References https://www.twcert.org.tw/tw/cp-132-8339-570fa-1.html https://www.twcert.org.tw/tw/cp-132-10319-adc18-1.html https://infosec.fcu.edu.tw/vulnerability/cve-2025-8853/ https://ycrc.edu.tw/show_news.php?id=662 https://lic.nuk.edu.tw/p/406-1012-84010,r73.php?Lang=zh-tw https://tp2rc.tanet.edu.tw/node/1127 https://www.cvedetails.com/cve/CVE-2025-8853/ http://www.2100t.com.tw/web/
Related VulnerabilitiesPoCCVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization BypassPoCCVE-2026-49468: LiteLLM Proxy < 1.84.0 - Host Header Authentication BypassPoCCVE-2026-56681: 9router <=0.5.4 - Authentication BypassPoCCVE-2026-89013: Dolibarr < 24.0.0 - Authorization Bypass via hashp ParameterPoCCVE-2026-80099: Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC SecretPoCCVE-2026-42018: JFrog Artifactory - Anonymous Token Disclosure via Trailing Slash Auth BypassPoCCVE-2026-86218: N-able N-central <2026.3.1.14 - Pre-Authentication Remote Code ExecutionPoCCVE-2026-18072: Advanced Responsive Video Embedder 10.8.7/10.8.8 - Hardcoded Backdoor Authentication BypassPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCarangodb-auth-bypass: ArangoDB - Authentication Bypass via URL-Encoded Underscore (%5f) to RCEPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-0650: OpenFlagr <= 1.1.18 - Authentication BypassPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization Bypass