Skip to content
THREATWIRE

Index

Search

Search the public record. Drafts and scheduled notes are not included.

Critical

news

IBM MQ patches CVE-2026-10747 and CVE-2026-10858

IBM published critical MQ fixes: CVE-2026-10747 is CVSS 10.0 pre-auth protocol heap overflow on the listener path, and CVE-2026-10858 is CVSS 9.9 authenticated multi-segment heap underflow on NonStop and Appliance. No KEV listing and no public PoC confirmed.

Published 30m ago

High

news

Goose recipe command execution is CVE-2026-85623

VulnCheck published CVE-2026-85623 / GHSA-rh2p-fw5h-rc3m for Goose: recipe stdio extensions and retry checks can run shell commands the unicode recipe scan does not inspect. CVSS 3.1 8.8. Goose 1.52.0 ships a Desktop consent-before-session fix. A public PoC exists. Not in CISA KEV.

Published 58m ago

Critical

research

Reading the Next.js ImageResponse advisory

CVE-2026-94545 is a Satori escaping bug that Vercel says can become code execution in Node.js next/og. The only published numeric score is 5.3. Next.js 16.3.6 is the fix. A public PoC exists.

Published 5h ago

Critical

news

The Gotenberg public PoC is not a confirmed RCE

CVE-2026-40281 has a public repository and a CVSS 10.0 score. The vendor advisory describes unauthenticated file move, overwrite, and link creation inside the container. Code execution is not the published impact.

Published 6h ago

MediumNo PoC

CVE-2026-104711

OGNL injection in the legacy RESTful action mapper

RCE

Published 19h ago

research

How ThreatWire records a vulnerability

The status on a ThreatWire card is an editorial claim. Unknown stays unknown until a public source confirms a PoC, an exploit, or active use.

Published 34h ago

threats

Reading ransomware claims without amplifying them

A leak-site post is a claim. Victim impact, data theft, and encryption are separate facts and stay unmarked until a better source exists.

Published 2d ago

CriticalPoC Available

CVE-2026-94545

Satori SVG injection affecting Next.js ImageResponse

RCE

Published 6d ago

HighNo PoC

CVE-2026-96748

PyMongo connection-string host injection

Other

Published 11d ago

CriticalNo PoC

CVE-2026-10747

IBM MQ pre-auth heap overflow in protocol message processing

RCE

Published 18 Sept 2026

HighPoC Available

CVE-2026-85623

Goose recipe stdio extensions run commands without scan coverage

RCE

Published 4 Sept 2026