<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Auth-Bypass — PoC Archive</title><link>https://poc.intelseclab.com/tags/auth-bypass/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/auth-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-34910, CVE-2026-34909, CVE-2026-34908. Status: Patched. Affects: Ubiquiti UniFi OS Server. Tags: ubiquiti, unifi, unifi-os, auth-bypass, path-traversal, command-injection, rce, unauth, kev, mirai, nginx, CVE-2026-34910.</description><category>network</category><category>Critical</category><category>ubiquiti</category><category>unifi</category><category>unifi-os</category><category>auth-bypass</category><category>path-traversal</category><category>command-injection</category><category>rce</category><category>unauth</category><category>kev</category><category>mirai</category><category>nginx</category><category>CVE-2026-34910</category></item><item><title>Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025). Status: Patched (Oracle out-of-band Security Alert, October 2025). Affects: Oracle E-Business Suite — Oracle Concurrent Processing product, BI Publisher Integration component (reached via the /OA_HTML/ web tier: configurator/UiServlet and ieshostedsurvey.jsp). Tags: oracle-ebs, oracle-concurrent-processing, bi-publisher-integration, pre-auth, rce, ssrf, crlf-injection, request-smuggling, path-traversal, auth-bypass, xslt, java, cisa-kev, ransomware, cl0p, watchtowr.</description><category>web</category><category>Critical</category><category>oracle-ebs</category><category>oracle-concurrent-processing</category><category>bi-publisher-integration</category><category>pre-auth</category><category>rce</category><category>ssrf</category><category>crlf-injection</category><category>request-smuggling</category><category>path-traversal</category><category>auth-bypass</category><category>xslt</category><category>java</category><category>cisa-kev</category><category>ransomware</category><category>cl0p</category><category>watchtowr</category></item><item><title>Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — hardware · CVE-2025-65856. Status: Weaponized. Affects: Xiongmai XM530-based IP camera ONVIF service (tested on model XM530_50X50-WG_8M). Tags: xiongmai, xm530, onvif, ip-camera, iot, auth-bypass, access-control, information-disclosure, rtsp, cwe-306, cwe-287, python, bash, curl.</description><category>hardware</category><category>Critical</category><category>xiongmai</category><category>xm530</category><category>onvif</category><category>ip-camera</category><category>iot</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>rtsp</category><category>cwe-306</category><category>cwe-287</category><category>python</category><category>bash</category><category>curl</category></item><item><title>Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass &amp; Admin Credential Log Leak (CVE-2025-13315)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-13315-twonky-server-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-13315-twonky-server-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-13315. Status: PoC. Affects: Twonky Server (Lynx Technology), a DLNA/UPnP media server. Tags: twonky-server, dlna, upnp, media-server, auth-bypass, access-control, information-disclosure, credential-leak, cwe-284, unauthenticated, nuclei.</description><category>network</category><category>Critical</category><category>twonky-server</category><category>dlna</category><category>upnp</category><category>media-server</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>credential-leak</category><category>cwe-284</category><category>unauthenticated</category><category>nuclei</category></item><item><title>FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-58434-flowise-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-58434-flowise-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-58434. Status: Weaponized. Affects: FlowiseAI (/api/v1/account/forgot-password and /api/v1/account/reset-password endpoints). Tags: flowiseai, auth-bypass, account-takeover, forgot-password, reset-password, api, python, cwe-640.</description><category>web</category><category>Critical</category><category>flowiseai</category><category>auth-bypass</category><category>account-takeover</category><category>forgot-password</category><category>reset-password</category><category>api</category><category>python</category><category>cwe-640</category></item><item><title>ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</guid><description>Critical severity — network · CVE-2026-34472. Status: PoC. Affects: ZTE ZXHN H188A V6 home router firmware. Tags: router, firmware, unauthenticated, auth-bypass, credential-leak, iot, zte, wifi.</description><category>network</category><category>Critical</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>auth-bypass</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5415-wp-captcha-pro-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5415-wp-captcha-pro-auth-bypass/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-5415. Status: PoC. Affects: WP Captcha PRO (WordPress plugin, Advanced Google reCAPTCHA). Tags: wordpress, wp-captcha-pro, auth-bypass, privilege-escalation, nonce, ajax, account-takeover, plugin.</description><category>web</category><category>High</category><category>wordpress</category><category>wp-captcha-pro</category><category>auth-bypass</category><category>privilege-escalation</category><category>nonce</category><category>ajax</category><category>account-takeover</category><category>plugin</category></item><item><title>WordPress SignUp/SignIn &amp; Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-12416-wp-password-reset-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-12416-wp-password-reset-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-12416, CVE-2026-12417. Status: Weaponized. Affects: SignUp &amp; SignIn WordPress plugin (CVE-2026-12417); Invoice Generator WordPress plugin (CVE-2026-12416). Tags: wordpress, wp-plugin, account-takeover, password-reset, auth-bypass, ajax, mass-exploitation.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>account-takeover</category><category>password-reset</category><category>auth-bypass</category><category>ajax</category><category>mass-exploitation</category></item><item><title>SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0001-smartermail-password-reset/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0001-smartermail-password-reset/</guid><description>Critical severity (CVSS 9) — web · CVE-2026-0001 (tracked publicly as WT-2026-0001). Status: PoC. Affects: SmarterTools SmarterMail (webmail/admin control panel), typically on port 9998. Tags: smartermail, auth-bypass, password-reset, email-server, unauthenticated, rce-chain, smartertools, api.</description><category>web</category><category>Critical</category><category>smartermail</category><category>auth-bypass</category><category>password-reset</category><category>email-server</category><category>unauthenticated</category><category>rce-chain</category><category>smartertools</category><category>api</category></item><item><title>SimpleHelp OIDC Authentication Bypass (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48558. Status: PoC. Affects: SimpleHelp remote support / remote monitoring &amp; management (RMM) server, OIDC authentication flow. Tags: simplehelp, oidc, jwt, alg-none, auth-bypass, rmm, remote-support, cisa-kev.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>auth-bypass</category><category>rmm</category><category>remote-support</category><category>cisa-kev</category></item><item><title>pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29000-pac4j-jwt-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29000-pac4j-jwt-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-29000. Status: Weaponized. Affects: pac4j (JWT authentication module), used in Java web applications. Tags: pac4j, jwt, jwe, auth-bypass, alg-none, jwks, privilege-escalation, java.</description><category>web</category><category>Critical</category><category>pac4j</category><category>jwt</category><category>jwe</category><category>auth-bypass</category><category>alg-none</category><category>jwks</category><category>privilege-escalation</category><category>java</category></item><item><title>OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-28466-openclaw-gateway-websocket-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-28466-openclaw-gateway-websocket-rce/</guid><description>Critical severity — network · CVE-2026-28466. Status: Weaponized. Affects: OpenClaw gateway. Tags: openclaw, websocket, rce, gateway, auth-bypass, node-invoke, command-injection.</description><category>network</category><category>Critical</category><category>openclaw</category><category>websocket</category><category>rce</category><category>gateway</category><category>auth-bypass</category><category>node-invoke</category><category>command-injection</category></item><item><title>NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-24207-triton-sagemaker-auth-bypass-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-24207-triton-sagemaker-auth-bypass-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-24207 (sibling: CVE-2026-24206, Vertex AI, analysis only). Status: Weaponized. Affects: NVIDIA Triton Inference Server. Tags: nvidia-triton, sagemaker, auth-bypass, rce, cwe-288, ml-inference, model-loading, pre-auth.</description><category>network</category><category>Critical</category><category>nvidia-triton</category><category>sagemaker</category><category>auth-bypass</category><category>rce</category><category>cwe-288</category><category>ml-inference</category><category>model-loading</category><category>pre-auth</category></item><item><title>MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30849-mantisbt-soap-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30849-mantisbt-soap-auth-bypass/</guid><description>High severity — web · CVE-2026-30849. Status: Weaponized. Affects: MantisBT (SOAP API). Tags: mantisbt, soap, auth-bypass, type-juggling, php, bug-tracker, typescript.</description><category>web</category><category>High</category><category>mantisbt</category><category>soap</category><category>auth-bypass</category><category>type-juggling</category><category>php</category><category>bug-tracker</category><category>typescript</category></item><item><title>LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49468-litellm-host-header-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49468-litellm-host-header-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-49468. Status: PoC. Affects: LiteLLM (BerriAI) proxy. Tags: litellm, llm-proxy, auth-bypass, host-header, route-confusion, cwe-290, fastapi, starlette, python.</description><category>web</category><category>Critical</category><category>litellm</category><category>llm-proxy</category><category>auth-bypass</category><category>host-header</category><category>route-confusion</category><category>cwe-290</category><category>fastapi</category><category>starlette</category><category>python</category></item><item><title>Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27771-gitea-registry-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27771-gitea-registry-auth-bypass/</guid><description>Critical severity — web · CVE-2026-27771. Status: Weaponized. Affects: Gitea (self-hosted Git service with OCI container registry). Tags: gitea, forgejo, oci-registry, auth-bypass, container-registry, unauthenticated, information-disclosure.</description><category>web</category><category>Critical</category><category>gitea</category><category>forgejo</category><category>oci-registry</category><category>auth-bypass</category><category>container-registry</category><category>unauthenticated</category><category>information-disclosure</category></item><item><title>Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30824-flowise-nvidia-nim-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30824-flowise-nvidia-nim-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-30824. Status: Weaponized. Affects: Flowise (NVIDIA NIM integration endpoints). Tags: flowise, nvidia-nim, auth-bypass, cwe-306, token-theft, container-management, python, unauthenticated.</description><category>web</category><category>Critical</category><category>flowise</category><category>nvidia-nim</category><category>auth-bypass</category><category>cwe-306</category><category>token-theft</category><category>container-management</category><category>python</category><category>unauthenticated</category></item><item><title>Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-31816-budibase-auth-bypass-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-31816-budibase-auth-bypass-rce/</guid><description>Critical severity — web · CVE-2026-31816. Status: Weaponized. Affects: Budibase (low-code platform). Tags: budibase, auth-bypass, rce, plugin-upload, reverse-shell, low-code, python, datasource-plugin.</description><category>web</category><category>Critical</category><category>budibase</category><category>auth-bypass</category><category>rce</category><category>plugin-upload</category><category>reverse-shell</category><category>low-code</category><category>python</category><category>datasource-plugin</category></item><item><title>Apache Tomcat Split-Collection Security Constraint Bypass (CVE-2026-43515)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43515-tomcat-constraint-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-43515-tomcat-constraint-bypass/</guid><description>High severity — web · CVE-2026-43515. Status: PoC. Affects: Apache Tomcat — org.apache.catalina.realm.RealmBase.findSecurityConstraints(). Tags: apache-tomcat, java, security-constraint, auth-bypass, realm-base, servlet, web-xml, access-control.</description><category>web</category><category>High</category><category>apache-tomcat</category><category>java</category><category>security-constraint</category><category>auth-bypass</category><category>realm-base</category><category>servlet</category><category>web-xml</category><category>access-control</category></item><item><title>Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29145-tomcat-mtls-ocsp-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29145-tomcat-mtls-ocsp-bypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-29145. Status: PoC. Affects: Apache Tomcat (CLIENT_CERT / Mutual TLS authentication). Tags: tomcat, mtls, client-cert, ocsp, auth-bypass, revocation-check, docker-lab, java.</description><category>web</category><category>Critical</category><category>tomcat</category><category>mtls</category><category>client-cert</category><category>ocsp</category><category>auth-bypass</category><category>revocation-check</category><category>docker-lab</category><category>java</category></item><item><title>AdminPanel 4.0 CSRF File Deletion / Setup-Mode Reset — CVE-2026-30498</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30498-adminpanel-csrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-30498-adminpanel-csrf/</guid><description>High severity — web · CVE-2026-30498 (reserved by MITRE). Status: PoC. Affects: AdminPanel 4.0 (archived project). Tags: csrf, php, file-deletion, auth-bypass, setup-mode, get-request, adminpanel.</description><category>web</category><category>High</category><category>csrf</category><category>php</category><category>file-deletion</category><category>auth-bypass</category><category>setup-mode</category><category>get-request</category><category>adminpanel</category></item><item><title>PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-0257-pan-os-globalprotect-auth-bypass/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-0257-pan-os-globalprotect-auth-bypass/</guid><description>High severity (CVSS 7.8) — web · CVE-2026-0257. Status: PoC. Affects: Palo Alto Networks PAN-OS — GlobalProtect portal and gateway (also affects certain Prisma Access deployments). Tags: auth-bypass, VPN, GlobalProtect, PAN-OS, Palo-Alto, certificate-bypass, cookie-forgery, Prisma-Access, unauthenticated.</description><category>web</category><category>High</category><category>auth-bypass</category><category>VPN</category><category>GlobalProtect</category><category>PAN-OS</category><category>Palo-Alto</category><category>certificate-bypass</category><category>cookie-forgery</category><category>Prisma-Access</category><category>unauthenticated</category></item><item><title>Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-10520-ivanti-sentry-rce/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-10520-ivanti-sentry-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-10520, CVE-2026-10523. Status: PoC. Affects: Ivanti Sentry (formerly MobileIron Sentry). Tags: pre-auth, RCE, OS-command-injection, Ivanti, Sentry, MICS-API, auth-bypass, admin-creation, CISA-KEV.</description><category>network</category><category>Critical</category><category>pre-auth</category><category>RCE</category><category>OS-command-injection</category><category>Ivanti</category><category>Sentry</category><category>MICS-API</category><category>auth-bypass</category><category>admin-creation</category><category>CISA-KEV</category></item><item><title>Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-50751-checkpoint-ikev1-bypass/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-50751-checkpoint-ikev1-bypass/</guid><description>Critical severity (CVSS 9.3) — network · CVE-2026-50751. Status: PoC. Affects: Check Point Remote Access VPN / Mobile Access / Spark Firewall. Tags: auth-bypass, VPN, IKEv1, Check-Point, Remote-Access, certificate-bypass, Qilin, ransomware, CISA-KEV, unauthenticated.</description><category>network</category><category>Critical</category><category>auth-bypass</category><category>VPN</category><category>IKEv1</category><category>Check-Point</category><category>Remote-Access</category><category>certificate-bypass</category><category>Qilin</category><category>ransomware</category><category>CISA-KEV</category><category>unauthenticated</category></item><item><title>ToolShell - SharePoint Unauthenticated RCE Chain</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_toolshell-sharepoint-chain/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_toolshell-sharepoint-chain/</guid><description>Critical severity — web · CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706. Status: Weaponized. Affects: Microsoft SharePoint Server. Tags: RCE, SharePoint, unauthenticated, deserialization, auth-bypass, APT27, APT31, ransomware, Windows, IIS.</description><category>web</category><category>Critical</category><category>RCE</category><category>SharePoint</category><category>unauthenticated</category><category>deserialization</category><category>auth-bypass</category><category>APT27</category><category>APT31</category><category>ransomware</category><category>Windows</category><category>IIS</category></item><item><title>Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-dynamic-route-injection-auth-bypass/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-dynamic-route-injection-auth-bypass/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-44574. Status: Weaponized. Affects: Next.js App Router with dynamic route segments and middleware-based access control. Tags: auth-bypass, dynamic-route, nxtP-injection, middleware-bypass, param-smuggling, Next.js, App-Router, unauthenticated.</description><category>web</category><category>High</category><category>auth-bypass</category><category>dynamic-route</category><category>nxtP-injection</category><category>middleware-bypass</category><category>param-smuggling</category><category>Next.js</category><category>App-Router</category><category>unauthenticated</category></item><item><title>Fortinet FortiCloud SSO Authentication Bypass</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_fortinet-forticloud-sso-auth-bypass/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_fortinet-forticloud-sso-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-59718, CVE-2025-59719 (Advisory: FG-IR-25-647). Status: Weaponized. Affects: Fortinet FortiOS, FortiProxy, FortiSwitchManager (FortiCloud SSO feature). Tags: auth-bypass, SAML, SSO, unauthenticated, FortiOS, FortiProxy, FortiSwitchManager, active-exploitation.</description><category>network</category><category>Critical</category><category>auth-bypass</category><category>SAML</category><category>SSO</category><category>unauthenticated</category><category>FortiOS</category><category>FortiProxy</category><category>FortiSwitchManager</category><category>active-exploitation</category></item><item><title>VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-16_vmware-esxi-ad-auth-bypass/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-16_vmware-esxi-ad-auth-bypass/</guid><description>Medium severity (CVSS 6.8) — network · CVE-2024-37085. Status: Weaponized. Affects: VMware ESXi hosts joined to Microsoft Active Directory. Tags: auth-bypass, Active Directory, ESXi, vCenter, ransomware, unauthenticated-esxi.</description><category>network</category><category>Medium</category><category>auth-bypass</category><category>Active Directory</category><category>ESXi</category><category>vCenter</category><category>ransomware</category><category>unauthenticated-esxi</category></item><item><title>Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-16_pan-os-management-auth-bypass/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-16_pan-os-management-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-0108. Status: Weaponized. Affects: Palo Alto Networks PAN-OS management web interface. Tags: auth-bypass, path-traversal, PAN-OS, Palo Alto, management-interface, unauthenticated.</description><category>web</category><category>Critical</category><category>auth-bypass</category><category>path-traversal</category><category>PAN-OS</category><category>Palo Alto</category><category>management-interface</category><category>unauthenticated</category></item><item><title>Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-fortiproxy-auth-bypass-cve-2024-55591/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-fortiproxy-auth-bypass-cve-2024-55591/</guid><description>Critical severity (CVSS 9.6) — web · CVE-2024-55591 (Fortinet FG-IR-24-535). Status: Weaponized — public PoC exploit code available, listed in CISA KEV (added 2025-01-14), confirmed used in ransomware intrusions. Affects: Fortinet FortiOS/FortiProxy management interfaces. Tags: auth-bypass, websocket, race-condition, FortiOS, FortiProxy, unauthenticated, super-admin, kev, known-ransomware-use, cwe-288.</description><category>web</category><category>Critical</category><category>auth-bypass</category><category>websocket</category><category>race-condition</category><category>FortiOS</category><category>FortiProxy</category><category>unauthenticated</category><category>super-admin</category><category>kev</category><category>known-ransomware-use</category><category>cwe-288</category></item><item><title>cPanel &amp; WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-16_cpanel-whm-auth-bypass-crlf-session-injection/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-16_cpanel-whm-auth-bypass-crlf-session-injection/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-41940. Status: Weaponized. Affects: cPanel &amp; WHM. Tags: auth-bypass, CRLF-injection, session-poisoning, cPanel, WHM, unauthenticated.</description><category>web</category><category>Critical</category><category>auth-bypass</category><category>CRLF-injection</category><category>session-poisoning</category><category>cPanel</category><category>WHM</category><category>unauthenticated</category></item><item><title>Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-15_nextjs-middleware-bypass-cve-2025-29927/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-15_nextjs-middleware-bypass-cve-2025-29927/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-29927. Status: Weaponized. Affects: Next.js (Vercel). Tags: auth-bypass, middleware-bypass, Next.js, unauthenticated, header-injection.</description><category>web</category><category>Critical</category><category>auth-bypass</category><category>middleware-bypass</category><category>Next.js</category><category>unauthenticated</category><category>header-injection</category></item></channel></rss>