
⚠️⚠️ CVE-2026-57149 (CVSS 9.9) + CVE-2026-55247 (CVSS 9.1) + CVE-2026-55248 (CVSS 9.1): Plone patch bundle — Classic portlet TALES injection to RCE (auth + portlet mgmt required) plus http://plone.app.event DoS/SSRF/XSS issues. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJQbG9uZSI= 🎯17.7K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Plone" 🔖Refer: https://securityonline.info/plone-rce-vulnerability/ #OSINT #FOFA #CyberSecurity #Vulnerability
Post summary
The post announces three high‑severity Plone CVEs, details their technical aspects (RCE, DoS, SSRF, XSS), provides FOFA search references, and indicates a patch bundle is available, but does not supply PoC code or evidence of active exploitation.




