Divert[verified]@Divert_SecurityDisclosure
The tweet announces the disclosure of CVE-2026-29058, describing an AVideo command injection vulnerability and noting that probes were detected, without revealing PoC, exploit code, or patch details.
Gray Hats@the_yellow_fallPatch
The tweet announces a critical CVE-2026-29058 flaw in AVideo‑Encoder that allows remote command execution and urges immediate patching.
iototsecnews@iototsecnewsDisclosure
The article reports the discovery of CVE‑2026‑29058, an OS command injection flaw in AVideo that allows attackers to fully compromise servers with a single crafted request, but offers no evidence of exploitation or mitigation steps.
Hackviser@hackviserrDisclosure
The post announces a new CVE (2026-29058) exposing unauthenticated command injection and remote code execution in AVideo Encoder, emphasizing that an environment is prepared for exploitation.
CRAC Learning - Tech@cracbotDisclosure
Announces a critical CVE (CVE-2026-29058) affecting AVideo before version 7.0, noting an unauthenticated exploit that allows arbitrary OS command execution.
StrongKeep Cybersecurity@StrongKeepCyberPatch
The post warns SMBs of a zero‑click command injection in AVideo (CVE‑2026‑29058) and urges immediate patching to mitigate the risk.
CVE@CVEnewDisclosure
CVE-2026-29058 discloses that pre‑7.0 versions of AVideo allow unauthenticated attackers to execute arbitrary OS commands through shell command injection.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces a new unauthenticated remote code execution vulnerability in AVideo Platform versions prior to 7.0, providing the CVE identifier and a link to a generic vulnerability details page.