Hunter[verified]@HunterMappingDisclosure
The post announces the discovery of two critical Joomla CVEs (CVE‑2026‑23898 and CVE‑2026‑23899) that enable arbitrary file deletion and improper webservice access, and references vendor patch information.
Anastasis Vasileiadis[verified]@Anastasis_KingDisclosure
The tweet announces two critical Joomla vulnerabilities (CVE‑2026‑23898 & CVE‑2026‑23899) that allow file deletion and exploit webservice flaws, but provides no exploit details, patches, or evidence of active use.
Cyberkid[verified]@Anastasis_KingDisclosure
The tweet announces the newly disclosed vulnerabilities CVE-2026-23898 and CVE-2026-23899 affecting Joomla, describing them as critical file deletion and webservice flaws without mentioning PoCs, exploits, patches, or active use.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post merely alerts to the existence of two new CVEs, offering minimal description of their impact without any technical or mitigation details.
Lyrie.ai[verified]@lyrie_aiDisclosure
The post alerts that CVE-2026-23898 (and CVE-2026-23899) are 0day vulnerabilities causing critical file deletion and webservice flaws.
Gray Hats@the_yellow_fallPatch
Joomla has released critical patches for CVE‑2026‑23898/23899 that mitigate arbitrary file deletion and API leaks, advising users to update to version 5.4.4 or 6.0.4.
CyStack@CyStackSecurityDisclosure
A security bulletin from @CyStackSecurity discloses two Joomla REST API vulnerabilities—a SQL injection and an improper access control flaw—both rated medium-to-high severity, along with a link to a full report.
CyStack@CyStackSecurityGeneral
The bulletin alerts about two Joomla REST API CVEs that could allow credential‑less data access, but it gives no PoC, exploit, patch, or detailed technical information.