Orizon[verified]@OrizonCyberPatch
The tweet announces a critical cryptographic vulnerability (CVE-2026-59099) affecting Apereo CAS 7.3.0, ratings it CVSS 9.1/10, and urges to apply the available patch.
ThreatAft@ThreatAftDisclosure
The article announces CVE-2026-59099, a critical AES‑GCM nonce reuse flaw in Apereo CAS, enabling decryption of webflow state and token forging by unauthenticated attackers; no exploitation evidence or patch information is provided.
Infoflowcloud@infoflowcloudDisclosure
The provided text announces CVE-2026-59099 as a cryptographic flaw in Apereo CAS that permits remote unauthenticated attackers to recover plaintext conversation data, with no mention of a PoC, exploit code, active use, or patch.
CVE@CVEnewDisclosure
The advisory discloses a cryptographic flaw in Apereo CAS 7.3.0‑8.0.0‑RC6 that permits remote unauthenticated attackers to gain plaintext conversation state.