Chocapikk 🤘🏻[verified]@Chocapikk_Exploit
The post announces three new CVEs for openDCIM and provides a PoC and functional exploit chain leading to an unauthenticated RCE, but does not mention patches or evidence of active exploitation.
dbugs[verified]@ptdbugsExploit
Researchers revealed a chain of CVEs in OpenDCIM that lead from SQL injection to RCE, provided detailed technical info and a publicly available exploit tool, but did not report any active exploitation or patches.
Michael Martino[verified]@battista212Active Exploitation
The post reports an ongoing exploitation campaign targeting openDCIM using CVE-2026-28515 and CVE-2026-28517, advises verifying February patches, and notes a single source IP.
Caitlin Condon@catc0nActive Exploitation
Canaries detected first‑time exploitation of openDCIM CVE‑2026‑28515 and CVE‑2026‑28517 with PHP webshells dropped by a single Chinese IP, indicating active attacks.
Gray Hats@the_yellow_fallActive Exploitation
Hackers are actively exploiting three openDCIM CVEs (CVE‑2026‑28515/28516/28517) via sub‑second unauthenticated remote code execution, highlighting an urgent need for data center security measures.
CVETrends@CVEShieldGeneral
The post simply lists five CVE identifiers as trending, without providing any additional context, technical details, or actionable information.
CVE@CVEnewDisclosure
The CVE-2026-28515 vulnerability in openDCIM 23.04 is a missing authorization flaw in installer scripts, as disclosed in the CVE record.
CVETrends@CVEShieldGeneral
The post merely lists five trending CVEs without providing any details on exploitation, mitigation, or technical specifics.