Critical 10.0: CVE-2026-49185 hits FieldX MDM with unauthenticated OS command injection. Unverified adb payloads go straight into Runtime.exec(). No auth, no interaction, full system compromise. https://t.co/lcS1Zp31Gd
CVE-2026-41283: Critical 9.9 in OpenStack Mistral through 22.0.0. Policy enforcement bypass enables RCE via exposed API endpoints, leading to service credential exfiltration. If Mistral is in your stack, treat this as urgent. https://t.co/rnKKY85O1u
CVE-2026-46135: Critical (9.8) race condition in the Linux kernel's nvmet-tcp. ICReq handling vs queue teardown can be exploited remotely with no auth required. No interaction needed. Patch your kernel. #Linux#CVE https://t.co/ROSS12nEem
CVE-2026-46562: Critical 9.8 unauthenticated RCE in yamcs-core. Nashorn ScriptEngine evaluates user-supplied algorithm text with zero restrictions. No auth, no interaction, full system compromise possible. Patch now if you run YAMCS. #yamcs#infosec https://t.co/g31wDvmxLh
CVE-2026-44887: Critical (9.8) unauthenticated RCE in Pi.Alert. Attackers can inject arbitrary Python code via the web config editor, no credentials needed. If you're running Pi.Alert, update immediately. #NetworkSecurity#RCE
https://t.co/ScZTrD7vXs
Actively exploited in the wild. CVE-2025-48595 is an integer overflow in Android Framework enabling local privilege escalation - no privileges needed. CVSS 8.4, now on CISA KEV. Patch now. https://t.co/n7vnaOEzt7
β±οΈ Attackers are exploiting vulnerabilities faster than many organizations can identify and patch them.
π‘οΈ @SecAlertsCo explains how faster vulnerability alerts can help reduce exposure and improve response times.
β‘οΈ https://t.co/dDcXhS3f0z
#cybersecurity#sponsored
β±οΈ Attackers are exploiting vulnerabilities faster than many organizations can identify and patch them.
π‘οΈ @SecAlertsCo explains how faster vulnerability alerts can help reduce exposure and improve response times.
β‘οΈ https://t.co/dDcXhS3f0z
#cybersecurity#sponsored
CVE-2026-49201: Acer Wave 7 router has a hardcoded AES key in upload.cgi. Anyone can decrypt, tamper, and re-encrypt your backups. CVSS 10 critical, no auth required. If this router is in your stack, act now. https://t.co/2Rsl1WSnmn
CVE-2026-49200: Critical severity on the Acer Wave 7 router. No auth needed to read acer_cgi.log, which exposes cleartext web + Telnet credentials. Full system compromise, no friction. Check your network gear. #CriticalVuln#InfoSec https://t.co/wmyilNCLiy
CVSS 10 critical in npm/vm2 (GHSA-v6mx-mf47-r5wg): sandbox escape via prototype manipulation using Buffer internals. No auth, no interaction, full host compromise possible. Patch to v3.11.4 if you run vm2. https://t.co/HrZl8rg776
CVSS 10.0 in vm2 (npm). CVE-2026-47131 is a critical sandbox escape via prototype manipulation - no auth, no interaction, full host compromise possible. If you use vm2, update to v3.11.4 now. #nodejs#security https://t.co/pYZr15pKcb
GHSA-m4wx-m65x-ghrr: vm2 sandbox escape, CVSS 10. A previous fix for CVE-2023-37903 was bypassed via a strict equality check flaw in nodevm.js. Network-exploitable, no auth needed, full RCE scope. Update vm2 now. https://t.co/Ly0xGUIdpu
CVSS 10.0 in vm2 (npm). CVE-2026-47137 is a sandbox escape that bypasses the fix for CVE-2023-37903 - unauthenticated, no interaction needed, full compromise possible. If vm2 is in your stack, treat this as critical. #nodejs#security https://t.co/mpwdoehrZO