Chocapikk 🤘🏻[verified]@Chocapikk_Exploit
Three new CVEs in openDCIM allow unauthenticated RCE, with a functional exploit already available on GitHub.
dbugs[verified]@ptdbugsExploit
The report outlines a high‑severity CVE chain in openDCIM that leads to RCE via SQL injection and command execution, provides a GitHub exploit for demonstration, yet does not confirm active exploitation or patches.
Michael Martino[verified]@battista212Active Exploitation
The text reports an active openDCIM exploitation campaign using CVE‑2026‑28515 and CVE‑2026‑28517 to drop PHP webshells, and advises verifying February patches and removing installation artifacts.
Caitlin Condon@catc0nActive Exploitation
The tweet reports a first-time exploitation of openDCIM CVE-2026-28515 and CVE-2026-28517, with an attacker dropping PHP webshells, but does not provide a PoC, exploit tool details, or patch information.
CVE@CVEnewDisclosure
The text announces an OS command injection vulnerability in openDCIM 23.04, specifically in report_network_map.php, and references the CVE record for further details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The tweet announces CVE-2026-28517, an OS command injection flaw in openDCIM 23.04, but provides no PoC, exploit code, or patch details.