References https://www.twcert.org.tw/tw/cp-132-8049-83fe4-1.html https://www.twcert.org.tw/newepaper/cp-151-8049-83fe4-3.html https://www.twcert.org.tw/tw/lp-132-1-11-20.html https://www.twcert.org.tw/tw/lp-132-1-4-60.html https://www.twcert.org.tw/tw/dl-362-cf1aa7c22c2b4b8e97c856c799e735cb.html
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2026-73034: DB-GPT <= 0.8.1 - Arbitrary File WritePoCCVE-2026-54917: SeaweedFS <= 4.29 - Path Traversal File WritePoCCVE-2026-12898: All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File WritePoCCVE-2026-25895: FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritePoCCVE-2026-56265: Crawl4AI < 0.8.7 - Hardcoded JWT Signing Key Authentication BypassPoCCVE-2025-11953: React Native Community CLI - Unauthenticated OS Command InjectionPoCCVE-2026-49049: JoomShaper Helix3 <=3.1.0 - Unauthenticated Arbitrary JSON File WritePoCCVE-2026-50160: Hoppscotch <= 2026.4.1 - Mass Assignment JWT_SECRET OverwritePoCCVE-2026-44825: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials盛源|DMS+ (非行動端) - Use of Hard-coded CredentialsFOSSBilling /system/string_render 命令执行漏洞(CVE-2026-28496)