CCB Alert
@CCBalert
Followers
7K
Following
335
Media
145
Statuses
3K
CCB Alert is the advisory page of the Centre for Cybersecurity Belgium @CCBbelgium. Use [email protected] for interaction.
Belgium
Joined August 2009
Warning: Improper Input Validation vulnerability in #TeamViewer DEX Client affecting users with Content Distribution Service enabled. #CVE-2025-44016 CVSS: 8.8. The high-severity flaw can lead to #ArbitraryCodeExecution! #Patch #Patch #Patch More info: https://t.co/5kiP7VDNki
teamviewer.com
0
1
0
Warning: Critical Absolute Path Traversal in #Barracuda Service Center #RMM. #CVE-2025-34392 CVSS: 10.0. Remote attacker without authenticatiom or user interaction can exploit this vulnerability to write files and upload webshells, can lead to #RCE
https://t.co/LXQbggYnZ3
#Patch
0
0
0
Warning: Critical File Download vulnerability in #ConnectWise #ScreenConnect <25.8. #CVE-2025-14265 CVSS: 9.1. An authorized user can install untrusted extensions on the ScreenConnect server! #Patch #Patch #Patch More info: https://t.co/6hkZriTA7Y
connectwise.com
0
1
0
Warning: Unauthenticated XXE vulnerability in #GeoServer. #CVE-2025-58360 CVSS: 8.2. This now #ActivelyExploited flaw allows remote file reading and SSRF! #Patch #Patch #Patch More info: https://t.co/VI3YUBic5V
github.com
## Description An XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint ``/geoserver/wms`` operation ``GetMap``. However, this inp...
0
0
0
Warning: High Path Traversal in PutContents #API in #Gogs. CVE-2025-8110 CVSS: 8.7. This actively exploited #0Day can lead to local execution of code! Low privilege remote attackers can bypass security controls and achieve full system compromise. https://t.co/07QSaGplbm
#Patch
wiz.io
Wiz Research discovered a Gogs zero-day (CVE-2025-8110) that bypasses a previous RCE fix via symlinks, leading to file overwrite and remote code execution.
0
0
0
Warning: #FreePBX addresses an authentication bypass vulnerability, #CVE-2025-66039, in FreePBX Endpoint Manager, which allow unauthenticated logins to administrator control panel. More information can be found here: https://t.co/KhetDV0KDo
#Patch #Patch #Patch
github.com
### Summary Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header ### Description An authentication bypass vulnerability exists in the latest FreePBX versions ...
0
2
0
#Microsoft has released security patches for 56 vulnerabilities. 3 vulnerabilities were identified as critical, and 53 are classified as Important. 3 are 0-day vulnerabilities and 1 is actively exploited. Patches are available via Patch Tuesday. Time to #patch #patch #patch
0
0
2
Warning: 11 vulnerabilities were patched in #Advantech WISE-DeviceOnServer. The most critical CVE, #CVE-2025-34256 (CVSSv3 9.8), allows remote attackers to forge authentication tokens, enabling unauthorised access or session manipulation.#Path Patch #Patch
0
0
0
Warning: Command injection vulnerability in #ArrayNetworks AG Series. No CVE identifier assigned yet. This vulnerability has been actively exploited since August 2025 for remote code execution. Read their alert: https://t.co/Xw9HMnEDBE #RCE! #Patch #Patch #Patch
0
1
0