OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
Critical RCE vulnerability CVE‑2026‑28370 in OpenStack Vitrage affecting multiple versions; patch or restrict API access immediately.
CVETodo[verified]@CveTodoDisclosure
CVE-2026-28370 is a critical RCE flaw in OpenStack Vitrage’s query parser caused by improper user input handling, allowing attackers with API access to execute code on the host. No PoC, exploit, patch, or active exploitation details are provided.
Open Source Security mailing list@oss_securityDisclosure
A new CVE (CVE‑2026‑28370) is disclosed, revealing RCE via the Vitrage API query parser; no PoC, exploit, patch, or active exploitation details are provided.
Gray Hats@the_yellow_fallPatch
Nokia reports a critical RCE vulnerability (CVE-2026-28370) in OpenStack Vitrage's RCA service, urging immediate patching to prevent host takeover.
PulsePatch.io@pulsepatchioDisclosure
A code execution vulnerability in OpenStack Vitrage’s query parser affecting API users has been disclosed; users should assess exposure and await official patches.
CRAC Learning - Tech@cracbotDisclosure
The post highlights a critical CVE (CVE-2026-28370) in OpenStack Vitrage's query parser affecting versions before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, with a CVSS score of 9.1, but provides no PoC, exploit, or patch details.
PulsePatch.io@pulsepatchioPatch
The post announces CVE‑2026‑28370, an eval injection flaw in OpenStack Vitrage, and advises updating to v15.0.1.
CVE@CVEnewDisclosure
OpenStack Vitrage’s query parser before versions 12.0.1, 13.0.0, 14.0.0, and 15.0.0 allows a user with API access to trigger code execution, indicating a remote code execution vulnerability.