/threat/cve-20

mastodon:infosec-exchangeother67d ago kagi ↗

CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: https:// radar.offseq.com/threat/cve-20 26-54120-cwe-20-improper-input-validation-in-microsoft-surface-management-services-203a5e59f513d748 🖥️ # OffSeq # infosec # Microsoft # CVE202654120

CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized lo

mastodon:infosec-exchangeother67d ago kagi ↗

CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. https:// radar.offseq.com/threat/cve-20 26-61884-cwe-288-in-tycon-systems-tpdin-monitor-web2-38fd252c1e4f018a # OffSeq # CVE # IoT # Infosec

CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: https:// radar.offse

mastodon:infosec-exchangeother67d ago kagi ↗

CVE-2026-48021 in med-united epa4all (<2026-05-20): CRITICAL TLS cert validation flaw lets attackers decrypt/modify patient records & tokens. Upgrade to 2026-05-20+ ASAP. Details: https:// radar.offseq.com/threat/cve-20 26-48021-cwe-295-improper-certificate-validation-in-med-united-epa4all-26e8e441c1a877ee # OffSeq # HealthcareSecurity # Vuln # CVE202648021

CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+

mastodon:infosec-exchangeother66d ago kagi ↗

CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. https:// radar.offseq.com/threat/cve-20 26-16766-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-9e7c09567b0712f8 # OffSeq # infosec # perl # vuln

CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https:// ra

mastodon:infosec-exchangeother66d ago kagi ↗

CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https:// radar.offseq.com/threat/cve-20 26-12503-cwe-59-improper-link-resolution-before-file-access-link-following-in-loytec-lip-me20xc-acfbe89cb621dc0e # OffSeq # Vulnerability # ICS # Loytec # CVE2026

CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is

mastodon:infosec-exchangeother66d ago kagi ↗

CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. https:// radar.offseq.com/threat/cve-20 26-10818-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpforms-wpforms-pro-98bc8d14f7da8c03 # OffSeq # WordPress # Infosec # CVE202610818

CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update whe

mastodon:infosec-exchangeother65d ago kagi ↗

CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. https:// radar.offseq.com/threat/cve-20 26-63720-improper-control-of-generation-of-code-code-injection-in-koxudaxi-datamodel-code-a0a27f1d30c87e2e # OffSeq # infosec # Python # CVE20266372

CVE-2026-17459: perwendel spark 2.9.0 – 2.9.4 affected by symlink following in staticFiles.externalLocation. Exploit public, MEDIUM severity. Restrict external resource access and monitor for patches.

mastodon:infosec-exchangeother65d ago kagi ↗

CVE-2026-17459: perwendel spark 2.9.0 – 2.9.4 affected by symlink following in staticFiles.externalLocation. Exploit public, MEDIUM severity. Restrict external resource access and monitor for patches. https:// radar.offseq.com/threat/cve-20 26-17459-symlink-following-in-perwendel-spark-e9c7a3ae8bd59674 # OffSeq # CVE202617459 # Java # Security

SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. https://

mastodon:infosec-exchangeother65d ago kagi ↗

SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. https:// radar.offseq.com/threat/cve-20 26-17458-server-side-request-forgery-in-mf-yang-openclaw-cn-a8d78509307a6c7f # OffSeq # SSRF # Vuln # mfyang

mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. https:// radar.offs

mastodon:infosec-exchangeother65d ago kagi ↗

mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. https:// radar.offseq.com/threat/cve-20 26-17457-information-disclosure-in-mf-yang-openclaw-cn-1d4fae9414fd0132 # OffSeq # Vuln # InfoSec # CVE202617457

🔴 New security advisory: CVE-2026-16812 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems •

mastodon:infosec-exchangeother64d ago kagi ↗

🔴 New security advisory: CVE-2026-16812 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www. yazoul.net/advisory/cve/cve-20 26-16812-vco-orchestator-unauth-access-exploited # Cybersecurity # SecurityPatchin

🔴 New security advisory: CVE-2026-55579 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems •

mastodon:infosec-exchangeother63d ago kagi ↗

🔴 New security advisory: CVE-2026-55579 affects multiple systems. • Impact: Remote code execution or complete system compromise possible • Risk: Attackers can gain full control of affected systems • Mitigation: Patch immediately or isolate affected systems Full breakdown: https://www. yazoul.net/advisory/cve/cve-20 26-55579-pheditor-hardcoded-admin-rce-poc # InfoSec # ZeroDay # ThreatIntel

CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. https:/

mastodon:infosec-exchangeother62d ago kagi ↗

CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. https:// radar.offseq.com/threat/cve-20 26-65883-cwe-502-deserialization-of-untrusted-data-in-aimy-extensionscom-aimy-captcha-less-form-dff78e8752eedd4a # OffSeq # Joomla # Exploit # RCE

CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. https:

mastodon:infosec-exchangeother62d ago kagi ↗

CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. https:// radar.offseq.com/threat/cve-20 26-0667-cwe-754-improper-check-for-unusual-or-exceptional-conditions-in-schneider-electric-09bef19ebc8e9eb8 # OffSeq # ICS # Vulnerability # SCADA

CVE-2026-67595 (CRITICAL): VaahCMS 2.0.0 – 2.3.4 ships with malicious JS in OTP email templates. Enables C2, keylogging, WhatsApp scraping, and remote page control. Avoid JS-enabled viewing until patc

mastodon:infosec-exchangeother62d ago kagi ↗

CVE-2026-67595 (CRITICAL): VaahCMS 2.0.0 – 2.3.4 ships with malicious JS in OTP email templates. Enables C2, keylogging, WhatsApp scraping, and remote page control. Avoid JS-enabled viewing until patched. https:// radar.offseq.com/threat/cve-20 26-67595-embedded-malicious-code-in-webreinvent-vaahcms-94fc0638a0fe22eb # OffSeq # Infosec # CVE202667595 # VaahCMS

CVE-2026-59952 | open-circle valibot <1.4.2 suffers from improper exception handling in flatten(), causing TypeErrors & potential DoS if attacker-controlled keys collide w/ Object.prototype methods. S

mastodon:infosec-exchangeother62d ago kagi ↗

CVE-2026-59952 | open-circle valibot <1.4.2 suffers from improper exception handling in flatten(), causing TypeErrors & potential DoS if attacker-controlled keys collide w/ Object.prototype methods. Severity: MEDIUM. Upgrade to 1.4.2+ https:// radar.offseq.com/threat/cve-20 26-59952-cwe-755-improper-handling-of-exceptional-conditions-in-open-circle-valibot-c7fe163cf2db3032 # OffSeq # Valibot # App

CVE-2026-16727 (HIGH): Race condition in ASUS Armoury Crate 5.4.1 lets local users escalate privileges via improper synchronization. No patch available. Limit local access & monitor systems. https://

mastodon:infosec-exchangeother62d ago kagi ↗

CVE-2026-16727 (HIGH): Race condition in ASUS Armoury Crate 5.4.1 lets local users escalate privileges via improper synchronization. No patch available. Limit local access & monitor systems. https:// radar.offseq.com/threat/cve-20 26-16727-cwe-362-concurrent-execution-using-shared-resource-with-improper-synchronization-race-75a81e87495a29e2 # OffSeq # CVE202616727 # ASUS # Vuln

CVE-2026-16610: ASE Pro plugin (≤8.9.0) for WordPress suffers CRITICAL RCE via recursive_html. Unauth attackers can execute code if [post_cf_form] is public. Update/disable plugin ASAP. https:// radar

mastodon:infosec-exchangeother62d ago kagi ↗

CVE-2026-16610: ASE Pro plugin (≤8.9.0) for WordPress suffers CRITICAL RCE via recursive_html. Unauth attackers can execute code if [post_cf_form] is public. Update/disable plugin ASAP. https:// radar.offseq.com/threat/cve-20 26-16610-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-ase-admin-and-site-9666b4d559bc4aea # OffSeq # WordPress # CVE2026_16610 # Security

CRITICAL SSRF vuln (CVE-2026-14529) in IBM WebSphere App Server 9.0, 8.5, and Liberty 17.0.0.3 – 26.0.0.8 if SIP (sipServlet-1.1) is enabled. Review SIP use, disable if possible. Details: https:// rad

mastodon:infosec-exchangeother61d ago kagi ↗

CRITICAL SSRF vuln (CVE-2026-14529) in IBM WebSphere App Server 9.0, 8.5, and Liberty 17.0.0.3 – 26.0.0.8 if SIP (sipServlet-1.1) is enabled. Review SIP use, disable if possible. Details: https:// radar.offseq.com/threat/ibm-we bsphere-application-server-90-and-85-and-ibm-websphere-application-server-liberty-17003-through-99257a570e2e63d4 # OffSeq # IBM # WebSphere # SSRF # CVE202614529

Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! htt

mastodon:infosec-exchangeother61d ago kagi ↗

Phoenix Contact CHARX SEC-3150 v1.0.0 hit by CRITICAL (CVSS 9.3) command injection (CVE-2026-7849): unauthenticated remote attackers can execute root commands. No mitigation yet — restrict access! https:// radar.offseq.com/threat/cve-20 26-7849-cwe-77-improper-neutralization-of-special-elements-used-in-a-command-command-injection-8b9703c63834cb6a # OffSeq # ICS # Vuln # CVE2026_7849

CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch

mastodon:infosec-exchangeother61d ago kagi ↗

CRITICAL vuln: CVE-2026-47876 in VMware Cloud Foundation (9.1.x.x/9.0.x.x/5.x) allows VM admin to execute code on host via VMXNET3 adapter. Restrict admin access, use other adapters if possible. Patch not yet available. https:// radar.offseq.com/threat/cve-20 26-47876-cwe-787-out-of-bounds-write-in-vmware-cloud-foundation-111066eb743eb8c6 # OffSeq # VMware # InfoSec # CVE202647876