Skip to content
THREATWIRE

Index

Search

Search the public record. Drafts and scheduled notes are not included.

Critical

news

DevKit Pro admin takeover is CVE-2026-14378

Wordfence disclosed CVE-2026-14378 in DevKit Pro for WordPress through 2.3.0: unauthenticated administrator session takeover via the user-switch revert flow. CVSS 9.8. A public PoC exists under a misnamed repository. Not in CISA KEV. CVE-2026-19660 is a different Divi Membership bug.

Published 2h ago

Critical

news

IBM MQ patches CVE-2026-10747 and CVE-2026-10858

IBM published critical MQ fixes: CVE-2026-10747 is CVSS 10.0 pre-auth protocol heap overflow on the listener path, and CVE-2026-10858 is CVSS 9.9 authenticated multi-segment heap underflow on NonStop and Appliance. No KEV listing and no public PoC confirmed.

Published 3h ago

Critical

news

Visual Composer LFI is CVE-2026-12227

Wordfence disclosed an unauthenticated local file inclusion in the Visual Composer Website Builder WordPress plugin up to 45.16.0, CVSS 9.8. A public PoC repository exists. Exploitation in the wild and CISA KEV listing are not confirmed.

Published 6h ago

Critical

threats

NetScaler command execution is CVE-2026-88771

Citrix bulletin CTX697096 confirms unauthenticated command execution on NetScaler in the default configuration. CISA listed CVE-2026-88771 on 27 September 2026. A later alert with no CVE id is this bulletin, not a new unnumbered bug.

Published 7h ago

Critical

news

The Gotenberg public PoC is not a confirmed RCE

CVE-2026-40281 has a public repository and a CVSS 10.0 score. The vendor advisory describes unauthenticated file move, overwrite, and link creation inside the container. Code execution is not the published impact.

Published 8h ago

CriticalPoC Available

CVE-2026-14378

DevKit Pro unauthenticated admin takeover via revert_switch

Auth bypass

Published 4d ago

CriticalActive ExploitationKEV0-day

CVE-2026-88771

NetScaler unauthenticated command execution

RCE

Published 8d ago

CriticalPoC Available

CVE-2026-12227

Visual Composer unauthenticated local file inclusion

Other

Published 11d ago

CriticalNo PoC

CVE-2026-10747

IBM MQ pre-auth heap overflow in protocol message processing

RCE

Published 18 Sept 2026

CriticalNo PoC

CVE-2026-10858

IBM MQ authenticated heap underflow on multi-segment messages

RCE

Published 18 Sept 2026

CriticalPoC Available

CVE-2026-40281

Gotenberg ExifTool argument injection

Other

Published 6 May 2026

CriticalActive ExploitationKEV0-day

CVE-2024-3400

PAN-OS GlobalProtect command injection

RCE

Published 12 Apr 2024