⚠️⚠️ CVE-2026-18963 (CVSS 9.1): Unauthenticated account takeover in Keycloak via password-reset flow bypass — any account including admins can be reset
🔗FOFA Link: https://t.co/PmlMi5gT8p
🎯111.5K Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="KEYCLOAK-身份认证系统"
🔖Refer: https://t.co/tYbMHydrfc
#OSINT #FOFA #CyberSecurity #Vulnerability
⚠️⚠️ CVE-2026-21962 (CVSS 10.0): Unauthenticated access-control bypass in Oracle HTTP Server & WebLogic Server Proxy Plug-in
🔗FOFA Link: https://t.co/g7TjIM03xc
🎯1.4M+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="BEA-WebLogic-Server"
🔖Refer: https://t.co/WJNysc5atD
#OSINT #FOFA #CyberSecurity #Vulnerability
CVE-2026-33017 (CVSS 9.8) is a critical, unauthenticated remote code execution vulnerability in Langflow that lets a single POST request execute arbitrary Python code. Our latest blog post shows how to detect exploitation with Wazuh.
Read on: https://t.co/F9uqEQOqSM
⚠️⚠️ CVE-2026-55040 (CVSS 9.1): Unauthenticated JWT auth bypass on on-prem Microsoft SharePoint lets attackers impersonate any user, incl. site admins; actively exploited (CISA KEV) since public PoC.
🔗FOFA Link: https://t.co/icaNiboe5l
🎯283.8K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="Microsoft-SharePoint"
🔖Refer: https://t.co/4XGxESir6Z
#OSINT #FOFA #CyberSecurity #Vulnerability #SharePoint
⚠️⚠️ CVE-2025-62593 (CVSS 9.4, KEV): Unauthenticated server-side RCE on exposed Ray Dashboards, reachable via DNS rebinding in Firefox/Safari.
🔗FOFA Link: https://t.co/wOiULkxpNk
🎯1M+ Results are found on https://t.co/HSOBZfCA2r.
FOFA Query: app="Ray-Dashboard"
🔖Refer: https://t.co/rcZt6UnUNA
#OSINT #FOFA #CyberSecurity #Vulnerability #Ray
⚠️⚠️ CVE-2026-19478 (CVSS 9.4): Critical unauthenticated GraphQL flaw in self-managed GitLab CE/EE allows remote attackers to modify or delete public projects and user data under certain conditions. Patched in 19.2.4, 19.1.6, 19.0.8, and 18.11.11.
🔗FOFA Link: https://t.co/KQIzhhkUqK
🎯368.9K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="GitLab"
🔖Refer: https://t.co/vOENvOCeuw
#OSINT #FOFA #CyberSecurity #Vulnerability
⚠️⚠️ Vulnerability Alert (CVSS 9.8): Unpatched SQL injection in GeoServer allows remote attackers to achieve RCE. Actively exploited in the wild since disclosure. Patches released in versions 3.0.1, 2.28.5, and 2.27.6.
🔗FOFA Link: https://t.co/VQuHXOSfe7
🎯38.7K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="GeoServer"
🔖Refer: https://t.co/onDCgKR8wX
#OSINT #FOFA #CyberSecurity #Vulnerability
Managing disks on Linux goes way beyond df. Here are the useful commands for partitions, disk health, I/O, filesystems, and more 😎👇
Find high-res pdf ebooks with all my Linux related infographics at https://t.co/3t6LHw8TIY
#linux#devops#software#sysadmin#technology
🛑 Attackers are exploiting a SharePoint authentication bypass.
CVE-2026-55040 lets unauthenticated attackers forge JWTs and impersonate any SharePoint site user, including administrators. Eight of 12 recorded exploit attempts occurred on August 12 and 13, after Rapid7 published a PoC.
See how the exploit works: https://t.co/7DxzQeCz9K
⚠️⚠️ CVE-2026-64633 (CVSS 10.0) + CVE-2026-58075 (CVSS 8.7): Unauthenticated RCE and arbitrary file read on Veeam ONE agent host
🔗FOFA Link: https://t.co/5rwRviZOqt
🎯1.1K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: title="Veeam ONE"
🔖Refer: https://t.co/GhQDWKDauu
#OSINT #FOFA #CyberSecurity #Vulnerability
⚠️⚠️ CVE-2026-60004 (CVSS 9.8): Self-hosted Gitea RCE — repository writers can plant a Git hook via the /api/v1/repos/{owner}/{repo}/diffpatch endpoint and run shell commands as the Gitea service account. Default open registration lets outsiders obtain write access. Affects Gitea 1.17–<1.27.1; fixed in 1.27.1 (released 2026-07-27).
🔗FOFA Link: https://t.co/aqKk5QdDxw
🎯248.4K+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="Gitea"
PoC: https://t.co/LRnzCFr8nP
🔖Refer: https://t.co/xDw9RPBTik
#OSINT #FOFA #CyberSecurity #Vulnerability