
⚠️⚠️ CVE-2026-57149 (CVSS 9.9) + CVE-2026-55247 (CVSS 9.1) + CVE-2026-55248 (CVSS 9.1): Plone patch bundle — Classic portlet TALES injection to RCE (auth + portlet mgmt required) plus http://plone.app.event DoS/SSRF/XSS issues. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJQbG9uZSI= 🎯17.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Plone" 🔖Refer: https://securityonline.info/plone-rce-vulnerability/ #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
The post announces three high‑severity CVEs affecting Plone, details the exploitation vectors (TALES injection to RCE, DoS/SSRF/XSS), and provides a security advisory link.
