PoC Archive PoC Archive

tag

Kerberos

Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912 network Unverified
CVE-2026-27912networkHIGH 8Unverified2026-08-11Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)
CVE-2026-25177 network Patched
CVE-2026-25177networkHIGH 8.8Patched2026-08-11AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)
CVE-2026-54121 network Patched
CVE-2026-54121networkHIGH 8.8Patched2026-07-27Apache Druid Kerberos Cookie-Signing Secret Recovery via ThreadLocalRandom Seed Inversion (CVE-2025-59390)
CVE-2025-59390 crypto Patched
CVE-2025-59390cryptoCRITICAL 9.8Patched2026-07-06