References https://www.twcert.org.tw/tw/cp-132-10493-bf807-1.html https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/1cbd839f-19c1-4497-baef-559836775ed4/ https://www.cve.org/CVERecord?id=CVE-2025-12868 https://app.opencve.io/cve/CVE-2025-12868 https://vulners.com/cve/CVE-2025-12868 https://www.twcert.org.tw/newepaper/cp-151-10493-bf807-3.html https://cc.ncku.edu.tw/p/404-1213-289867.php?Lang=zh-tw https://www.ntrc.edu.tw/announce.php?page=2 https://www.twcert.org.tw/en/lp-139-2-3-20.html
Related VulnerabilitiesCuteHttpFileServer/chfs存在未授权任意文件上传PoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication BypassPoCCVE-2026-28411: WeGIA < 3.6.5 - Unauthenticated Authentication Bypass via extract()PoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCCVE-2026-48558: SimpleHelp <=5.5.15 - OIDC JWT Authentication BypassPoCCVE-2026-82329: JFrog Artifactory Access Blank Join Key Authentication BypassPoCCVE-2026-86207: N-able N-central - Authentication Bypass北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞PoCCVE-2026-42596: Gotenberg < 8.31.0 - Server-Side Request Forgery