Upwind Security MDR[verified]@UpwindMDRDisclosure
MISP faces two high‑severity CVEs—one involving mass assignment via unvalidated primary keys and another exposing OAuth 2.0 weaknesses—both fixable by upgrading to the latest version.
CERT-PY@CERTpyGeneral
The post announces three MISP CVEs and links to a CERT page for more information, but provides no technical or exploit details.
Cyber Threat Observatory | Alan Turing Institute@TuringCyberObsDisclosure
The report announces a new CVE‑2026‑56422 vulnerability—a user‑auth Bypass enabling manipulation of identifiers—without providing exploit code or patch details.
VulDB 🛡@vuldbActive Exploitation
The post indicates attackers are actively targeting the MISP CVE-2026-56422 vulnerability, but no PoC, exploit code, patch, or technical details are shared.
Infoflowcloud@infoflowcloudDisclosure
The post announces the existence of CVE-2026‑56422 with some technical detail but does not provide any PoC, exploit, patch, or evidence of active exploitation.
CVE@CVEnewDisclosure
The text announces CVE‑2026‑56422, describing how MISP controllers can accept untrusted request fields, but provides no PoC, exploit code, patch, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE-2026-56422, highlighting that improper input validation in MISP Core Controllers can lead to unauthorized object manipulation, but it does not provide exploit code, patch details, or evidence of active exploitation.