Carlos Vieira (lynx)[verified]@carlos_crowsecDisclosure
The post announces a newly discovered insecure deserialization flaw in Wazuh Cluster (CVE-2026-25769) that can lead to remote command execution, provides a PoC, and references a vendor advisory for patching.
Clandestine[verified]@akaclandestinePoC
The GitHub repository provides a proof‑of‑concept demonstrating RCE via insecure deserialization in Wazuh, but there is no evidence of active exploitation or an available patch.
NullSecurityX[verified]@NullSecurityXDisclosure
The post announces a critical RCE in Wazuh Cluster (CVE‑2026‑25769) that can give root access from a compromised worker node, with a video walk‑through linked to explain the issue.
Nicolas Krassas[verified]@DinosnDisclosure
A new CVE-2026-25769 critical RCE vulnerability in Wazuh via unsafe deserialization has been disclosed, with a blog post linking to more details.
NullSecurityX[verified]@NullSecurityXPoC
The post shares a video that demonstrates how CVE-2026-25769 enables a single compromised worker node to achieve root access on a Wazuh master, offering detection and defense guidance.
Co11ateral[verified]@co11ateralPoC
A proof‑of‑concept exploit for CVE‑2026‑25769, an RCE via insecure deserialization in Wazuh, is published on GitHub, with no evidence of live attacks or patches mentioned.
Lucas[verified]@lucasverdanDisclosure
A new critical Wazuh vulnerability (CVE-2026-25769) that allows remote code execution via insecure deserialization on the master node has been disclosed, with no evidence of exploitation or patch availability.
Jason Abernathy[verified]@jlabernathyGeneral
The post highlights the discovery of CVE-2026-25769—a critical remote code execution vulnerability in Wazuh cluster deployments—without providing any PoC, exploit, patch, or evidence of active exploitation.