CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. https:// radar.offseq
711). 9).
711). 9).
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. https:// radar.offseq.com/threat/cve-20 26-19599-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-d62870fccbe1d229 # OffSeq # Vuln # InfoSec # RCE
plank laravel-mediable <7.0.2 has a CRITICAL vuln (CVE-2026-93352): .pht files not blocked, allowing unauthenticated RCE. Upgrade to 7.0.2+ ASAP. https:// radar.offseq.com/threat/cve-20 26-93352-unrestricted-upload-of-file-with-dangerous-type-in-plank-laravel-mediable-969ae75c94489a3a # OffSeq # CVE202693352 # RCE # Laravel # Infosec
IBM Concert v1.0.0 – 3.0.0 hit by CRITICAL use-after-free bug (CVE-2026-6928, CVSS 9.8). Remote code execution & full compromise possible; no patch confirmed. Monitor IBM advisories. https:// radar.offseq.com/threat/cve-20 26-6928-cwe-416-use-after-free-in-ibm-concert-2eb5c8a4bd6982d7 # OffSeq # Vuln # IBM # CVE20266928 # Infosec
Botslab G980H dash cams are affected by CVE-2026-81630 (CRITICAL, CVSS 9.2): Firmware authenticity is not cryptographically verified, enabling remote code execution if updates are intercepted. Avoid untrusted networks until a patch is released. https:// radar.offseq.com/threat/cve-20 26-81630-cwe-345-insufficient-verification-of-data-authenticity-in-botslab-g980h-23022026fbd9ffd9 # OffSeq # CVE202
CVE-2026-93291 (CRITICAL): Eufy Omni C20 (<1.6.4) fails certificate validation, exposing devices to MITM and arbitrary code execution. Patch status unknown — use strong network protections. https:// radar.offseq.com/threat/cve-20 26-93291-cwe-295-improper-certificate-validation-in-eufy-omni-c20-63bb60225f0bad8d # OffSeq # CVE202693291 # IoTSecurity # Vuln # Infosec
CVE-2026-93399 (CRITICAL): Bookly WordPress plugin (≤28.2) lets unauth'd attackers enumerate, access, and delete bookings via auth bypass in AJAX actions. No patch. Restrict plugin endpoints & monitor for abuse. https:// radar.offseq.com/threat/cve-20 26-93399-cwe-639-authorization-bypass-through-user-controlled-key-in-ladela-online-scheduling-437a419f1c3d5ec6 # OffSeq # WordPress # Vuln # Cyberse
CVE-2026-89055 (CRITICAL, CVSS 9.1): Customer Reviews for WooCommerce <=5.120.0 lets unauthenticated attackers delete arbitrary media via public review-form links. Restrict link access, monitor suspicious review activity. https:// radar.offseq.com/threat/cve-20 26-89055-cwe-862-missing-authorization-in-ivole-customer-reviews-for-woocommerce-49ae0564154df323 # OffSeq # CVE202689055 # WordPress # In