References https://www.twcert.org.tw/tw/cp-132-8047-adf79-1.html https://www.twcert.org.tw/en/cp-139-8048-f0e4d-2.html https://cc.nkust.edu.tw/p/405-1025-84600,c9642.php
Related VulnerabilitiesPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-29962: HSC MailInspector - Local File InclusionPoCCVE-2026-85200: GEO my WP <=4.5.5.3 - Unauthenticated Local File Inclusion关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告PoCCVE-2026-55229: Gotenberg < 8.34.0 - Local File DisclosurePoCCVE-2026-9133: Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File ReadPoCmaven-settings-xml-exposure: Apache Maven settings.xml Credentials - ExposurePoCnuget-config-exposure: NuGet.config Package Source Credentials - ExposurePoCpypirc-credentials-exposure: Python .pypirc Credentials - ExposurePoCCVE-2026-18963: Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials BypassPoCCVE-2026-56265: Crawl4AI < 0.8.7 - Hardcoded JWT Signing Key Authentication Bypass