<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:peering-Manager:peering_manager:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apeering-managerpeering_manager/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 13:09:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apeering-managerpeering_manager/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution Vulnerability in Nextcloud</title><link>https://feed.craftedsignal.io/briefs/2026-09-nextcloud-rce/</link><pubDate>Thu, 17 Sep 2026 13:09:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-nextcloud-rce/</guid><description>A critical vulnerability in Nextcloud Hub, tracked as CVE-2024-28112, allows remote attackers to execute arbitrary code on the underlying application server.</description><content:encoded><![CDATA[<p>Nextcloud has released a security advisory addressing a remote code execution (RCE) vulnerability, identified as CVE-2024-28112. This flaw exists within the Nextcloud Hub software and stems from the improper handling of user-supplied input during request processing. An unauthenticated or remote attacker can leverage this vulnerability to inject and execute malicious code on the application server. This level of compromise grants the attacker the ability to read, modify, or delete sensitive data stored within the Nextcloud environment and potentially pivot into the wider network infrastructure. Given the critical nature of the vulnerability, organizations running Nextcloud Hub should prioritize patching their instances to the vendor-recommended version immediately.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2024-28112 allows an attacker to achieve full remote code execution on the server hosting Nextcloud. This provides the actor with unauthorized access to file stores, user credentials, and database contents, potentially leading to total system compromise and data exfiltration.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all internet-facing Nextcloud Hub instances and audit logs for anomalous POST requests or unexpected child processes spawned by the web server user.</li>
<li>Apply the security update provided by Nextcloud to resolve CVE-2024-28112 immediately.</li>
<li>Review web server access logs for requests containing suspicious payload patterns that could indicate attempted exploitation of the input handling flaw.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>web-application</category><category>vulnerability</category><category>rce</category></item></channel></rss>