7 Aug 2026, 07:19 UTC133 views3 reactionsread 7 August 2026 Photo
CVE-2026-64638: Pre-auth reflected XSS in WordPress, 8.9 rating 🔥
WordPress is vulnerable to a pre-auth reflected cross-site scripting (XSS) on the login screen, which can be escalated to RCE.
Search at Netlas.io:
👉 Link: https://nt.ls/SjACB
👉 Dork: tag.name:"wordpress"
Vendor's advisory:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-52p2-r8wf-jcrf
🔥2❤1
6 Aug 2026, 09:08 UTC182 views8 reactionsread 7 August 2026 🤖 Desktop AI Supercomputers and Automated Cyberattacks
AI supercomputers now fit on a desk. Combine them with uncensored open models and autonomous agents, and cyberattacks become cheaper, faster, and far easier to scale.
✔ Why local AI changes the economics of offensive operations
✔ How model guardrails can be removed or bypassed
✔ How agents automate reconnaissance, exploitation, and retries
✔ Why defenders must …
❤4🔥4
5 Aug 2026, 07:02 UTC233 views3 reactionsread 7 August 2026 Photo
CVE-2026-15307: Server-side file-write and request forgery via spatial lookups in Django, 8.8 rating 🔥
Recently disclosed Django vulnerability allows an attacker to write a file to disk (in some cases enabling remote code execution) or issue a network request as the Django process user. This flaw is reachable by staff users with view permissions on any registered model containing a spatial field.
Search at Netlas.…
❤2🔥1
3 Aug 2026, 10:44 UTC312 views4 reactionsread 7 August 2026 Photo
CVE-2026-16347: Possible brute-force attack in Mikrotik RouterOS, 8.8 rating 🔥
MikroTik RouterOS contains a weakness in its API authentication handling that allows attackers to brute-force logins for unauthorized system access.
Search at Netlas.io:
👉 Link: https://nt.ls/mMq91
👉 Dork: http.favicon.hash_sha256:6e08f1f90e778da22f07537040dfcdab9c29ac443d8386ba5be71fcbc418ff47 OR http.title:"RouterOS" OR http.body:"img…
🔥3❤1
30 Jul 2026, 07:58 UTC446 views10 reactionsread 7 August 2026 Photo
CVE-2026-56846, CVE-2026-56848 & CVE-2026-58043 and other: 3 high-severity and 8 medium or low vulnerabilities in Node.js 🔥
Recently disclosed vulnerabilities in Node.js touch HTTP/2, the Permission Model, and several core modules.
Search at Netlas.io:
👉 Link: https://nt.ls/AAg1f
👉 Dork: tag.name:"node_js"
Vendor's advisory:
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
❤4🔥4👍2
29 Jul 2026, 07:58 UTC412 views8 reactionsread 7 August 2026 Photo
Command injection in Mittel MiCollab, no CVE assigned yet, 9.8 rating 🔥
A command injection vulnerability has been discovered in the AWV component of Mitel MiCollab. A successful exploit of this vulnerability could allow an attacker to execute arbitrary commands and potentially gain control of the system.
Search at Netlas.io:
👉 Link: https://nt.ls/t8Tk9
👉 Dork: tag.name:"micollab"
Vendor's advisory:
https://www.m…
❤3🔥3🕊2
28 Jul 2026, 08:00 UTC390 views8 reactionsread 7 August 2026 Photo
CVE-2026-16812: OS Command injection in VeloCloud Orchestrator, 10.0 rating 🔥
A new vulnerability in Arista VeloCloud Orchestrator (VCO) allows an unauthenticated remote attacker run OS commands on the VCO host. A compromise can also expose managed devices. This vulnerability is already being actively exploited in the wild!
Search at Netlas.io:
👉 Link: https://nt.ls/PkM4n
👉 Dork: http.body:"single-spa-application:…
❤4🔥4
27 Jul 2026, 15:32 UTC521 views12 reactionsread 7 August 2026 Photo
CVE-2026-61511: Pre-auth RCE vulnerability in vBulletin, 9.3 rating 🔥
The vulnerability allows unauthenticated attacker to run arbitrary PHP code as the web server, which can mean full site takeover. PoC is now available!
Search at Netlas.io:
👉 Link: https://nt.ls/c7BPf
👉 Dork: tag.name:"vbulletin"
Read more: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
🔥6👍4❤2
23 Jul 2026, 08:01 UTC527 views14 reactionsread 7 August 2026 Photo
High-severity LPE in Exim, no CVE assigned yet 🤷
A new vulnerability in Exim allows a local attacker to read files outside the mail spool. This could lead to privilege escalation.
Search at Netlas.io:
👉 Link: https://nt.ls/qEnbs
👉 Dork: tag.name:"exim"
Vendor's advisory:
https://www.exim.org/static/doc/security/EXIM-Security-2026-06-22.1/EXIM-Security-2026-06-22.1.txt
🔥6❤5😱2👍1
22 Jul 2026, 08:21 UTC473 views13 reactionsread 7 August 2026 Photo
CVE-2026-60291, CVE-2026-60292, CVE-2026-60294 and other: A lot of vulnerabilities in Oracle Weblogic Server, 9.8 rating 🔥
Recently disclosed easily exploitable vulnerabilities in Oracle Weblogic Server allow unauthenticated attacker to compromise Oracle WebLogic Server.
Search at Netlas.io:
👉 Link: https://nt.ls/NdCqq
👉 Dork: tag.name:"weblogic"
Vendor's advisory:
https://www.oracle.com/security-alerts/cpujul2026…
🔥6❤4👍3
21 Jul 2026, 07:48 UTC451 views7 reactionsread 7 August 2026 Photo
HollowByte: DoS vulnerability in OpenSSL, no CVE assigned yet 🤷
By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can freeze server memory and to crush a host.
Search at Netlas.io:
👉 Link: https://nt.ls/be55E
👉 Dork: tag.name:"openssl"
Read more:
https://sec.okta.com/articles/2026/06/openssl-hollowbtye-a-dos-hiding-in-11-bytes/
🔥4❤2👍1
20 Jul 2026, 07:52 UTC474 views9 reactionsread 7 August 2026 Photo
CVE-2026-63030: Pre-Auth RCE in WordPress Core, 9.8 rating 🔥
Recently disclosed WordPress pre authentication RCE vulnerability can be exploited by an anonymous user in a stock install of WordPress with no plugins. PoC exists!
Search at Netlas.io:
👉 Link: https://nt.ls/Yvd0s
👉 Dork: tag.name:"wordpress"
Read more:
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
🔥4❤3👍2
Showing the 12 most recent of 22 posts we hold for @netlas. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.