
WordPress系にCVSS 10.0のファイルアップロード脆弱性。libxsltの型混同(CVE-2025-7424)やSambaの権限昇格も更新されており、インフラ管理者は確認を。本日のCVE 200件まとめ #セキュリティ #CVE #脆弱性 https://tsumikasane.net/security/daily/2026-04-29/
Post summary
The post announces newly disclosed CVEs, notably CVE-2025-7424 with a CVSS 10.0 file upload vulnerability in WordPress, along with updates on libxslt type confusion and Samba privilege escalation, but offers no PoC, exploit, patch or evidence of active exploitation.
