Tencent vulnerabilities
1 CVE tracked
This vendor appears in our reporting in two contrasting contexts. Tencent's Zhuque Lab discovered and exploited an 18-year-old critical Linux kernel SCTP use-after-free flaw to achieve container escape. Meanwhile, Tencent's own APIJSON product was found to have CVE-2026-72565, a critical unauthenticated remote SQL injection vulnerability. Defenders using APIJSON must immediately address CVE-2026-72565 for unpatched versions through 8.1.8, and should also consider the industry recommendation to deprecate the SCTP protocol to mitigate kernel-level container escape risks.
Azərbaycanca: Təchizatçı hesabatlarımızda bir-birinə zidd iki kontekstdə görünür. Tencent-in Zhuque Laboratoriyası 18 illik kritik Linux kernel zəifliyini (SCTP use-after-free) aşkar edərək konteynerdən qaçış imkanını nümayiş etdirmişdir. Digər tərəfdən, şirkətin öz məhsulu olan APIJSON-un CVE-2026-72565 identifikatorlu, autentifikasiya olunmadan uzaqdan SQL injection etməyə imkan verən kritik zəifliyi müəyyən edilmişdir. Müdafiəçi tərəf APIJSON istifadə edirsə, dərhal yamalanmamış `8.1.8` və aşağı versiyalar üçün CVE-2026-72565-ə qarşı tədbir görməli, eyni zamanda kernel səviyyəsində konteynerdən qaçış riskini azaltmaq üçün SCTP protokolunun deaktiv edilməsi tövsiyəsini nəzərdən keçirməlidir.
This vendor's CVEs1
This hub is built from skopnix's own reporting on Tencent: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.