White Rabbitx 🏴☠️[verified]@TheRabbitPyDisclosure
A critical Juju Dqlite authentication bypass (CVE-2026-4370) has been disclosed with a CVSS of 10.0, affecting specified Juju versions; patches 3.6.20/4.0.5 are available to mitigate the issue.
maruomosquit[verified]@maru1151157Patch
CVE-2026-4370 is a critical TLS authentication flaw in Juju that enables unauthenticated attackers to connect to the dqlite database, and users are advised to upgrade to patched versions.
Gray Hats@the_yellow_fallPatch
The tweet announces the CVE-2026-4370 TLS flaw with a 10.0 CVSS score and urges users to apply the 3.6.20 or 4.0.5 patch to mitigate the risk.
CrowdCyber 🌐@CrowdCyber_ComDisclosure
The post announces CVE-2026-4370 with a CVSS 10 score but lacks technical specifics, PoC, or mitigation guidance.
PulsePatch.io@pulsepatchioDisclosure
A new critical CVE (CVE‑2026‑4370) affecting Juju’s TLS authentication has been disclosed, highlighting the need to review TLS configurations; no evidence of exploitation or patch availability is mentioned.
CTIWatch@ctiwatchcloudGeneral
The post lists three CVE identifiers with high CVSS scores and a link to a vulnerabilities page, but offers no details on exploits, PoCs, patches, or active exploitation.
CosmicBytez@CosmicBytezPatch
The advisory announces a TLS authentication bypass in Juju Dqlite Cluster (CVE‑2026‑4370) that enables unauthenticated database access, highlighting that a vendor patch exists but offers no PoC or exploitation details.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑4370, detailing that Juju versions 3.2.0‑3.6.19 and 4.0‑4.0.4 are affected by a database cluster issue, but provides no PoC, exploit, patch, or evidence of active exploitation.