<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Gadget-Chain — PoC Archive</title><link>https://poc.intelseclab.com/tags/gadget-chain/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/gadget-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49113-roundcube-php-object-deserialization-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49113-roundcube-php-object-deserialization-rce/</guid><description>Critical severity (CVSS 9.9) — web · CVE-2025-49113. Status: Weaponized. Affects: Roundcube Webmail. Tags: roundcube, webmail, php, deserialization, object-injection, gadget-chain, rce, post-auth, cwe-502.</description><category>web</category><category>Critical</category><category>roundcube</category><category>webmail</category><category>php</category><category>deserialization</category><category>object-injection</category><category>gadget-chain</category><category>rce</category><category>post-auth</category><category>cwe-502</category></item><item><title>Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54068-livewire-appkey-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54068-livewire-appkey-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-54068. Status: Weaponized. Affects: Laravel Livewire (versions prior to v3.6.4). Tags: laravel, livewire, php, deserialization, app-key, hmac-forgery, gadget-chain, rce, cwe-502, python.</description><category>web</category><category>Critical</category><category>laravel</category><category>livewire</category><category>php</category><category>deserialization</category><category>app-key</category><category>hmac-forgery</category><category>gadget-chain</category><category>rce</category><category>cwe-502</category><category>python</category></item><item><title>GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-22777-givewp-php-object-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-22777-givewp-php-object-injection/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-22777. Status: PoC. Affects: GiveWP – Donation Plugin and Fundraising Platform (WordPress plugin, 100,000+ active installs). Tags: givewp, wordpress, wordpress-plugin, php-object-injection, deserialization, unserialize, gadget-chain, cwe-502, php, unauthenticated.</description><category>web</category><category>Critical</category><category>givewp</category><category>wordpress</category><category>wordpress-plugin</category><category>php-object-injection</category><category>deserialization</category><category>unserialize</category><category>gadget-chain</category><category>cwe-502</category><category>php</category><category>unauthenticated</category></item><item><title>Apache Camel `camel-consul` ConsulRegistry Deserialization RCE (CVE-2026-27172)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-27172-camel-consul-registry-deserialization/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-27172-camel-consul-registry-deserialization/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-27172. Status: Patched. Affects: Apache Camel camel-consul component (org.apache.camel.component.consul.ConsulRegistry). Tags: apache-camel, camel-consul, consulregistry, java-deserialization, rce, cwe-502, gadget-chain, ysoserial, spring-boot.</description><category>web</category><category>Critical</category><category>apache-camel</category><category>camel-consul</category><category>consulregistry</category><category>java-deserialization</category><category>rce</category><category>cwe-502</category><category>gadget-chain</category><category>ysoserial</category><category>spring-boot</category></item><item><title>WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54806-wp-activity-log-poi-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54806-wp-activity-log-poi-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-54806. Status: PoC. Affects: WP Activity Log (plugin slug: wp-security-audit-log) by Melapress, for WordPress. Tags: wordpress, wp-activity-log, wp-security-audit-log, php-object-injection, deserialization, cwe-502, blind-rce, gadget-chain.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-activity-log</category><category>wp-security-audit-log</category><category>php-object-injection</category><category>deserialization</category><category>cwe-502</category><category>blind-rce</category><category>gadget-chain</category></item><item><title>SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48909-sp-lms-joomla-phpobjectinjection-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48909-sp-lms-joomla-phpobjectinjection-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-48909 (GHSA-gf8c-xmwj-whrh). Status: PoC. Affects: JoomShaper SP LMS (com_splms) Joomla Learning Management System extension. Tags: joomla, sp-lms, com_splms, php-object-injection, cwe-502, deserialization, unauthenticated-rce, gadget-chain.</description><category>web</category><category>Critical</category><category>joomla</category><category>sp-lms</category><category>com_splms</category><category>php-object-injection</category><category>cwe-502</category><category>deserialization</category><category>unauthenticated-rce</category><category>gadget-chain</category></item><item><title>OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33439-openam-deserialization-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33439-openam-deserialization-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-33439. Status: Weaponized. Affects: ForgeRock / OpenIdentityPlatform OpenAM. Tags: openam, forgerock, deserialization, rce, pre-auth, java, gadget-chain, xalan, jato.</description><category>web</category><category>Critical</category><category>openam</category><category>forgerock</category><category>deserialization</category><category>rce</category><category>pre-auth</category><category>java</category><category>gadget-chain</category><category>xalan</category><category>jato</category></item><item><title>Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34838-groupoffice-deserialization-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34838-groupoffice-deserialization-rce/</guid><description>Critical severity — web · CVE-2026-34838 (GHSA-h22j-frrf-5vxq). Status: PoC. Affects: Group-Office groupware suite. Tags: php, deserialization, rce, groupware, gadget-chain, authenticated, group-office, guzzlehttp.</description><category>web</category><category>Critical</category><category>php</category><category>deserialization</category><category>rce</category><category>groupware</category><category>gadget-chain</category><category>authenticated</category><category>group-office</category><category>guzzlehttp</category></item><item><title>Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34486-tomcat-tribes-deserialization-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34486-tomcat-tribes-deserialization-rce/</guid><description>Critical severity — web · CVE-2026-34486. Status: Weaponized. Affects: Apache Tomcat Tribes clustering (EncryptInterceptor). Tags: deserialization, rce, tomcat, tribes, clustering, java, gadget-chain, unauthenticated.</description><category>web</category><category>Critical</category><category>deserialization</category><category>rce</category><category>tomcat</category><category>tribes</category><category>clustering</category><category>java</category><category>gadget-chain</category><category>unauthenticated</category></item><item><title>Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42779-apache-mina-deserialization-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42779-apache-mina-deserialization-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-42779. Status: PoC. Affects: Apache MINA (mina-core). Tags: apache-mina, java, deserialization, cwe-502, gadget-chain, commons-collections, rce, filter-bypass.</description><category>network</category><category>Critical</category><category>apache-mina</category><category>java</category><category>deserialization</category><category>cwe-502</category><category>gadget-chain</category><category>commons-collections</category><category>rce</category><category>filter-bypass</category></item></channel></rss>