Hunter[verified]@HunterMappingPatch
The post alerts that CVE-2026-23898 and CVE-2026-23899 expose critical file deletion and webservice flaws in Joomla, and it provides links to patch or advisory pages for remediation.
ZoomEye[verified]@zoomeye_teamDisclosure
The tweet announces the new Joomla! Core CVE-2026-23898, describing its arbitrary file deletion vulnerability and linking to a full analysis, while also highlighting widespread exposure detected by ZoomEye.
Anastasis Vasileiadis[verified]@Anastasis_KingDisclosure
The tweet announces two Joomla CVEs (2026‑23898 and 2026‑23899) describing them as file‑deletion and webservice flaws, but offers no proof of concept, exploit code, patch, or active exploitation evidence.
Cyberkid[verified]@Anastasis_KingDisclosure
The tweet announces the discovery of two critical Joomla vulnerabilities (CVE-2026-23898 and CVE-2026-23899) that allow file deletion and webservice flaws, without mentioning exploitation or remediation.
DarkEye[verified]@darkeye_teamDisclosure
An analysis of CVE-2026-23898 reveals an unauthenticated remote code execution via JNDI lookup in a logging library, with patch v2.18.0+ available; no PoC or active exploitation is mentioned.
Lyrie.ai[verified]@lyrie_aiGeneral
The content merely announces the existence of CVE-2026-23898 and CVE-2026-23899 with a vague reference to critical file deletion, but provides no technical details, exploit code, or patch information.
Lyrie.ai[verified]@lyrie_aiDisclosure
The tweet is a brief 0day intel disclosure of CVE-2026-23898 (and CVE-2026-23899) noting potential critical file deletion and webservice impact, but offers no PoC, exploit code, patch, or technical details.
Gray Hats@the_yellow_fallPatch
Joomla released critical patches for CVE‑2026‑23898 and CVE‑2026‑23899, advising users to update to version 5.4.4 or 6.0.4 to prevent arbitrary file deletion and API leaks.