August 28, 2026
- Essity disclosed two HackerOne reports: a critical blind SQL injection in
/api/WDMProductwith stacked queries and potential OS command execution (report), and pre-auth stored XSS in unauthenticatedContactApiendpoints with cross-tenant impact (report). · Exploitation & Vulnerabilities
in Australia Charges Two Over the TeamPCP Supply-Chain Spree