References https://www.twcert.org.tw/en/cp-139-7386-9e391-2.html https://cve.imfht.com/detail/CVE-2023-35087?lang=en https://nvd.nist.gov/vuln/detail/CVE-2023-35087 https://www.cve.org/CVERecord?id=CVE-2023-39239 https://www.cvedetails.com/cve/CVE-2023-39239/ https://github.com/advisories/GHSA-r4fx-9v33-wcf4 https://www.twcert.org.tw/en/cp-139-7385-34e7e-2.html https://nvd.nist.gov/vuln/detail/CVE-2023-35086 https://devhub.checkmarx.com/cve-details/cve-2023-35087/
Related VulnerabilitiesPoCCVE-2026-11801: WPAdverts <= 2.3.2 - Information DisclosurePoCCVE-2026-17594: Sonatype Nexus Repository < 3.95.0 - Privilege Escalation via Repository Format MismatchPoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoCCVE-2026-27796: Homarr < 1.54.0 - Information DisclosurePoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCE关于U9 cloud接口存在BinaryFormatter反序列化漏洞的安全通告PoCCVE-2026-1980: WPBookit <= 1.0.8 - Unauthenticated Customer Information DisclosurePoCCVE-2026-8386: WP Go Maps < 10.0.10 - Unauthenticated Marker Information DisclosureFOSSBilling /system/string_render 命令执行漏洞(CVE-2026-28496)PoCCVE-2026-22778: vLLM 0.8.3 - 0.14.0 - Information DisclosurePoCCVE-2026-8383: LearnPress < 4.3.7 - Information DisclosurePoCweaver-getemdslist-disclosure: Weaver E-cology getEmDsList Sensitive Information DisclosurePoCCVE-2026-54236: vLLM <= 0.23.0 - Anthropic Router Heap Address Information Leak