Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #2
RaspAP hit with three unpatched CVE disclosures
Original: π¨ RaspAP Mass Disclosure β 3 CVEs, no patch CVE-2026-101860 (CVSS 8.8) β privilege escalation via sudoers manipulation β
Security researchers have disclosed three vulnerabilities in RaspAP, the popular router software for Raspberry Pi, with no patches available. The most severe, CVE-2026-101860 with a CVSS score of 8.8, allows privilege escalation to root via sudoers manipulation. Two further flaws, CVE-2026-101859 (5.4) and CVE-2026-101858 (4.7), involve OS command injection, including through the OpenVPN handler and WiFiManager SSID handling.
Why now: Unpatched vulnerabilities with root access implications on widely used Raspberry Pi router software raise immediate concern for users of exposed devices
RaspAPRaspberry PiCVE-2026-101860
Rank over time, top of the chart is #1. 2 snapshots from 4 h ago to 4 h ago.
Evidence
- π¨ RaspAP Mass Disclosure β 3 CVEs, no patch CVE-2026-101860 (CVSS 8.8) β privilege escalation via sudoers manipulation β root on the Pi CVE-2026-101859 (CVSS 5.4) β OS command injection, OpenVPN handler CVE-2026-101858 (CVSS 4.7) β OS command injection, WiFiManager SSID Publicβ¦ Β· threataft@infosec.exchange Β· 2
API: https://socialmediatrends-api.osmike.com/v1/trends/385039