Sami Laiho[verified]@samilaihoPatch
CVE-2026-67308 is a critical shell injection flaw in Wazuh GitHub Actions with an official fix available and PoC-level exploitation demonstrated, rated CVSS 10.0.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The tweet discloses a critical shell injection flaw in Wazuh GitHub Actions that permits arbitrary command execution and secret exfiltration; upgrading to commit 44bf114 resolves the issue.
Xavier Rivera[verified]@XavierRiveraXGeneral
The NVD has assigned CVE-2026-67308 as a shell injection flaw in Wazuh GitHub Actions that allows arbitrary command execution via a crafted VERSION.json, but the post provides no evidence of exploitation or remediation.
SecAlerts@SecAlertsCoActive Exploitation
CVE-2026-67308 allows shell injection via a malicious VERSION.json in GitHub Actions, is actively being exploited in the wild, and has been patched in commit 44bf114+.
VulDB 🛡@vuldbActive Exploitation
The brief alert indicates that elevated activity has been detected targeting the Wazuh Workflows CVE-2026-67308, suggesting that the vulnerability is currently being used in active attacks.
ThreatAft@ThreatAftDisclosure
A new CVE (CVE-2026-67308) is disclosed with detailed exploitation method and CVSS rating, but no PoC, tool, or active exploitation evidence is provided.
VulDB 🛡@vuldbDisclosure
A severe vulnerability (CVE-2026-67308) has been disclosed for Wazuh Workflows, with a reference to a VulDB entry, but no PoC, exploitation details, patches, or technical specifics are mentioned.