View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

SafePal breach exposes order data of nearly 40,000 customers

💥 BREACHES & INCIDENTS

  • SafePal breach exposes order data of 39,798 customers
    SafePal disclosed a breach exposing personal order information of 39,798 customers.
    • SafePal customers who placed orders between March 2, 2025, and April 11, 2026, were affected.
    • Names, email addresses, shipping addresses, phone numbers, and purchase details were exposed.
    • An authorization flaw in SafePal’s order-tracking plug-in enabled access to other customers’ order records.
    • Scammers used the exposed data in phishing and impersonation attempts through fraudulent websites and links.
      📄 Source: safepal.com · 📎 Coverage: theblock.co · 👁 via BleepingComputer

🔓 CVEs & KEV

  • CVE-2026-19961 — CVSS 8.6 — Edimax EW-7478APC formWlSiteSurvey buffer overflowA vulnerability was detecte...

  • CVE-2026-19959 — CVSS 8.6 — Edimax EW-7478APC formWanTcpipSetup stack-based overflowA weakness has been i...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check