Rıdvan Yağlı[verified]@ridvanyagliPoC
The text announces a critical RCE vulnerability in Foreman (CVE-2026-1961) and provides a link to a public PoC, along with fixed versions and technical details.
Gray Hats@the_yellow_fallPatch
The post announces that Foreman has released a critical patch (v3.18.1) for CVE‑2026‑1961, a command injection vulnerability leading to remote code execution, with no indication of existing exploits or active attacks.
Open Source Security mailing list@oss_securityPatch
The post announces a remote code execution vulnerability in Foreman’s WebSocket proxy, provides technical details on how unsanitized hostnames lead to command injection, and notes that the issue is fixed in versions 3.18.1, 3.17.2, and 3.16.3.
CrowdCyber 🌐@CrowdCyber_ComDisclosure
The text announces a newly discovered high‑severity RCE vulnerability (CVE‑2026‑1961) in Foreman's WebSocket Proxy, referencing a source URL for additional details.
CVE@CVEnewDisclosure
The text announces a command‑injection vulnerability in Foreman’s WebSocket proxy, providing only technical details without any PoC, exploit code, or patch information.
The Hacker Wire@TheHackerWireDisclosure
A new high‑severity command injection flaw in Foreman's WebSocket proxy is described, but no PoC, exploit, active exploitation, or patch details are provided.