Firmis Labs[verified]@FirmisLabsGeneral
The text cites CVE-2026-33746 with a high CVSS score of 9.8/10, but provides no further details on exploitation or remediation.
IntegSec[verified]@integ_secGeneral
The text references CVE-2026-33746 as an authentication bypass in Convoy KVM Panel, but provides no further detail on PoC, exploit, or remediation steps.
Gray Hats@the_yellow_fallPatch
Convoy KVM’s CVE-2026-33746 is a critical 9.8 CVSS flaw that allows unauthenticated admin access via forged JWTs; users are urged to upgrade to v4.5.1 immediately.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE-2026-33746 as a critical flaw in Convoy’s JWT authentication, providing technical details but no exploits, patches, or evidence of active use.
CVEFind.com@CveFindComPatch
The post highlights a critical CVE-2026-33746 in Convoy KVM server management panel that permits JWT forging and user impersonation, and notes that a patch is available.
CVE@CVEnewDisclosure
CVE-2026-33746 is disclosed as a JWT verification flaw in Convoy KVM panel versions 3.9.0-beta through 4.5.1, with technical details presented but no mention of PoCs, exploits, or patches.
0day Signal@0dayPublishingDisclosure
The message announces CVE-2026-33746, describing a JWT signature bypass in Convoy that lets attackers forge user UUIDs to gain full control of the hosting panel, and links to a site for further details.