CRITICAL Ninja Forms bug lets attackers upload files — remote code execution risk for WordPress sites. No patch yet: restrict uploads & monitor activity. radar.offseq.com/threat/hackers-targeting... #OffSeq #WordPress #Security
Latest Posts by Offensive Sequence
Six Apart Movable Type ≤9.1.0 hit by CRITICAL code injection flaw. Unauthenticated attackers can run Perl scripts. No patch — restrict access & monitor logs. radar.offseq.com/threat/cve-2026-25776-co... #OffSeq #Vulnerability #Cybersecurity
CRITICAL: DSGVO Google Web Fonts GDPR plugin for WordPress lets unauth attackers upload PHP shells via AJAX. No patch yet — disable plugin or restrict AJAX if using vulnerable themes. More info: radar.offseq.com/threat/cve-2026-3535-cwe... #OffSeq #W...
CRITICAL: Iran-linked hackers disrupt US infrastructure via PLC & SCADA attacks. OT disruptions ongoing — check vendor advisories & strengthen OT defenses now. radar.offseq.com/threat/iran-linked-hacke... #OffSeq #ICS #OTsecurity
🚨 CRITICAL: Users manager – PN plugin for WordPress lets unauthenticated attackers escalate privileges by updating any user meta. Disable plugin until fixed! radar.offseq.com/threat/cve-2026-4003-cwe... #OffSeq #WordPress #Security
CRITICAL: Iran-linked actors disrupt US critical infrastructure via PLC & SCADA attacks ⚠️. No CVE yet. Monitor vendor updates, follow federal guidance, and secure OT environments. radar.offseq.com/threat/iran-linked-hacke... #OffSeq #ICS #CyberThreat
🚨 SiYuan <3.6.4 has a CRITICAL stored XSS bug — malicious notes can trigger remote code execution in the desktop app. Upgrade to 3.6.4 now. Details: radar.offseq.com/threat/cve-2026-39846-cw... #OffSeq #SiYuan #security
IBM Verify Identity Access Container (10.0 – 11.0.2) faces a CRITICAL flaw: local users can escalate to root. No patch yet — restrict access & monitor updates. radar.offseq.com/threat/cve-2026-1346-cwe... #OffSeq #IBMSecurity #Vulnerability
CRITICAL: Emmett (2.5.0 – <2.8.1) has a path traversal flaw — attackers can read server files remotely. Upgrade to 2.8.1+ now to secure your systems! radar.offseq.com/threat/cve-2026-39847-cw... #OffSeq #Emmett #Vulnerability
🚨 CRITICAL XSS in Mediawiki - GlobalWatchlist Extension (non-release branches). Severity: CRITICAL. Review non-release deployments now. radar.offseq.com/threat/cve-2026-39933-cw... #OffSeq #XSS #Mediawiki
Critical Flowise bug: improper JavaScript validation can let attackers run arbitrary code & access the file system. No patch yet — restrict who can access your Flowise instance! Details: radar.offseq.com/threat/critical-flowise-... #OffSeq #Flowise #...
CRITICAL path traversal in mintplex-labs/anything-llm (<=1.9.1) lets high-priv attackers read or delete .json files. Upgrade to 1.12.1 & restrict access. radar.offseq.com/threat/cve-2026-5627-cwe... #OffSeq #Security #PatchNow
ci4-cms-erp ci4ms <31.0.0.0 faces CRITICAL stored XSS (CVSS 9.4)! Attackers can run JS via profile name fields. Upgrade to 31.0.0.0+ for protection. radar.offseq.com/threat/cve-2026-34989-cw... #OffSeq #XSS #WebSecurity
goshs <2.0.0-beta.3 hit by CRITICAL path traversal bug. Attackers can write files anywhere — patch to 2.0.0-beta.3 ASAP! Details: radar.offseq.com/threat/cve-2026-35393-cw... #OffSeq #Security #Vulnerability
⚠️ CRITICAL: White House seeks $707M cut to CISA funding. No direct exploit, but federal cyber defense may be impacted. Monitor CISA updates for changes. radar.offseq.com/threat/white-house-seeks... #OffSeq #CISA #security
CRITICAL: goshs < 2.0.0-beta.3 path traversal bug lets remote attackers access or delete files. Upgrade to 2.0.0-beta.3 now! 🛡️ radar.offseq.com/threat/cve-2026-35471-cw... #OffSeq #infosec #golang
CRITICAL vuln in parisneo/lollms v2.1.0: Weak JWT secret lets attackers forge admin tokens & escalate privileges. Patch to v2.2.0 now! 🔒 radar.offseq.com/threat/cve-2026-1114-cwe... #OffSeq #CVE20261114 #AppSec
CRITICAL: Ninja Forms - File Uploads plugin (≤3.3.26) lets unauthenticated attackers upload arbitrary files, risking RCE. Upgrade to 3.3.27+ ASAP! radar.offseq.com/threat/cve-2026-0740-cwe... #OffSeq #WordPress #Security
CRITICAL: OS command injection in Anthropic Claude Code CLI & Agent SDK (CVSS 9.3). Arbitrary code exec possible via manipulated auth params. Vendor has patched — check status. radar.offseq.com/threat/cve-2026-35022-cw... #OffSeq #CloudSecurity #Vuln...
goshs < 2.0.0-beta.3 has a critical path traversal bug (CVSS 9.8) 🛡️. Attackers can write files anywhere on the server. Upgrade to 2.0.0-beta.3 or newer now! radar.offseq.com/threat/cve-2026-35392-cw... #OffSeq #Vulnerability #GoLang
CRITICAL: goshs (<2.0.0-beta.3) has a path traversal flaw. Attackers can write files outside intended dirs. Upgrade to 2.0.0-beta.3 ASAP! 🔒 radar.offseq.com/threat/cve-2026-35393-cw... #OffSeq #Vulnerability #GoLang
CRITICAL: patrickhener goshs (<2.0.0-beta.3) vulnerable to path traversal, letting attackers access or delete files outside intended dirs. Upgrade to 2.0.0-beta.3+ immediately! radar.offseq.com/threat/cve-2026-35471-cw... #OffSeq #CVE202635471 #Security
Belkin F9K1015 (v1.00.10) faces a HIGH severity stack buffer overflow — remote attackers could gain code execution. No patch from vendor. Limit remote access and watch for updates. radar.offseq.com/threat/cve-2026-5612-sta... #OffSeq #Vulnerability #...
Belkin F9K1015 routers (v1.00.10) face a HIGH risk stack overflow (CVE-2026-5628). No patch — disable remote mgmt & restrict access now! More at radar.offseq.com/threat/cve-2026-5628-sta... #OffSeq #Security #Belkin
Belkin F9K1015 (v1.00.10) faces HIGH-severity buffer overflow (CVE-2026-5629) — remote exploit possible, public code available, no patch yet. Restrict access & monitor updates. radar.offseq.com/threat/cve-2026-5629-sta... #OffSeq #Belkin #VulnAlert
Belkin F9K1015 v1.00.10 hit by HIGH severity stack buffer overflow (CVE-2026-5613). Exploit public, no patch yet. Restrict access & disable remote mgmt ASAP. radar.offseq.com/threat/cve-2026-5613-sta... #OffSeq #IoTSecurity #Vuln
Belkin F9K1015 (v1.00.10) faces HIGH-severity stack buffer overflow (public exploit out). No patch — disable remote access, restrict device exposure, and monitor. Stay updated: radar.offseq.com/threat/cve-2026-5614-sta... #OffSeq #RouterSecurity #Vul...
Belkin F9K1015 v1.00.10: HIGH severity buffer overflow can be exploited remotely — no patch yet. Restrict device access & monitor for threats. Full details: radar.offseq.com/threat/cve-2026-5610-sta... #OffSeq #Vulnerability #IoTSecurity
Belkin F9K1122 (v1.00.33) hit by HIGH severity buffer overflow (CVE-2026-5608) — public exploit, no patch. Restrict remote access & monitor for updates. Take action now: radar.offseq.com/threat/cve-2026-5608-sta... #OffSeq #Belkin #Vulnerability
Tenda CH22 v1.0.0.1 faces a HIGH severity buffer overflow (CVE-2026-5605). Patch unavailable — limit remote access & monitor your devices. Learn more: radar.offseq.com/threat/cve-2026-5605-sta... #OffSeq #Vulnerability #NetworkSecurity