Skip to content
THREATWIRE

Analysis

Research

Technical notes on how a vulnerability is recorded, what a status means, and what the public sources actually say.

High

Research

The Roundcube SQL injection is not in the CISA catalog

CVE-2026-48842 is a pre-authentication SQL injection in Roundcube virtuser_query, fixed in May 2026. A public PoC exists. CISA has not listed it, so ThreatWire does not mark Active Exploitation.

Published 2m ago

Critical

Research

Three Authlib signature bugs are not one patch

CVE-2026-28802, CVE-2026-27962, and CVE-2026-96760 are separate Authlib signature failures. Two have releases. The newest, through 1.7.2, does not.

Published 2m ago

High

Research

Two MongoDB driver bugs are not confirmed code execution

CVE-2026-96748 lets an untrusted hostname add a server to a PyMongo client. CVE-2026-96746 can crash the C driver. Both are scored 8.3. Neither NVD text is arbitrary code execution, and neither is in the CISA catalog.

Published 2m ago

Critical

Research

Reading the Next.js ImageResponse advisory

CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.

Published 1h ago

Research

How ThreatWire records a vulnerability

The status on a ThreatWire card is an editorial claim. Unknown stays unknown until a public source confirms a PoC, an exploit, or active use.

Published 29h ago