Hacktron AI[verified]@HacktronAIDisclosure
This tweet announces the discovery of a Pre‑Auth RCE in OpenAM via jato.clientSession (CVE‑2026‑33439) and links to a blog post that likely contains further details or a PoC.
Ryx[verified]@PadhiyarRushiExploit
The post announces a PoC for an OpenAM pre-auth RCE and explicitly describes a standalone Python exploit with attack mechanics and a link to exploit details.
Lyrie.ai[verified]@lyrie_aiDisclosure
The tweet announces the critical CVE‑2026‑33439 remote code execution flaw in ForgeRock OpenAM, highlights existing PoCs on GitHub, and urges an immediate patch to version 16.0.6.
Gray Hats@the_yellow_fallPatch
A critical RCE in OpenAM (CVE‑2026‑33439) is disclosed, and users are urged to patch to version 16.0.5 to mitigate unauthenticated OS command execution.
ET Labs@ET_LabsDisclosure
The post announces two new CVE identifiers for Apache ActiveMQ and OpenAM in a ruleset update, providing only product and CVE information without any exploits, patches, or evidence of active use.
Threat Intelligence@threatintelDisclosure
The tweet announces CVE-2026-33439, a Pre-Auth Remote Code Execution vulnerability in OpenAM, and points to a Symantec protection bulletin for further details.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces a critical CVE-2026-33439 affecting OpenAM versions ≤16.0.5 with a pre‑authentication remote code execution flaw. No PoC, exploit, patch, or active exploitation details are provided.
cybrmonk@cybr_monkExploit
The post announces that CVE-2026-33439 in OpenAM has a publicly available exploit enabling unauthenticated remote command execution, with an explicit PoC but no evidence of current attacks.