Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Alert Feeds
  • Cohesity TranZman Migration Appliance – 5 CVEs (command injection, LPE, unsigned patches, weak crypto)  – Full Disclosure
AttackFeed by Joe Wagner | Cohesity TranZman Migration Appliance - 5 CVEs (command injection, LPE, unsigned patches, weak crypto)  - Full Disclosure

Cohesity TranZman Migration Appliance – 5 CVEs (command injection, LPE, unsigned patches, weak crypto)  – Full Disclosure

Posted on March 12, 2026 By Joe-W
Alert Feeds

 

Posted by GregD via Fulldisclosure on Mar 12

Hi,

I’m disclosing five vulnerabilities discovered during an authorised
security assessment of the Cohesity TranZman Migration Appliance
(formerly Stone Ram TranZman), Release 4.0 Build 14614.

CVE-2025-67840 – Web API Command Injection (CVSS 7.2 High)
The /api/v1/scheduler/run and /api/v1/actions/run endpoints allow
authenticated administrators to execute arbitrary commands as root by
injecting into POST request parameters. Input is…
 – Read More  – Full Disclosure 

Post navigation

❮ Previous Post: Alipay DeepLink+JSBridge Attack Chain: Silent GPS Exfiltration, 17 Vulns, 6 CVEs (CVSS 9.3)  – Full Disclosure
Next Post: APPLE-SA-03-11-2026-2 iOS 15.8.7 and iPadOS 15.8.7  – Full Disclosure ❯

You may also like

AttackFeed by Joe Wagner | bmcweb (OpenBMC web server): four vulnerabilities — two unfixed, GHSA without a CVE  - Full Disclosure
Alert Feeds
bmcweb (OpenBMC web server): four vulnerabilities — two unfixed, GHSA without a CVE  – Full Disclosure
June 1, 2026
AttackFeed by Joe Wagner | APPLE-SA-03-24-2026-9 Safari 26.4  - Full Disclosure
Alert Feeds
APPLE-SA-03-24-2026-9 Safari 26.4  – Full Disclosure
March 28, 2026
AttackFeed by Joe Wagner | [IWCC 2026] CfP: 15th International Workshop on Cyber Crime - Linköping, Sweden, Aug 24-27, 2026  - Full Disclosure
Alert Feeds
[IWCC 2026] CfP: 15th International Workshop on Cyber Crime – Linköping, Sweden, Aug 24-27, 2026  – Full Disclosure
April 29, 2026
AttackFeed by Joe Wagner | [SECURITY ADVISORY] CVE-2026-34474 - ZTE H298A/H108N Unauthenticated Admin Credential Exposure  - Full Disclosure
Alert Feeds
[SECURITY ADVISORY] CVE-2026-34474 – ZTE H298A/H108N Unauthenticated Admin Credential Exposure  – Full Disclosure
May 25, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.