CCB Alert@CCBalertDisclosure
The post announces a critical RCE vulnerability (CVE-2026-25134) in Intermesh Group-Office CRM, describing the exploit vector via a crafted ZIP file, but provides no evidence of active exploitation or patch details.
David@DavidMarquet19General
A brief list of recent high‑CVSS CVEs with no additional context or actionable information.
Autumn Good@autumn_good_35Disclosure
The advisory announces CVE‑2026‑25134, a Remote Code Execution flaw in Intermesh GroupOffice that allows an authenticated basic user to run arbitrary commands on the server; no PoC, exploit code, or patch details are provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE-2026-25134, highlighting a remote code execution vulnerability in Group-Office caused by unsanitized language parameter handling.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑25134, describing a vulnerable action in Group‑Office's MaintenanceController and indicating that versions 6.8.150, 25.0.82, and 26.0.5 contain the patch.
0day Signal@0dayPublishingDisclosure
The post announces CVE‑2026‑25134, describing a classic command injection in Group‑Office’s exec() function via the unfiltered ‘lang’ parameter that allows full RCE through a crafted zip file, with no patches or active exploitation reported but providing technical details of the flaw.