References https://www.twcert.org.tw/tw/cp-132-4905-c99ac-1.html https://www.twcert.org.tw/tw/cp-132-5971-b691f-1.html https://www.twcert.org.tw/en/cp-139-5976-b87da-2.html https://www.cvedetails.com/cve/CVE-2022-26671/ https://nvd.nist.gov/vuln/detail/CVE-2022-26671 https://www.cve.org/CVERecord?id=CVE-2022-26671 https://cve.imfht.com/detail/CVE-2021-35961?lang=en https://github.com/advisories/ghsa-52qj-6cff-vhwq
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-58191: Appium base-driver <=10.6.0 - Reflected Cross-Site Scripting英特內|DreamMaker - 存在2個漏洞PoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposurePoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCpypirc-credentials-exposure: Python .pypirc Credentials - ExposurePoCCVE-2026-18963: Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass畅捷通T+系统 AccountExtendRuleController接口处存在反序列化漏洞PoCCVE-2026-56265: Crawl4AI < 0.8.7 - Hardcoded JWT Signing Key Authentication BypassPoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials