References https://www.twcert.org.tw/tw/cp-132-10620-527f1-1.html https://www.twcert.org.tw/newepaper/cp-151-10620-527f1-3.html https://www.appsecure.security/vulnerability-database/cve-2026-0853/ https://www.twcert.org.tw/tw/lp-132-1-3-20.html https://www.twcert.org.tw/newepaper/lp-151-3-2-20.html https://www.openinfosec.com/zh/shareArticle/content/1693
Related VulnerabilitiesPoCserverless-framework-config-exposure: Serverless Framework - Configuration ExposurePoCterraformrc-credentials-exposure: Terraform CLI Configuration - Credentials ExposurePoCterraform-tfstate-exposure: Terraform State - File ExposurePoCCVE-2026-89063: Bookly <=28.1 - IDOR Unauthenticated Sensitive Data AccessPoCmcp-streamable-http-exposure: MCP Streamable HTTP Server - Unauthenticated Initialize融易網路|GPM LIGHT - Sensitive Data ExposurePoCCVE-2026-6639: AI Copilot Content Generator <=1.4.6 - Unauthenticated Task Data ExposurePoCpowerdns-monitor-exposure: PowerDNS Authoritative Server Monitor - Unauthenticated ExposurePoCqdrant-telemetry-exposure: Qdrant - Telemetry ExposurePoCflowise-chatflows-exposure: Flowise AI - Unauthenticated Chatflows API ExposurePoClangflow-api-exposure: Langflow - Unauthenticated API ExposurePoCCVE-2026-42221: Nginx UI <= 2.3.7 - Unauthenticated Installer ExposurePoCgrafana-loki-api-exposure: Grafana Loki - Unauthenticated API Access