CVE-2026-81578 (CVSS 8.8) + CVE-2026-82078 (CVSS 9.4) can be chained from unauthenticated configuration manipulation to arbitrary Java code execution. The interesting part: the initial emergency patch was bypassed, leading to Emergency Patch Release 2. My technical breakdown covers the exploit chain, Udydn.class, Derby/JDBC activity, IOCs, Sigma/YARA detection, and incident-response steps.
2 Comments
solrize@lemmy.ml · 6 pts · 6d
From the linked post:
a_postmodern_hat@lemmy.world · 4 pts · 6d
UnLocoPoco@lemmy.world · 1 pts · 5d
Don't forget...windows in 2026 is made by microslop so expect more of these trivial things to pop up even more here and there