Hunter[verified]@HunterMappingDisclosure
The post announces two high‑severity RCE CVEs affecting Spinnaker pipelines, providing basic details and links to advisories, but no PoC, exploit code, or mention of active exploitation.
LeftenantZero[verified]@LeftenantZeroDisclosure
The author disclosed two 10.0 severity Spinnaker vulnerabilities (CVE-2026-32604 and CVE-2026-32613) that enable code execution and pivoting, with a linked blog post presumably containing further details.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces critical unauthenticated RCE vulnerabilities in Spinnaker’s clouddriver component (CVE-2026-32604/CVE-2026-32613) with a high CVSS score and potential for command execution via SPeL.
ZeroPath[verified]@ZeroPathAIPoC
The post announces a YouTube walkthrough demonstrating exploitation of two Spinnaker CVEs for code execution and production access, but does not provide functional code, a patch, or evidence of active exploitation.
ZeroPath[verified]@ZeroPathAIPoC
Two new CVE‑2026‑32604 and CVE‑2026‑32613 flaws in Spinnaker are disclosed with CVSS 10.0 and an associated PoC write‑up is provided at Zeropath.
LeftenantZero[verified]@LeftenantZeroPoC
The post announces CVE‑2026‑32604 and CVE‑2026‑32613 and asserts that full technical details along with working proof‑of‑concepts are available, though it does not discuss patches, active exploitation or debunking.
LeftenantZero[verified]@LeftenantZeroExploit
A YouTube video demonstrates exploitation of two Spinnaker CVEs, providing PoC and script, but does not report real‑world attacks or patches.
Can Artuc[verified]@canartucPatch
Spinnaker has released patches for the high‑severity CVE‑2026‑32613 remote takeover vulnerability, with backports across multiple release branches.