Exploit achieved unauthenticated remote code execution roughly 20 hours after disclosure.
Part of the PlainSec briefing for 2026-03-26