kaminuma@kaminuma_devPatch
The post announces that two baserCMS CVEs have been publicly disclosed and patched, with an advisory link provided. No PoC, exploit, or active exploitation information is mentioned.
CVE@CVEnewDisclosure
The announcement reveals an OS command injection flaw in baserCMS versions before 5.2.3 that can be exploited via the core update feature.
CVEarity@CVEarityDisclosure
The tweet announces a new critical CVE with basic severity information but provides no technical, exploit, or mitigation details.
CVEFind.com@CveFindComPatch
A critical OS command injection vulnerability in baserCMS has been patched in version 5.2.3, and administrators are encouraged to update immediately.
The Hacker Wire@TheHackerWireDisclosure
The post announces a critical OS command injection vulnerability (CVE-2026-21861) in baserCMS versions before 5.2.3, highlighting the affected core update functionality.
PulsePatch.io@pulsepatchioDisclosure
The post announces the discovery of CVE‑2026‑21861 in baserCMS, a command‑injection RCE that permits arbitrary command execution.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE‑2026‑21861 as a privilege‑escalation RCE in baserCMS via exec(), without mentioning a PoC, exploit code, or patch, but does provide technical details about the vulnerability.