transilienceai[verified]@transilienceaiGeneral
The tweet highlights CVE-2025-60021 as a high‑severity command injection flaw in Apache bRPC but offers no evidence of exploitation or remediation.
Arnav Sharma 🇦🇺[verified]@arnavsharmaDisclosure
A critical command injection flaw is disclosed in Apache bRPC's /pprof/heap endpoint (CVE-2025-60021), enabling unauthenticated remote code execution with a CVSS score of 9.8.
_cr0w_@f3dscr0wActive Exploitation
CVE-2025-60021 in SmarterMail enables RCE through an authentication bypass with a CVSS of 10.0; active exploitation has been observed, urging immediate patching of affected email servers.
B2B Cyber Security.de@B2bCyberDisclosure
A new high‑severity vulnerability (CVE‑2025‑60021, CVSS 9.8) in Apache bRPC has been disclosed; no PoC, exploit code, or mitigation details are provided.
B2B Cyber Security.de@B2bCyberDisclosure
A critical vulnerability (CVE‑2025‑60021) with a high CVSS score (9.8) was identified in the Apache bRPC framework, but no PoC, exploit code, or patch information is mentioned.