CVE@CVEnewDisclosure
The post announces CVE-2026-32985, detailing an unauthenticated arbitrary file upload flaw in Xerte Online Toolkits' template import feature, with a link to the official CVE record.
The Hacker Wire@TheHackerWireDisclosure
The post discloses CVE-2026-32985 as an unauthenticated arbitrary file upload vulnerability in Xerte Online Toolkits 3.14 and earlier, detailing the affected functionality but providing no exploit, patch, or active exploitation information.
0day Signal@0dayPublishingDisclosure
The tweet announces CVE-2026-32985, a vulnerability in Xerte Online Toolkit that allows unauthenticated ZIP upload bypass and webshell deployment via path traversal.
CVEFind.com@CveFindComDisclosure
A critical unauthenticated file upload vulnerability in Xerte Online Toolkits enabling remote code execution has been disclosed; no exploit, patch, or active exploitation details are included.