<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Srimax</title><description>Actively exploited vulnerabilities affecting Srimax products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/srimax.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-27920 — Srimax Output Messenger Directory Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-27920</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-27920</guid><description>This directory traversal flaw in Output Messenger, a workplace messaging platform, lets an attacker step outside the application&apos;s intended file boundaries to read arbitrary files on the server — including configuration files that may contain credentials or sensitive settings. Notably, the vulnerability was exploited as a zero-day by a threat actor tracked as Marbled Dust in a regional espionage campaign, meaning real-world, targeted attacks occurred before a fix was publicly available.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate><category>Srimax</category><category>Output Messenger</category></item></channel></rss>