<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PoCs — PoC Archive</title><link>https://poc.intelseclab.com/pocs/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/pocs/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-21508-windows-mediaplayer-dll-hijack-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-21508-windows-mediaplayer-dll-hijack-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-21508. Status: Patched. Affects: Microsoft Windows Media Player / WUDFHost.exe. Tags: windows, dll-hijack, lpe, privilege-escalation, media-player, wudfhost, session0, com-hijack, CVE-2026-21508.</description><category>binary</category><category>High</category><category>windows</category><category>dll-hijack</category><category>lpe</category><category>privilege-escalation</category><category>media-player</category><category>wudfhost</category><category>session0</category><category>com-hijack</category><category>CVE-2026-21508</category></item><item><title>UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-34910, CVE-2026-34909, CVE-2026-34908. Status: Patched. Affects: Ubiquiti UniFi OS Server. Tags: ubiquiti, unifi, unifi-os, auth-bypass, path-traversal, command-injection, rce, unauth, kev, mirai, nginx, CVE-2026-34910.</description><category>network</category><category>Critical</category><category>ubiquiti</category><category>unifi</category><category>unifi-os</category><category>auth-bypass</category><category>path-traversal</category><category>command-injection</category><category>rce</category><category>unauth</category><category>kev</category><category>mirai</category><category>nginx</category><category>CVE-2026-34910</category></item><item><title>Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68398. Status: Patched. Affects: Linux Kernel (PPPoL2TP subsystem). Tags: linux, kernel, ubuntu, pppol2tp, l2tp, ppp, uaf, use-after-free, race-condition, lpe, privilege-escalation, kaslr-bypass, apparmor-bypass, suid, heap-spray, kmalloc-256, CVE-2026-68398.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>ubuntu</category><category>pppol2tp</category><category>l2tp</category><category>ppp</category><category>uaf</category><category>use-after-free</category><category>race-condition</category><category>lpe</category><category>privilege-escalation</category><category>kaslr-bypass</category><category>apparmor-bypass</category><category>suid</category><category>heap-spray</category><category>kmalloc-256</category><category>CVE-2026-68398</category></item><item><title>PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-17544-php-bcmath-oob-write/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-17544-php-bcmath-oob-write/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-17544 / GHSA-x692-q9x7-8c3f. Status: Patched (PHP 8.4.24 / 8.5.9). Affects: PHP (ext/bcmath). Tags: php, bcmath, oob-write, stack-smashing, rce, cwe-787, CVE-2026-17544.</description><category>web</category><category>Critical</category><category>php</category><category>bcmath</category><category>oob-write</category><category>stack-smashing</category><category>rce</category><category>cwe-787</category><category>CVE-2026-17544</category></item><item><title>nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42533. Status: Patched. Affects: nginx 1.30.1 (and likely earlier versions). Tags: nginx, pcre, heap-overflow, rce, preauth, info-leak, capture-variable, map-directive, aslr-bypass, CVE-2026-42533.</description><category>web</category><category>Critical</category><category>nginx</category><category>pcre</category><category>heap-overflow</category><category>rce</category><category>preauth</category><category>info-leak</category><category>capture-variable</category><category>map-directive</category><category>aslr-bypass</category><category>CVE-2026-42533</category></item><item><title>Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-23111. Status: Patched. Affects: Linux kernel (nf_tables subsystem). Tags: linux, kernel, nftables, nf-tables, uaf, catchall, lpe, privilege-escalation, slab-spray, kaslr-bypass, rop, namespace, CVE-2026-23111.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>nftables</category><category>nf-tables</category><category>uaf</category><category>catchall</category><category>lpe</category><category>privilege-escalation</category><category>slab-spray</category><category>kaslr-bypass</category><category>rop</category><category>namespace</category><category>CVE-2026-23111</category></item><item><title>Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-53361. Status: Patched. Affects: Linux Kernel (AF_UNIX socket garbage collector). Tags: linux, kernel, af-unix, garbage-collector, msg-peek, uaf, container-escape, lpe, slub, dirty-pagetable, CVE-2026-53361.</description><category>binary</category><category>Critical</category><category>linux</category><category>kernel</category><category>af-unix</category><category>garbage-collector</category><category>msg-peek</category><category>uaf</category><category>container-escape</category><category>lpe</category><category>slub</category><category>dirty-pagetable</category><category>CVE-2026-53361</category></item><item><title>Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-2764-firefox-jit-uaf/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-2764-firefox-jit-uaf/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-2764 / MFSA 2026-13. Status: Patched. Affects: Mozilla Firefox (SpiderMonkey JavaScript Engine). Tags: firefox, spidermonkey, jit, uaf, type-confusion, wasm, browser, ionmonkey, baseline, proxy, CVE-2026-2764.</description><category>binary</category><category>High</category><category>firefox</category><category>spidermonkey</category><category>jit</category><category>uaf</category><category>type-confusion</category><category>wasm</category><category>browser</category><category>ionmonkey</category><category>baseline</category><category>proxy</category><category>CVE-2026-2764</category></item><item><title>Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-8452-citrix-netscaler-saml-preauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-8452-citrix-netscaler-saml-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-8452. Status: Patched. Affects: Citrix NetScaler ADC and NetScaler Gateway. Tags: citrix, netscaler, adc, gateway, saml, heap-overflow, preauth, rce, shellcode, webshell, freebsd, xml-signature, c14n, CVE-2026-8452.</description><category>network</category><category>Critical</category><category>citrix</category><category>netscaler</category><category>adc</category><category>gateway</category><category>saml</category><category>heap-overflow</category><category>preauth</category><category>rce</category><category>shellcode</category><category>webshell</category><category>freebsd</category><category>xml-signature</category><category>c14n</category><category>CVE-2026-8452</category></item><item><title>Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2026-20200 / NSIDE-SA-2026-003. Status: Patched. Affects: Cisco Integrated Management Controller (CIMC). Tags: cisco, imc, cimc, argument-injection, rce, redfish, curl, reverse-shell, arm, file-read, file-write, CVE-2026-20200.</description><category>network</category><category>Critical</category><category>cisco</category><category>imc</category><category>cimc</category><category>argument-injection</category><category>rce</category><category>redfish</category><category>curl</category><category>reverse-shell</category><category>arm</category><category>file-read</category><category>file-write</category><category>CVE-2026-20200</category></item><item><title>Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7. Status: Patched (9.2.15 / 10.1.4). Affects: Apache Traffic Server. Tags: apache, traffic-server, ats, header-injection, metadata-spoof, cache-poisoning, acl-bypass, plugin, CVE-2026-33267.</description><category>web</category><category>Critical</category><category>apache</category><category>traffic-server</category><category>ats</category><category>header-injection</category><category>metadata-spoof</category><category>cache-poisoning</category><category>acl-bypass</category><category>plugin</category><category>CVE-2026-33267</category></item><item><title>Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-47301. Status: Patched. Affects: Microsoft Configuration Manager (SCCM / ConfigMgr), AdminService REST API. Tags: windows, sccm, configmgr, rce, cab, path-traversal, dll-hijacking, dll-proxy, arbitrary-file-write, system, microsoft, CVE-2026-47301.</description><category>network</category><category>Critical</category><category>windows</category><category>sccm</category><category>configmgr</category><category>rce</category><category>cab</category><category>path-traversal</category><category>dll-hijacking</category><category>dll-proxy</category><category>arbitrary-file-write</category><category>system</category><category>microsoft</category><category>CVE-2026-47301</category></item><item><title>Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64564. Status: Patched. Affects: Linux kernel, SCTP (Stream Control Transmission Protocol) ASCONF subsystem. Tags: linux, kernel, lpe, sctp, use-after-free, asconf, del-ip, heap-spray, packet-tx-ring, kaslr-bypass, credential-overwrite, debian, CWE-416, CVE-2026-64564.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>sctp</category><category>use-after-free</category><category>asconf</category><category>del-ip</category><category>heap-spray</category><category>packet-tx-ring</category><category>kaslr-bypass</category><category>credential-overwrite</category><category>debian</category><category>CWE-416</category><category>CVE-2026-64564</category></item><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64531. Status: Patched. Affects: Linux kernel, Open vSwitch (OVS) kernel module, conntrack subsystem. Tags: linux, kernel, lpe, openvswitch, ovs, conntrack, netlink, memory-corruption, sudoers, CVE-2026-64531.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>openvswitch</category><category>ovs</category><category>conntrack</category><category>netlink</category><category>memory-corruption</category><category>sudoers</category><category>CVE-2026-64531</category></item><item><title>Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-17106. Status: Patched. Affects: Docker Engine / Docker Desktop, docker cp CLI command. Tags: docker, container-escape, race-condition, symlink, path-traversal, runc, host-takeover, linux, macos, CWE-367, CWE-59, CVE-2026-17106.</description><category>binary</category><category>Critical</category><category>docker</category><category>container-escape</category><category>race-condition</category><category>symlink</category><category>path-traversal</category><category>runc</category><category>host-takeover</category><category>linux</category><category>macos</category><category>CWE-367</category><category>CWE-59</category><category>CVE-2026-17106</category></item><item><title>Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-27912-resetnightmare-kerberos-changepw-password-reset/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-27912-resetnightmare-kerberos-changepw-password-reset/</guid><description>High severity (CVSS 8) — network · CVE-2026-27912. Status: Patched. Affects: Microsoft Windows Kerberos Key Distribution Center (KDC), Change Password protocol (kadmin/changepw). Tags: windows, kerberos, active-directory, privilege-escalation, password-reset, domain-controller, upn, rubeus, changepw, krbtgt, CWE-285, microsoft, CVE-2026-27912.</description><category>network</category><category>High</category><category>windows</category><category>kerberos</category><category>active-directory</category><category>privilege-escalation</category><category>password-reset</category><category>domain-controller</category><category>upn</category><category>rubeus</category><category>changepw</category><category>krbtgt</category><category>CWE-285</category><category>microsoft</category><category>CVE-2026-27912</category></item><item><title>Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-11_shieldbreak-defender-rogueplanet-patch-bypass/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-11_shieldbreak-defender-rogueplanet-patch-bypass/</guid><description>High severity (CVSS 7.8) — binary · Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11. Status: Unpatched. Affects: Microsoft Windows Defender (Antimalware Service Executable / MsMpEng.exe), threat remediation subsystem. Tags: windows, windows-defender, lpe, privilege-escalation, 0day, patch-bypass, cloud-files, cfapi, object-manager, symlink, wer, dll-sideload, CWE-59, CWE-426, microsoft, rogueplanet, shieldbreak.</description><category>binary</category><category>High</category><category>windows</category><category>windows-defender</category><category>lpe</category><category>privilege-escalation</category><category>0day</category><category>patch-bypass</category><category>cloud-files</category><category>cfapi</category><category>object-manager</category><category>symlink</category><category>wer</category><category>dll-sideload</category><category>CWE-59</category><category>CWE-426</category><category>microsoft</category><category>rogueplanet</category><category>shieldbreak</category></item><item><title>Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-25177-ad-spn-unicode-collision-detector/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-25177-ad-spn-unicode-collision-detector/</guid><description>High severity (CVSS 8.8) — network · CVE-2026-25177. Status: Patched. Affects: Microsoft Active Directory Domain Services, Service Principal Name (SPN) validation. Tags: windows, active-directory, kerberos, spn, unicode, homoglyph, privilege-escalation, detection, scanner, ldap, CWE-641, microsoft, CVE-2026-25177.</description><category>network</category><category>High</category><category>windows</category><category>active-directory</category><category>kerberos</category><category>spn</category><category>unicode</category><category>homoglyph</category><category>privilege-escalation</category><category>detection</category><category>scanner</category><category>ldap</category><category>CWE-641</category><category>microsoft</category><category>CVE-2026-25177</category></item><item><title>Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-64561. Status: Patched. Affects: Linux kernel, KVM/x86 shadow-MMU (nested EPT/NPT shadowing) — arch/x86/kvm/mmu/mmu.c and arch/x86/kvm/mmu/paging_tmpl.h. Tags: linux-kernel, kvm, x86, shadow-mmu, nested-virtualization, svm, npt, ept, guest-to-host-escape, vm-escape, use-after-free, CWE-416, cross-cache, kaslr-bypass, usermode-helper, virtualization.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>kvm</category><category>x86</category><category>shadow-mmu</category><category>nested-virtualization</category><category>svm</category><category>npt</category><category>ept</category><category>guest-to-host-escape</category><category>vm-escape</category><category>use-after-free</category><category>CWE-416</category><category>cross-cache</category><category>kaslr-bypass</category><category>usermode-helper</category><category>virtualization</category></item><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-63077-teamcity-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-63077-teamcity-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-63077. Status: Patched. Affects: JetBrains TeamCity (on-premises CI/CD server), agent polling subsystem. Tags: jetbrains, teamcity, preauth-rce, xstream, deserialization, hsqldb, polyglot, jsp, CWE-502, agent-polling, ci-cd.</description><category>web</category><category>Critical</category><category>jetbrains</category><category>teamcity</category><category>preauth-rce</category><category>xstream</category><category>deserialization</category><category>hsqldb</category><category>polyglot</category><category>jsp</category><category>CWE-502</category><category>agent-polling</category><category>ci-cd</category></item><item><title>Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025). Status: Patched (Oracle out-of-band Security Alert, October 2025). Affects: Oracle E-Business Suite — Oracle Concurrent Processing product, BI Publisher Integration component (reached via the /OA_HTML/ web tier: configurator/UiServlet and ieshostedsurvey.jsp). Tags: oracle-ebs, oracle-concurrent-processing, bi-publisher-integration, pre-auth, rce, ssrf, crlf-injection, request-smuggling, path-traversal, auth-bypass, xslt, java, cisa-kev, ransomware, cl0p, watchtowr.</description><category>web</category><category>Critical</category><category>oracle-ebs</category><category>oracle-concurrent-processing</category><category>bi-publisher-integration</category><category>pre-auth</category><category>rce</category><category>ssrf</category><category>crlf-injection</category><category>request-smuggling</category><category>path-traversal</category><category>auth-bypass</category><category>xslt</category><category>java</category><category>cisa-kev</category><category>ransomware</category><category>cl0p</category><category>watchtowr</category></item><item><title>MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</guid><description>Critical severity (CVSS 8.8) — binary · MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet. Status: Unpatched. Affects: MariaDB Server, ST_Area() geometry function and SYS_REFCURSOR cursor-array management. Tags: mariadb, database, rce, low-privilege, heap, oob-read, use-after-free, aslr-bypass, pie-bypass, coop, vtable, cursor, st-area, multipolygon, CWE-125, CWE-416, docker, v12-security.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>database</category><category>rce</category><category>low-privilege</category><category>heap</category><category>oob-read</category><category>use-after-free</category><category>aslr-bypass</category><category>pie-bypass</category><category>coop</category><category>vtable</category><category>cursor</category><category>st-area</category><category>multipolygon</category><category>CWE-125</category><category>CWE-416</category><category>docker</category><category>v12-security</category></item><item><title>Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD). Status: Patched (Ivanti EPMM 11.8.1.1, 11.9.1.1, 11.10.0.2 and later). Affects: Ivanti Endpoint Manager Mobile (EPMM), previously branded MobileIron Core — the /mifs/aad/api/ administrative API surface. Tags: ivanti, epmm, mobileiron-core, mdm, authentication-bypass, cwe-287, unauthenticated, api, pii-disclosure, cisa-kev, ransomware, scanner.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron-core</category><category>mdm</category><category>authentication-bypass</category><category>cwe-287</category><category>unauthenticated</category><category>api</category><category>pii-disclosure</category><category>cisa-kev</category><category>ransomware</category><category>scanner</category></item><item><title>Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</guid><description>Critical severity (CVSS 9) — network · CVE-2025-22457. Status: Patched. Affects: Ivanti Connect Secure, Pulse Connect Secure (end of support), Ivanti Policy Secure, Ivanti ZTA Gateways — the /home/bin/web HTTPS front-end process. Tags: ivanti, connect-secure, pulse-connect-secure, policy-secure, zta-gateway, vpn, stack-overflow, CWE-121, buffer-overflow, rce, unauthenticated, rop, heap-spray, aslr-bruteforce, x-forwarded-for, cisa-kev, ransomware, ruby, edge-device.</description><category>network</category><category>Critical</category><category>ivanti</category><category>connect-secure</category><category>pulse-connect-secure</category><category>policy-secure</category><category>zta-gateway</category><category>vpn</category><category>stack-overflow</category><category>CWE-121</category><category>buffer-overflow</category><category>rce</category><category>unauthenticated</category><category>rop</category><category>heap-spray</category><category>aslr-bruteforce</category><category>x-forwarded-for</category><category>cisa-kev</category><category>ransomware</category><category>ruby</category><category>edge-device</category></item><item><title>GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2021-22205 (chains CVE-2021-22204 in ExifTool). Status: Patched (GitLab 13.8.8, 13.9.6, 13.10.3). Affects: GitLab Community Edition and Enterprise Edition (via bundled ExifTool, invoked by GitLab Workhorse). Tags: gitlab, exiftool, djvu, rce, preauth, unauthenticated, workhorse, perl, qx, reverse-shell, metadata-injection, kev, ransomware, python, cve-2021-22205, cve-2021-22204.</description><category>web</category><category>Critical</category><category>gitlab</category><category>exiftool</category><category>djvu</category><category>rce</category><category>preauth</category><category>unauthenticated</category><category>workhorse</category><category>perl</category><category>qx</category><category>reverse-shell</category><category>metadata-injection</category><category>kev</category><category>ransomware</category><category>python</category><category>cve-2021-22205</category><category>cve-2021-22204</category></item><item><title>Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-60004-gitea-diffpatch-githook-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-60004-gitea-diffpatch-githook-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-60004. Status: Patched. Affects: Gitea (self-hosted Git service), diffpatch API endpoint, Git three-way merge fallback. Tags: gitea, git, diffpatch, git-hook, post-index-change, three-way-merge, bare-repository, CWE-94, authenticated-rce, self-hosted, code-hosting.</description><category>web</category><category>High</category><category>gitea</category><category>git</category><category>diffpatch</category><category>git-hook</category><category>post-index-change</category><category>three-way-merge</category><category>bare-repository</category><category>CWE-94</category><category>authenticated-rce</category><category>self-hosted</category><category>code-hosting</category></item><item><title>Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)</title><link>https://poc.intelseclab.com/pocs/misc/2026-08-09_cve-2026-18718-ghidra-swift-demangler-code-execution/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-08-09_cve-2026-18718-ghidra-swift-demangler-code-execution/</guid><description>High severity (CVSS 7.5) — misc · CVE-2026-18718. Status: Patched. Affects: Ghidra (NSA reverse engineering framework), Swift Demangler analyzer. Tags: ghidra, nsa, reverse-engineering, swift, demangler, code-execution, project-file, analyzer, CWE-427, CWE-494, uncontrolled-search-path, supply-chain, research-tool, shared-project.</description><category>misc</category><category>High</category><category>ghidra</category><category>nsa</category><category>reverse-engineering</category><category>swift</category><category>demangler</category><category>code-execution</category><category>project-file</category><category>analyzer</category><category>CWE-427</category><category>CWE-494</category><category>uncontrolled-search-path</category><category>supply-chain</category><category>research-tool</category><category>shared-project</category></item><item><title>CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2024-51378. Status: Patched (commit 1c0c6cb; CyberPanel 2.3.8 and later). Affects: CyberPanel (aka Cyber Panel), by CyberPersons — Django-based hosting control panel. Tags: cyberpanel, rce, command-injection, preauth, unauthenticated, options-method, secmiddleware-bypass, statusfile, kev, ransomware, psaux, python, httpx, cve-2024-51378.</description><category>web</category><category>Critical</category><category>cyberpanel</category><category>rce</category><category>command-injection</category><category>preauth</category><category>unauthenticated</category><category>options-method</category><category>secmiddleware-bypass</category><category>statusfile</category><category>kev</category><category>ransomware</category><category>psaux</category><category>python</category><category>httpx</category><category>cve-2024-51378</category></item><item><title>Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-16232. Status: Patched. Affects: Check Point Security Management Server and Multi-Domain Security Management Server (MDS) — the legacy FWM/CPMI SIC service on TCP 18190 and the CPM SOAP web services on TCP 19009. Tags: check-point, smartconsole, security-management-server, multi-domain-server, cpmi, sic, fwm, authentication-bypass, CWE-287, improper-authentication, privilege-escalation, sso-token-forgery, soap, dle, cisa-kev, bod-26-04, python, firewall-management.</description><category>network</category><category>Critical</category><category>check-point</category><category>smartconsole</category><category>security-management-server</category><category>multi-domain-server</category><category>cpmi</category><category>sic</category><category>fwm</category><category>authentication-bypass</category><category>CWE-287</category><category>improper-authentication</category><category>privilege-escalation</category><category>sso-token-forgery</category><category>soap</category><category>dle</category><category>cisa-kev</category><category>bod-26-04</category><category>python</category><category>firewall-management</category></item><item><title>Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-08-09_cve-2026-64640-apache-polaris-cross-tenant-credential-vending/</guid><description>High severity (CVSS 8.1) — cloud · CVE-2026-64640. Status: Patched. Affects: Apache Polaris (Apache Iceberg REST catalog), registerTable and registerView endpoints. Tags: apache-polaris, iceberg, apache-iceberg, credential-vending, confused-deputy, authorization-bypass, cross-tenant, s3, storage, allowed-locations, CWE-441, CWE-639, CWE-918, ssrf, server-side-read, information-disclosure, register-table, register-view.</description><category>cloud</category><category>High</category><category>apache-polaris</category><category>iceberg</category><category>apache-iceberg</category><category>credential-vending</category><category>confused-deputy</category><category>authorization-bypass</category><category>cross-tenant</category><category>s3</category><category>storage</category><category>allowed-locations</category><category>CWE-441</category><category>CWE-639</category><category>CWE-918</category><category>ssrf</category><category>server-side-read</category><category>information-disclosure</category><category>register-table</category><category>register-view</category></item><item><title>Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</guid><description>High severity — binary · NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier). Status: Unpatched — Barrier is unmaintained with no vendor fix; patched successor Deskflow covers the same issue via CVE-2026-41477 / GHSA-6rx5-g478-775c. Affects: Barrier (debauchee), Windows service daemon barrierd.exe. Tags: barrier, barrierd, windows, ipc, tcp-24801, unauthenticated, lpe, privilege-escalation, system, cwe-306, local.</description><category>binary</category><category>High</category><category>barrier</category><category>barrierd</category><category>windows</category><category>ipc</category><category>tcp-24801</category><category>unauthenticated</category><category>lpe</category><category>privilege-escalation</category><category>system</category><category>cwe-306</category><category>local</category></item><item><title>Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-65694 (VulnCheck advisory). Status: Unpatched. Affects: Microweber CMS — ServeStaticFileContoller::serveFromUserfiles(). Tags: microweber, path-traversal, cwe-22, unauthenticated, arbitrary-file-read, laravel, query-string-override.</description><category>web</category><category>High</category><category>microweber</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>arbitrary-file-read</category><category>laravel</category><category>query-string-override</category></item><item><title>IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-9198. Status: Weaponized. Affects: IBM Langflow OSS (visual AI/agent-flow builder). Tags: langflow, ibm, auto-login, code-injection, cwe-94, unauthenticated, rce, python-exec, ai-agent-framework.</description><category>web</category><category>Critical</category><category>langflow</category><category>ibm</category><category>auto-login</category><category>code-injection</category><category>cwe-94</category><category>unauthenticated</category><category>rce</category><category>python-exec</category><category>ai-agent-framework</category></item><item><title>CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-40684. Status: Patched (FortiOS ≥7.2.2, ≥7.0.7; FortiProxy ≥7.2.1, ≥7.0.7; FortiSwitchManager ≥7.2.1). Affects: Fortinet FortiOS (FortiGate firewalls), FortiProxy web proxy, FortiSwitchManager web management interface / administrative REST API. Tags: fortios, fortiproxy, fortiswitchmanager, authentication-bypass, rest-api, header-injection, loopback-spoofing, fortigate, ssl-vpn, scanner.</description><category>network</category><category>Critical</category><category>fortios</category><category>fortiproxy</category><category>fortiswitchmanager</category><category>authentication-bypass</category><category>rest-api</category><category>header-injection</category><category>loopback-spoofing</category><category>fortigate</category><category>ssl-vpn</category><category>scanner</category></item><item><title>Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-32432-craftcms-preauth-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-32432-craftcms-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-32432. Status: Patched (Craft CMS 5.6.17+). Affects: Craft CMS (craftcms/cms). Tags: craftcms, rce, preauth, session-poisoning, php-deserialization, yii2, phpfpm, unauthenticated, go, cve-2025-32432.</description><category>web</category><category>Critical</category><category>craftcms</category><category>rce</category><category>preauth</category><category>session-poisoning</category><category>php-deserialization</category><category>yii2</category><category>phpfpm</category><category>unauthenticated</category><category>go</category><category>cve-2025-32432</category></item><item><title>Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-54988-apache-tika-xfa-xxe/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-54988-apache-tika-xfa-xxe/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-54988 (GHSA-p72g-pv48-7w9x, Apache JIRA TIKA-4459). Status: Weaponized. Affects: Apache Tika - tika-parser-pdf-module (and legacy tika-parsers). Tags: apache-tika, xxe, xfa, pdf-parsing, cwe-611, ssrf, file-disclosure, tika-server.</description><category>web</category><category>Critical</category><category>apache-tika</category><category>xxe</category><category>xfa</category><category>pdf-parsing</category><category>cwe-611</category><category>ssrf</category><category>file-disclosure</category><category>tika-server</category></item><item><title>Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-16723-fastjson-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-16723-fastjson-rce/</guid><description>Critical severity (CVSS 9) — web · CVE-2026-16723. Status: PoC (no vendor patch, Fastjson 1.x line unpatched). Affects: Alibaba Fastjson (Java JSON library), packaged inside a Spring Boot executable fat-JAR. Tags: fastjson, deserialization, rce, java, spring-boot, autotype-bypass, jar-protocol, ssrf.</description><category>web</category><category>Critical</category><category>fastjson</category><category>deserialization</category><category>rce</category><category>java</category><category>spring-boot</category><category>autotype-bypass</category><category>jar-protocol</category><category>ssrf</category></item><item><title>Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-49176. Status: Weaponized — SYSTEM shell confirmed against a real, vulnerable Windows 11 build. Affects: Windows WalletService (Windows.ApplicationModel.Wallet WinRT API, backed by an ESE/Jet Blue database under the caller's Documents\Wallet folder). Tags: windows, walletservice, lpe, privilege-escalation, ese, extensible-storage-engine, known-folder-redirection, persisted-callback, local.</description><category>binary</category><category>High</category><category>windows</category><category>walletservice</category><category>lpe</category><category>privilege-escalation</category><category>ese</category><category>extensible-storage-engine</category><category>known-folder-redirection</category><category>persisted-callback</category><category>local</category></item><item><title>Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</guid><description>High severity (CVSS 8.4) — network · CVE-2026-54992. Status: PoC (crash/DoS confirmed, no RCE demonstrated). Affects: Windows Message Queuing (MSMQ) — Queue Manager (mqqm.dll, hosted in mqsvc.exe), reached via the MS-MQRR (RemoteRead) RPC interface. Tags: windows, msmq, message-queuing, heap-overflow, integer-overflow, rpc, dos, crash.</description><category>network</category><category>High</category><category>windows</category><category>msmq</category><category>message-queuing</category><category>heap-overflow</category><category>integer-overflow</category><category>rpc</category><category>dos</category><category>crash</category></item><item><title>Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-66066-rails-activestorage-libvips-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-66066-rails-activestorage-libvips-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-66066 (GHSA-xr9x-r78c-5hrm). Status: Weaponized. Affects: Ruby on Rails — Active Storage (image variant processing via :vips/libvips). Tags: ruby-on-rails, active-storage, libvips, arbitrary-file-read, marshal-deserialization, rce, unauthenticated, cwe-22.</description><category>web</category><category>Critical</category><category>ruby-on-rails</category><category>active-storage</category><category>libvips</category><category>arbitrary-file-read</category><category>marshal-deserialization</category><category>rce</category><category>unauthenticated</category><category>cwe-22</category></item><item><title>MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports &amp; Sharing Groups (CVE-2026-56423)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56423-misp-core-deleteselection-broken-access-control/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56423-misp-core-deleteselection-broken-access-control/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-56423. Status: Weaponized — contributor-level bulk hard-delete of a foreign organizations Event Report confirmed against a real MISP core build; denied on the patched build. Affects: MISP (Malware Information Sharing Platform) Core — EventReportsController::deleteSelection and SharingGroupsController::deleteSelection. Tags: misp, misp-core, broken-access-control, cwe-862, bulk-deletion, authenticated, threat-intel-platform.</description><category>web</category><category>High</category><category>misp</category><category>misp-core</category><category>broken-access-control</category><category>cwe-862</category><category>bulk-deletion</category><category>authenticated</category><category>threat-intel-platform</category></item><item><title>Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-50522-sharepoint-preauth-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-50522-sharepoint-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-50522. Status: Weaponized — public PoC confirmed used in real attacks within hours of release (watchTowr honeypot telemetry). Affects: Microsoft SharePoint Server (on-premises). Tags: sharepoint, deserialization, binaryformatter, ws-federation, unauthenticated, rce, kev, actively-exploited, microsoft.</description><category>web</category><category>Critical</category><category>sharepoint</category><category>deserialization</category><category>binaryformatter</category><category>ws-federation</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>microsoft</category></item><item><title>Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-57830. Status: Weaponized. Affects: Helix Ultimate Framework (plg_system_helixultimate), the JoomShaper Joomla template framework bundled with virtually every JoomShaper Joomla template. Tags: joomla, helix-ultimate, joomshaper, arbitrary-file-deletion, cwe-862, unauthenticated, csrf-token-only-check.</description><category>web</category><category>Critical</category><category>joomla</category><category>helix-ultimate</category><category>joomshaper</category><category>arbitrary-file-deletion</category><category>cwe-862</category><category>unauthenticated</category><category>csrf-token-only-check</category></item><item><title>Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56291. Status: Weaponized. Affects: Balbooa Forms (com_baforms) — third-party Joomla! extension by balbooa.com. Tags: joomla, balbooa-forms, file-upload, webshell, unauthenticated, rce, kev, actively-exploited, cwe-434.</description><category>web</category><category>Critical</category><category>joomla</category><category>balbooa-forms</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>cwe-434</category></item><item><title>ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc). Status: Weaponized. Affects: Linux kernel, KVM/arm64 in-kernel vGIC-ITS (Interrupt Translation Service) emulation (arch/arm64/kvm/vgic/vgic-its.c). Tags: linux-kernel, kvm, arm64, vgic-its, guest-to-host-escape, vm-escape, double-free, use-after-free, kaslr-bypass, heap-grooming, virtualization.</description><category>binary</category><category>Critical</category><category>linux-kernel</category><category>kvm</category><category>arm64</category><category>vgic-its</category><category>guest-to-host-escape</category><category>vm-escape</category><category>double-free</category><category>use-after-free</category><category>kaslr-bypass</category><category>heap-grooming</category><category>virtualization</category></item><item><title>GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</guid><description>High severity — binary · N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27). Status: Unpatched. Affects: Windows Recovery Environment (WinRE) — Microsoft Defender Offline Scan launch path (ReAgent.xml scheduled operation). Tags: windows, bitlocker, winre, defender, offline-scan, trust-boundary-bypass, zero-day, unpatched, physical-access, local.</description><category>binary</category><category>High</category><category>windows</category><category>bitlocker</category><category>winre</category><category>defender</category><category>offline-scan</category><category>trust-boundary-bypass</category><category>zero-day</category><category>unpatched</category><category>physical-access</category><category>local</category></item><item><title>GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_gitlab-oj-json-parser-rce-chain/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_gitlab-oj-json-parser-rce-chain/</guid><description>Critical severity — web · N/A (no CVE assigned as of 2026-07-27 — researcher disclosure via depthfirst.com blog, covered by The Hacker News). Status: Weaponized. Affects: GitLab Community/Enterprise Edition — Jupyter notebook diff rendering (backed by the Oj native Ruby JSON parser gem). Tags: gitlab, oj-gem, json-parser, rce, aslr-bypass, ruby, deserialization, no-cve-yet.</description><category>web</category><category>Critical</category><category>gitlab</category><category>oj-gem</category><category>json-parser</category><category>rce</category><category>aslr-bypass</category><category>ruby</category><category>deserialization</category><category>no-cve-yet</category></item><item><title>Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-53753 (GHSA-qxjp-w3pj-48m7). Status: Weaponized — full end-to-end command execution reproduced against the official unclecode/crawl4ai:0.8.6 image. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper, Docker API server. Tags: crawl4ai, sandbox-escape, rce, python, ast-bypass, unauthenticated, llm-tooling, ai-security.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>sandbox-escape</category><category>rce</category><category>python</category><category>ast-bypass</category><category>unauthenticated</category><category>llm-tooling</category><category>ai-security</category></item></channel></rss>