<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cisa-Kev — PoC Archive</title><link>https://poc.intelseclab.com/tags/cisa-kev/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cisa-kev/index.xml" rel="self" type="application/rss+xml"/><item><title>Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025). Status: Patched (Oracle out-of-band Security Alert, October 2025). Affects: Oracle E-Business Suite — Oracle Concurrent Processing product, BI Publisher Integration component (reached via the /OA_HTML/ web tier: configurator/UiServlet and ieshostedsurvey.jsp). Tags: oracle-ebs, oracle-concurrent-processing, bi-publisher-integration, pre-auth, rce, ssrf, crlf-injection, request-smuggling, path-traversal, auth-bypass, xslt, java, cisa-kev, ransomware, cl0p, watchtowr.</description><category>web</category><category>Critical</category><category>oracle-ebs</category><category>oracle-concurrent-processing</category><category>bi-publisher-integration</category><category>pre-auth</category><category>rce</category><category>ssrf</category><category>crlf-injection</category><category>request-smuggling</category><category>path-traversal</category><category>auth-bypass</category><category>xslt</category><category>java</category><category>cisa-kev</category><category>ransomware</category><category>cl0p</category><category>watchtowr</category></item><item><title>Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD). Status: Patched (Ivanti EPMM 11.8.1.1, 11.9.1.1, 11.10.0.2 and later). Affects: Ivanti Endpoint Manager Mobile (EPMM), previously branded MobileIron Core — the /mifs/aad/api/ administrative API surface. Tags: ivanti, epmm, mobileiron-core, mdm, authentication-bypass, cwe-287, unauthenticated, api, pii-disclosure, cisa-kev, ransomware, scanner.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron-core</category><category>mdm</category><category>authentication-bypass</category><category>cwe-287</category><category>unauthenticated</category><category>api</category><category>pii-disclosure</category><category>cisa-kev</category><category>ransomware</category><category>scanner</category></item><item><title>Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</guid><description>Critical severity (CVSS 9) — network · CVE-2025-22457. Status: Patched. Affects: Ivanti Connect Secure, Pulse Connect Secure (end of support), Ivanti Policy Secure, Ivanti ZTA Gateways — the /home/bin/web HTTPS front-end process. Tags: ivanti, connect-secure, pulse-connect-secure, policy-secure, zta-gateway, vpn, stack-overflow, CWE-121, buffer-overflow, rce, unauthenticated, rop, heap-spray, aslr-bruteforce, x-forwarded-for, cisa-kev, ransomware, ruby, edge-device.</description><category>network</category><category>Critical</category><category>ivanti</category><category>connect-secure</category><category>pulse-connect-secure</category><category>policy-secure</category><category>zta-gateway</category><category>vpn</category><category>stack-overflow</category><category>CWE-121</category><category>buffer-overflow</category><category>rce</category><category>unauthenticated</category><category>rop</category><category>heap-spray</category><category>aslr-bruteforce</category><category>x-forwarded-for</category><category>cisa-kev</category><category>ransomware</category><category>ruby</category><category>edge-device</category></item><item><title>Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-16232. Status: Patched. Affects: Check Point Security Management Server and Multi-Domain Security Management Server (MDS) — the legacy FWM/CPMI SIC service on TCP 18190 and the CPM SOAP web services on TCP 19009. Tags: check-point, smartconsole, security-management-server, multi-domain-server, cpmi, sic, fwm, authentication-bypass, CWE-287, improper-authentication, privilege-escalation, sso-token-forgery, soap, dle, cisa-kev, bod-26-04, python, firewall-management.</description><category>network</category><category>Critical</category><category>check-point</category><category>smartconsole</category><category>security-management-server</category><category>multi-domain-server</category><category>cpmi</category><category>sic</category><category>fwm</category><category>authentication-bypass</category><category>CWE-287</category><category>improper-authentication</category><category>privilege-escalation</category><category>sso-token-forgery</category><category>soap</category><category>dle</category><category>cisa-kev</category><category>bod-26-04</category><category>python</category><category>firewall-management</category></item><item><title>SimpleHelp OIDC Authentication Bypass (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48558. Status: PoC. Affects: SimpleHelp remote support / remote monitoring &amp; management (RMM) server, OIDC authentication flow. Tags: simplehelp, oidc, jwt, alg-none, auth-bypass, rmm, remote-support, cisa-kev.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>auth-bypass</category><category>rmm</category><category>remote-support</category><category>cisa-kev</category></item><item><title>Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_cve-2025-3248-langflow-unauth-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_cve-2025-3248-langflow-unauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-3248. Status: Weaponized. Affects: Langflow (open-source AI/LLM workflow builder). Tags: RCE, unauthenticated, missing-authentication, Langflow, AI-application, python-exec, CISA-KEV, agentic-ransomware, JADEPUFFER.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>missing-authentication</category><category>Langflow</category><category>AI-application</category><category>python-exec</category><category>CISA-KEV</category><category>agentic-ransomware</category><category>JADEPUFFER</category></item><item><title>Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-35616-forticlient-ems-auth-bypass/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-35616-forticlient-ems-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-35616. Status: Weaponized. Affects: Fortinet FortiClient Endpoint Management Server (EMS). Tags: authentication-bypass, header-spoofing, Fortinet, FortiClient-EMS, FortiBleed, credential-theft, CISA-KEV, active-exploitation, ransomware.</description><category>network</category><category>Critical</category><category>authentication-bypass</category><category>header-spoofing</category><category>Fortinet</category><category>FortiClient-EMS</category><category>FortiBleed</category><category>credential-theft</category><category>CISA-KEV</category><category>active-exploitation</category><category>ransomware</category></item><item><title>Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-45247-mirasvit-magento-cache-warmer-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-45247-mirasvit-magento-cache-warmer-rce/</guid><description>Critical severity (CVSS 9.3) — web · CVE-2026-45247. Status: Weaponized. Affects: Mirasvit Full Page Cache Warmer extension for Magento 2. Tags: php-object-injection, insecure-deserialization, RCE, Magento, Mirasvit, e-commerce, cookie-based, unauthenticated, CISA-KEV, active-exploitation.</description><category>web</category><category>Critical</category><category>php-object-injection</category><category>insecure-deserialization</category><category>RCE</category><category>Magento</category><category>Mirasvit</category><category>e-commerce</category><category>cookie-based</category><category>unauthenticated</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48907. Status: Weaponized. Affects: Joomla Content Editor (JCE) extension by Widget Factory. Tags: RCE, unauthenticated, Joomla, JCE, CMS, access-control, webshell, php-webshell, file-upload, CISA-KEV, active-exploitation.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>Joomla</category><category>JCE</category><category>CMS</category><category>access-control</category><category>webshell</category><category>php-webshell</category><category>file-upload</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20230-cisco-ucm-webdialer-ssrf-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20230-cisco-ucm-webdialer-ssrf-rce/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230. Status: Weaponized. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tags: SSRF, RCE, Cisco, Unified-Communications-Manager, WebDialer, file-write, webshell, jsp-webshell, CISA-KEV, active-exploitation.</description><category>network</category><category>Critical</category><category>SSRF</category><category>RCE</category><category>Cisco</category><category>Unified-Communications-Manager</category><category>WebDialer</category><category>file-write</category><category>webshell</category><category>jsp-webshell</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-24061-gnu-telnetd-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-24061-gnu-telnetd-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-24061. Status: Weaponized. Affects: GNU Inetutils telnetd. Tags: RCE, unauthenticated, authentication-bypass, telnetd, GNU-Inetutils, NEW-ENVIRON, legacy, OT, CISA-KEV, active-exploitation, Python.</description><category>network</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>authentication-bypass</category><category>telnetd</category><category>GNU-Inetutils</category><category>NEW-ENVIRON</category><category>legacy</category><category>OT</category><category>CISA-KEV</category><category>active-exploitation</category><category>Python</category></item><item><title>Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-34908-unifi-os-rce-chain/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-34908-unifi-os-rce-chain/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-34908, CVE-2026-34909, CVE-2026-34910. Status: PoC. Affects: Ubiquiti UniFi OS Server. Tags: unauth-rce, nginx-bypass, path-traversal, command-injection, CISA-KEV, Mirai, Gaafgyt, chain, UniFi, Ubiquiti, network.</description><category>network</category><category>Critical</category><category>unauth-rce</category><category>nginx-bypass</category><category>path-traversal</category><category>command-injection</category><category>CISA-KEV</category><category>Mirai</category><category>Gaafgyt</category><category>chain</category><category>UniFi</category><category>Ubiquiti</category><category>network</category></item><item><title>Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-28_cve-2026-20253-splunk-preauth-rce/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-28_cve-2026-20253-splunk-preauth-rce/</guid><description>Critical severity — web · CVE-2026-20253. Status: PoC. Affects: Splunk Enterprise. Tags: pre-auth, RCE, PostgreSQL, Splunk, CISA-KEV, lo-export, sidecar, unauthenticated, file-write.</description><category>web</category><category>Critical</category><category>pre-auth</category><category>RCE</category><category>PostgreSQL</category><category>Splunk</category><category>CISA-KEV</category><category>lo-export</category><category>sidecar</category><category>unauthenticated</category><category>file-write</category></item><item><title>Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-10520-ivanti-sentry-rce/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-10520-ivanti-sentry-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-10520, CVE-2026-10523. Status: PoC. Affects: Ivanti Sentry (formerly MobileIron Sentry). Tags: pre-auth, RCE, OS-command-injection, Ivanti, Sentry, MICS-API, auth-bypass, admin-creation, CISA-KEV.</description><category>network</category><category>Critical</category><category>pre-auth</category><category>RCE</category><category>OS-command-injection</category><category>Ivanti</category><category>Sentry</category><category>MICS-API</category><category>auth-bypass</category><category>admin-creation</category><category>CISA-KEV</category></item><item><title>Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-20245-cisco-sdwan-priv-esc/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-20245-cisco-sdwan-priv-esc/</guid><description>High severity (CVSS 7.8) — network · CVE-2026-20245. Status: PoC. Affects: Cisco Catalyst SD-WAN Manager (vManage), SD-WAN Controller (vSmart), SD-WAN Validator (vBond). Tags: privilege-escalation, Cisco, SD-WAN, vManage, file-upload, command-injection, root, CISA-KEV, no-patch, Mandiant, nation-state.</description><category>network</category><category>High</category><category>privilege-escalation</category><category>Cisco</category><category>SD-WAN</category><category>vManage</category><category>file-upload</category><category>command-injection</category><category>root</category><category>CISA-KEV</category><category>no-patch</category><category>Mandiant</category><category>nation-state</category></item><item><title>Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-50751-checkpoint-ikev1-bypass/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-50751-checkpoint-ikev1-bypass/</guid><description>Critical severity (CVSS 9.3) — network · CVE-2026-50751. Status: PoC. Affects: Check Point Remote Access VPN / Mobile Access / Spark Firewall. Tags: auth-bypass, VPN, IKEv1, Check-Point, Remote-Access, certificate-bypass, Qilin, ransomware, CISA-KEV, unauthenticated.</description><category>network</category><category>Critical</category><category>auth-bypass</category><category>VPN</category><category>IKEv1</category><category>Check-Point</category><category>Remote-Access</category><category>certificate-bypass</category><category>Qilin</category><category>ransomware</category><category>CISA-KEV</category><category>unauthenticated</category></item><item><title>Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-nftables-uaf-lpe/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-nftables-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2024-1086. Status: Weaponized. Affects: Linux kernel (netfilter nf_tables subsystem). Tags: LPE, UAF, Linux kernel, nf_tables, netfilter, CISA KEV, ransomware, x64.</description><category>binary</category><category>High</category><category>LPE</category><category>UAF</category><category>Linux kernel</category><category>nf_tables</category><category>netfilter</category><category>CISA KEV</category><category>ransomware</category><category>x64</category></item></channel></rss>