
5/ CVE-2026-33359 (CVSS 7.5) : Motion alert images, forever. When your camera detects motion, it uploads a JPEG to Alibaba OSS. The URL is broadcast in the MQTT stream. No signed URLs. No expiry. No auth. The link works for anyone, forever.
Post summary
CVE-2026-33359 reveals that motion‑triggered JPEGs uploaded to Alibaba OSS are publicly accessible via URLs that never expire, lacking authentication or signed URLs. The post provides an overview of the vulnerability but no exploitation code, patch, or evidence of active attacks.

