Upwind Security MDR[verified]@UpwindMDRPatch
Apache OFBiz versions prior to 24.09.06 suffer a hard‑coded key vulnerability; users are urged to upgrade to the patched release to remediate.
ADK Cyber[verified]@ADKCyberPatch
The post announces CVE-2026-31986—a hard‑coded key vulnerability in Apache OFBiz—and recommends upgrading to 24.09.06, without providing exploit or PoC details.
The Cyber Security Hub™[verified]@TheCyberSecHubDisclosure
A new pre‑authentication remote code execution vulnerability (CVE‑2026‑31986) impacting Bonita and OFBiz servers has been disclosed; no PoC, exploit, or patch information is provided.
Shah Sheikh[verified]@shah_sheikhDisclosure
The article announces a new pre‑authentication RCE vulnerability (CVE‑2026‑31986) affecting Bonita and OFBiz servers, explaining how an unauthenticated web request can trigger internal API execution, but it does not discuss PoC, exploit tools, active attacks, or patches.
Tony Cleal CISSP, SSCP, CISA, CISM, GCIH@tony_clealExploit
The article discloses CVE‑2026‑31986, a pre‑authentication RCE in Bonita Ofbiz, provides PoC and exploit code, details the technical aspects and CVSS score, and notes a vendor patch, but does not report active exploitation.
Help Net Security@helpnetsecurityDisclosure
The tweet announces a pre‑authentication remote code execution vulnerability (CVE‑2026‑31986) affecting Bonita and OFBiz Java servers, providing basic technical details but no patch, exploit, or PoC information.
selva@SelvaKtm2Patch
The message announces that Apache OFBiz is affected by CVE-2026-31986, an unauthenticated remote code execution vulnerability, and that a patch is available.
cybersecuritypath@cybrsecpathPatch
The post announces an Apache OFBiz patch for CVE-2026-31986, which is an unauthenticated remote code execution flaw, and does not provide PoC or exploit details.