
#AppSec 1⃣ RCE in the Electron desktop client via stored XSS in synced table captions https://github.com/advisories/GHSA-phhp-9rm9-6gr2 // Critical CVE-2026-39846, 9.1/10 2⃣ GhidraServer PKI User Impersonation via Null Signature https://github.com/califio/publications/tree/main/MADBugs/ghidra-server // Null-signature flaw in GhidraServer's PKI authentication module allows any user with a valid CA-signed certificate to impersonate any other user on the server 3⃣ SandboxJS: Sandbox integrity escape https://github.com/advisories/GHSA-2gg9-6p7w-6cpj // Critical CVE-2026-34208, 10/10
Post summary
The tweet lists three critical CVEs with links to GitHub advisories that contain proof‑of‑concept details and explains exploitation methods, yet it does not mention active exploitation or any patches.





