ThreatSynop[verified]@ThreatSynopActive Exploitation
Microsoft has patched CVE‑2026‑21389, a memory‑corruption flaw in MSHTML that is actively exploited via crafted web/HTML content. Systems with legacy IE components should prioritize patching and monitor for suspicious delivery chains.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-21389, an OS command injection vulnerability in XWEB Pro 1.12.1 and earlier, with a CVSS score of 8.0 (HIGH).
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-21389, an OS command injection vulnerability in XWEB Pro 1.12.1 and earlier, with a CVSS score of 8.0, but does not mention PoC, exploit, patch, or active exploitation.
CVE@CVEnewDisclosure
The post announces the existence of CVE‑2026‑21389, an OS command injection flaw in XWEB Pro that allows authenticated attackers to achieve remote code execution.