ボス@サイバーセキュリティの専門家[verified]@boss_sec_laboPatch
The post announces three new high‑severity CVEs—Cisco UCM SSRF (root privilege), a CI/CD design flaw affecting over 30,000 GitHub repos, and a ManageEngine SSO bypass (CVSS 9.0)—and stresses that patches have been released but must be verified as applied.
Cyber Edition[verified]@CyberEditionPatch
A high‑severity flaw (CVE‑2026‑11374) in ManageEngine AD360 allows unauthenticated attackers to predict SSO tickets and hijack accounts; a vendor patch is available.
Upwind Security MDR[verified]@UpwindMDRDisclosure
This is a disclosure of a critical ManageEngine vulnerability (CVE-2026-11374) that lets unauthenticated attackers predict SSO tickets and take over accounts, accompanied by vendor-released fixed versions.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The tweet reports that CVE‑2026‑11374, a predictable SSO ticket generation flaw in ManageEngine AD360, has been actively exploited by attackers to gain administrative access and lateral movement, with a link to a full analysis.
UNDERCODE TESTING[verified]@UndercodeUpdateDisclosure
The post announces a critical account takeover flaw in ManageEngine AD360's SSO token prediction, linking to a video presented for educational purposes.
Daily CyberSecurity@the_yellow_fallDisclosure
The post announces a critical account‑takeover flaw (CVE‑2026‑11374) in ManageEngine AD360 that permits unauthenticated attacks, urging administrators to update their systems immediately.
Bishop Fox@bishopfoxGeneral
The tweet references research into CVE-2026-11374, outlining the attack path and limited exploitability, but offers no PoC, tool, patch, or debunking information.
Eduardo P. Sánchez@darkslakerDisclosure
BishopFox’s post offers a research walk-through of CVE‑2026‑11374, covering its root cause and defense considerations, but it provides no PoC, exploit code, active exploitation evidence, or patch guidance.