Aretiq.AI[verified]@AretiqAIExploit
The bulletin announces several critical CVEs in Tencent/APIJson, Spip, and Dokploy, noting that proof‑of‑concepts and functional exploits are available, with no mention of patches or active exploitation.
Hugo | DevOps | Cybersecurity 🇱🇻[verified]@HugoValtersPatch
CVE‑2026‑66738 is a critical code injection flaw in SPIP versions before 4.4.18 that allows authenticated editors to achieve remote code execution via the SQLite navigation endpoint; urgent patching or isolation is recommended.
CVE@CVEnewDisclosure
A code injection vulnerability (CVE-2026-66738) was disclosed in SPIP versions prior to 4.4.18, affecting SQLite-backed installations through the navigation menu endpoint.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces a code injection flaw in SPIP versions before 4.4.18 affecting SQLite installations, providing some technical detail but no PoC, exploit code, patch information, or evidence of active exploitation.