High 7.1
CVE-2026-32882
Exploitation of CVE-2026-32882 in libheif and OpenAI SSO Misconfiguration
Vendor / product: libheif
Event date: 2026-09-18
Victim organization: OpenAI
Public PoC: Yes
First tracked by RiskWire: 2026-09-20
Named threat actors
Hacktron
Sources & citations (4)
- Claude Opus 5 Hacked OpenAI's Private Code Repo: Memory Defense Bypassed in Hours techtimes.com · 2026-09-19
- AI Didn't Hack OpenAI. A Missed Debian Backport and an SSO Misconfiguration Did dev.to · 2026-09-20
- Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws thehackernews.com · 2026-09-19
- StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento dev.to · 2026-09-19
References
See CVE-2026-32882 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →