CVE-2026-67352Disclosure

LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

0.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-02: 2Patch / Workaround · 2026-08-02: 1Technical Details · 2026-08-02: 108-02
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-67352 - Stored XSS in Luci-App-Https-Dns-Proxy. Resolver_url injects HTML, runs JS in admin's browser. CVSS 7.6. No patch yet; restrict access. https://www.valtersit.com/cve/CVE-2026-67352 #CVE #infosec #XSS #cybersecurityawareness #cyebrsecuritytips #cybersecuritynews #devops #devsecops #developer #developers #git #gitlab #github #sysadmin #redteam #blueteam #python #linux #kali #hacker #ethicalhacker #ethicalhacking

    Post summary

    The post discloses a stored XSS vulnerability (CVE‑2026‑67352) in Luci‑App‑Https‑Dns‑Proxy, noting no patch yet and recommending restricting access, with a CVSS score of 7.6.

    0000071
    979 followersView on X
  • VulDB 🛡@vuldb
    General

    It is possible to see elevated activities targeting OpenWrt LuCI (CVE-2026-67352) https://vuldb.com/vuln/385307/cti

    Post summary

    The note hints at potential increased activity against OpenWrt's LuCI application linked to CVE‑2026‑67352, but offers no concrete evidence of exploitation or remedy.

    00000113
    2.3K followersView on X

Explore more