🚨CVE-2026-25243 — authenticated RCE in Redis (fixed in 8.6.3). A crafted RESTORE payload triggers a double-free in the RDB deserializer, leading to code execution in the redis-server process. A public PoC is now circulating. If you're not on 8.6.3+, patch now. #Redis#RCE#CVE
🚨CVE-2026-16723: authenticated RCE in self-managed GitLab (≤18.11.3). Any user with push access can run commands as the git user. Patched 6 weeks ago, PoC dropped July 24. Push access ≠ system access — update now if you're on an old version. #infosec#Pentest#AppSec
🚨CVE-2026-16232 — CVSS 9.3 auth bypass in Check Point SmartConsole, actively exploited. Attackers get a full admin login token with zero authentication. Limited to internet-exposed management interfaces — proof that "don't expose management panels to the internet"
🚨CVE-2026-58644 — critical SharePoint deserialization flaw (CVSS 9.8), on CISA KEV with a 48-hour federal deadline. One of the most reliable pre-auth RCE chains in years. Patch now, don't just mitigate. #infosec#Pentest
🚨CVE-2026-6875 — pre-auth RCE in ServiceNow, actively exploited days after the patch shipped. Attackers used a sandbox-escape gadget chain different from the public PoC. Pre-auth = no login needed, straight to code execution. If you're self-hosted, patch now. #infosec#AppSec
@ParsUnity کلا هیچ سیستمی ایمن نیست من خودم اوسینتو دوست دارم ولی فکر نکنم بشه با اوسینت کل اطلاعات یکیو دروورد تو تلگرام مگه آسیب پذیری باشه مثل idor BAC