CVE-2026-36537Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-17: 1Technical Details · 2026-06-17: 106-17
Signal classification1 categories
Disclosure
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-36537 (CVSS 9.8): OAuth authorization code exchange auth bypass in ThingsBoard v4.3.0.1. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJUaGluZ3NCb2FyZCI%3D 🎯14K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="ThingsBoard" 🔖Refer: https://nvd.nist.gov/vuln/detail/CVE-2026-36537 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    This post announces the CVE‑2026‑36537 (OAuth authorization code exchange auth bypass in ThingsBoard v4.3.0.1) and shares FOFA search results showing many potential affected instances, but it provides no evidence of exploitation, a PoC, or a patch.

    07142174.3K
    14.6K followersView on X

Explore more