FOFA[verified]@fofabotDisclosure
The tweet announces four high‑severity vulnerabilities (CVE‑2026‑39893, CVE‑2026‑39948, CVE‑2026‑39955, CVE‑2026‑39938) in Cacti ≤ 1.2.30, highlighting pre‑authentication SQLi and LFI issues; it provides FOFA search links and a reference page for further details.
Hunter[verified]@HunterMappingDisclosure
The post announces three high‑CVSS SQL injection flaws in Cacti, citing their CVEs and linking to advisories and an external service scan, but it provides no exploitation proof or remediation guidance.
セキュリティ対策Lab[verified]@securityLab_jpPatch
The post announces four CVEs affecting the Cacti monitoring framework and refers readers to a link that likely details exploits fixes, focusing on mitigation rather than exploitation.
TECHEPAGES[verified]@techepagesDisclosure
Three Cacti CVEs (39893, 39955, 39938) with CVSS 9.8 enable unauthenticated SQL injection and local file inclusion; users are urged to upgrade to version 1.2.31.
ExploitGrid@exploitgridActive Exploitation
The post enumerates CVEs with publicly available exploits, confirms at least one is actively used in the wild, and provides basic technical details but no patches or debunking.
Daily CyberSecurity@the_yellow_fallPatch
The tweet warns of critical pre-auth SQL injection and LFI flaws in Cacti 1.2.30 and recommends applying the 1.2.31 update.
CERT-PY@CERTpyDisclosure
The post announces three new CVE vulnerabilities affecting Cacti products and directs readers to external links for additional information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The snippet announces a new unauthenticated local file inclusion vulnerability (CVE‑2026-39938) in Cacti 1.2.30 and earlier versions, directing readers to a Vulmon page for details.