kmkz[verified]@kmkz_securityExploit
The author released a Python PoC and a Metasploit module for CVE-2025-54988/CVE-2025-66516, detailing an XXE flaw in Elasticsearch’s Tika attachment processor that allows arbitrary file reads, with code available on GitHub.
Kaan[verified]@wkaandemirGeneral
The update announces new CVEs added to a security guide, providing basic vulnerability type details but no PoC, exploit code, active exploitation evidence, patches, or debunking information.
OPSWAT[verified]@OPSWATDisclosure
The post announces a critical XXE flaw (CVE‑2025‑66516) in Apache Tika, emphasizing that patching alone is insufficient and advocating for additional safeguards such as file sanitization and supply‑chain security.
Picus Security[verified]@PicusSecurityPatch
CVE-2025-66516 is a high‑severity XXE flaw in Apache Tika’s tika-core; patching to version 3.2.2+ resolves the issue, and technical details with a PoC are available via the linked breakdown.
Security Arsenal, LLC[verified]@SecurityAr58409Exploit
Rapid7 has released 16 new Metasploit modules targeting CVE‑2025‑66516, an Apache Tika XXE flaw in Elasticsearch ingest‑attachment, but no evidence of current exploitation in the wild is presented.
@pedri77@pedri77Disclosure
The post announces the discovery of a critical Apache Tika vulnerability (CVE-2025-66516) that can exploit XML external entity injection, with a maximum CVSS score of 10.0.
Sarath Reddy@Sarath802274020Disclosure
The tweet announces the disclosure of two CVEs that allow malicious PDFs to break Apache Tika, pointing to an article that likely details the vulnerability.
CERT-PY@CERTpyGeneral
The post lists three Atlassian CVEs and directs readers to a link for additional information, but provides no further technical or operational details.