<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Kev — PoC Archive</title><link>https://poc.intelseclab.com/tags/kev/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/kev/index.xml" rel="self" type="application/rss+xml"/><item><title>UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-34910, CVE-2026-34909, CVE-2026-34908. Status: Patched. Affects: Ubiquiti UniFi OS Server. Tags: ubiquiti, unifi, unifi-os, auth-bypass, path-traversal, command-injection, rce, unauth, kev, mirai, nginx, CVE-2026-34910.</description><category>network</category><category>Critical</category><category>ubiquiti</category><category>unifi</category><category>unifi-os</category><category>auth-bypass</category><category>path-traversal</category><category>command-injection</category><category>rce</category><category>unauth</category><category>kev</category><category>mirai</category><category>nginx</category><category>CVE-2026-34910</category></item><item><title>GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2021-22205 (chains CVE-2021-22204 in ExifTool). Status: Patched (GitLab 13.8.8, 13.9.6, 13.10.3). Affects: GitLab Community Edition and Enterprise Edition (via bundled ExifTool, invoked by GitLab Workhorse). Tags: gitlab, exiftool, djvu, rce, preauth, unauthenticated, workhorse, perl, qx, reverse-shell, metadata-injection, kev, ransomware, python, cve-2021-22205, cve-2021-22204.</description><category>web</category><category>Critical</category><category>gitlab</category><category>exiftool</category><category>djvu</category><category>rce</category><category>preauth</category><category>unauthenticated</category><category>workhorse</category><category>perl</category><category>qx</category><category>reverse-shell</category><category>metadata-injection</category><category>kev</category><category>ransomware</category><category>python</category><category>cve-2021-22205</category><category>cve-2021-22204</category></item><item><title>CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2024-51378. Status: Patched (commit 1c0c6cb; CyberPanel 2.3.8 and later). Affects: CyberPanel (aka Cyber Panel), by CyberPersons — Django-based hosting control panel. Tags: cyberpanel, rce, command-injection, preauth, unauthenticated, options-method, secmiddleware-bypass, statusfile, kev, ransomware, psaux, python, httpx, cve-2024-51378.</description><category>web</category><category>Critical</category><category>cyberpanel</category><category>rce</category><category>command-injection</category><category>preauth</category><category>unauthenticated</category><category>options-method</category><category>secmiddleware-bypass</category><category>statusfile</category><category>kev</category><category>ransomware</category><category>psaux</category><category>python</category><category>httpx</category><category>cve-2024-51378</category></item><item><title>Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-50522-sharepoint-preauth-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-50522-sharepoint-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-50522. Status: Weaponized — public PoC confirmed used in real attacks within hours of release (watchTowr honeypot telemetry). Affects: Microsoft SharePoint Server (on-premises). Tags: sharepoint, deserialization, binaryformatter, ws-federation, unauthenticated, rce, kev, actively-exploited, microsoft.</description><category>web</category><category>Critical</category><category>sharepoint</category><category>deserialization</category><category>binaryformatter</category><category>ws-federation</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>microsoft</category></item><item><title>Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56291. Status: Weaponized. Affects: Balbooa Forms (com_baforms) — third-party Joomla! extension by balbooa.com. Tags: joomla, balbooa-forms, file-upload, webshell, unauthenticated, rce, kev, actively-exploited, cwe-434.</description><category>web</category><category>Critical</category><category>joomla</category><category>balbooa-forms</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>cwe-434</category></item><item><title>SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48558. Status: Weaponized — forges valid privileged sessions with no credentials. Affects: SimpleHelp — remote support / RMM (remote monitoring and management) platform, OIDC authentication flow. Tags: simplehelp, rmm, oidc, jwt, alg-none, cwe-347, authentication-bypass, unauthenticated, remote, kev, actively-exploited, ransomware.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>rmm</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>cwe-347</category><category>authentication-bypass</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category><category>ransomware</category></item><item><title>Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-55255-langflow-responses-api-idor/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-55255-langflow-responses-api-idor/</guid><description>High severity (CVSS 8.4) — web · CVE-2026-55255 (GHSA-qrpv-q767-xqq2). Status: Weaponized — confirmed cross-user flow execution via a minimal request-only PoC. Affects: Langflow — open-source platform for building and deploying AI-powered agents and workflows (langflow-ai/langflow), OpenAI-compatible Responses API. Tags: langflow, ai-agent-framework, idor, cwe-639, authenticated, remote, cross-tenant, kev.</description><category>web</category><category>High</category><category>langflow</category><category>ai-agent-framework</category><category>idor</category><category>cwe-639</category><category>authenticated</category><category>remote</category><category>cross-tenant</category><category>kev</category></item><item><title>Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW). Status: PoC — scanner/tester confirms the WebDialer precondition and SSRF reachability. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) — WebDialer service. Tags: cisco, unified-communications-manager, ucm, webdialer, ssrf, cwe-918, unauthenticated, remote, privilege-escalation, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>cisco</category><category>unified-communications-manager</category><category>ucm</category><category>webdialer</category><category>ssrf</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>kev</category><category>actively-exploited</category></item><item><title>Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48282 (Adobe APSB26-68). Status: Weaponized — arbitrary file read/write, directory browsing, webshell deployment, and command execution all confirmed. Affects: Adobe ColdFusion — Remote Development Service (RDS), /CFIDE/main/ide.cfm. Tags: coldfusion, adobe, rds, path-traversal, cwe-22, unauthenticated, remote, webshell, kev, actively-exploited.</description><category>web</category><category>Critical</category><category>coldfusion</category><category>adobe</category><category>rds</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>webshell</category><category>kev</category><category>actively-exploited</category></item><item><title>SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</link><pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-15409 (SNWLID-2026-0008). Status: Weaponized — unauthenticated, non-root remote code execution confirmed against a real appliance build. Affects: SonicWall SMA1000 Appliance — WorkPlace interface (websocket proxy service). Tags: sonicwall, sma1000, workplace, ssrf, erlang, rpc, cwe-918, unauthenticated, remote, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>sonicwall</category><category>sma1000</category><category>workplace</category><category>ssrf</category><category>erlang</category><category>rpc</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category></item><item><title>ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2023-38950. Status: Weaponized (public PoC, in CISA KEV). Affects: ZKTeco BioTime (web-based time &amp; attendance / access control management platform). Tags: zkteco, biotime, path-traversal, arbitrary-file-read, cwe-22, unauthenticated, remote, iclock-api, kev.</description><category>web</category><category>High</category><category>zkteco</category><category>biotime</category><category>path-traversal</category><category>arbitrary-file-read</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>iclock-api</category><category>kev</category></item><item><title>Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48939. Status: Weaponized (public PoC available, actively exploited in the wild, in CISA KEV since 2026-07-10). Affects: iCagenda — events/calendar extension (component) for Joomla. Tags: joomla, icagenda, file-upload, rce, cwe-434, unauthenticated, remote, kev, cms, php, access-control-bypass.</description><category>web</category><category>Critical</category><category>joomla</category><category>icagenda</category><category>file-upload</category><category>rce</category><category>cwe-434</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>cms</category><category>php</category><category>access-control-bypass</category></item><item><title>Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-42237-sitecore-xp-deserialization-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-42237-sitecore-xp-deserialization-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2021-42237 (Sitecore advisory SC2021-003-499266). Status: Weaponized (public PoC + Metasploit module, in CISA KEV, known ransomware campaign use). Affects: Sitecore Experience Platform (XP). Tags: sitecore, deserialization, rce, cms, unauthenticated, remote, kev, known-ransomware-use, cwe-502.</description><category>web</category><category>Critical</category><category>sitecore</category><category>deserialization</category><category>rce</category><category>cms</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>known-ransomware-use</category><category>cwe-502</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25296. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Windows WMI monitoring configuration wizard. Tags: nagios-xi, os-command-injection, authenticated, config-wizard, windowswmi, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>windowswmi</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25297. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Switch (SNMP) monitoring configuration wizard. Tags: nagios-xi, os-command-injection, authenticated, config-wizard, switch, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>switch</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25298-nagios-xi-cloudvm-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25298-nagios-xi-cloudvm-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25298. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Cloud/VM monitoring configuration wizard (DigitalOcean provider sub-option). Tags: nagios-xi, os-command-injection, authenticated, config-wizard, cloud-vm, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>cloud-vm</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-26258. Status: Weaponized (public PoC available; listed in CISA KEV). Affects: D-Link DIR-820L wireless router, all hardware revisions. Tags: d-link, dir-820l, router, command-injection, cwe-78, unauthenticated, remote, iot, eol-device, kev.</description><category>network</category><category>Critical</category><category>d-link</category><category>dir-820l</category><category>router</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>remote</category><category>iot</category><category>eol-device</category><category>kev</category></item><item><title>Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-34299. Status: Weaponized. Affects: Monsta FTP (web-based FTP manager). Tags: monsta-ftp, rce, pre-auth, unrestricted-file-upload, cwe-434, php, ftp, docker, nuclei, kev.</description><category>network</category><category>Critical</category><category>monsta-ftp</category><category>rce</category><category>pre-auth</category><category>unrestricted-file-upload</category><category>cwe-434</category><category>php</category><category>ftp</category><category>docker</category><category>nuclei</category><category>kev</category></item><item><title>FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-39808-fortisandbox-os-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-39808-fortisandbox-os-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-39808. Status: Weaponized — real, working exploit verified from two independent sources. Affects: Fortinet FortiSandbox. Tags: fortinet, fortisandbox, os-command-injection, unauthenticated, root-rce, cwe-78, actively-exploited, kev.</description><category>network</category><category>Critical</category><category>fortinet</category><category>fortisandbox</category><category>os-command-injection</category><category>unauthenticated</category><category>root-rce</category><category>cwe-78</category><category>actively-exploited</category><category>kev</category></item><item><title>SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p). Status: Weaponized — public PoC with mass-scan support, added to CISA KEV 2026-07-07, confirmed active in-the-wild exploitation. Affects: SP Page Builder extension for Joomla (joomshaper.net). Tags: RCE, unauthenticated, file-upload, PHP-webshell, Joomla, CMS, access-control, Python, CVSS-10, kev, backdoor, cwe-434.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>file-upload</category><category>PHP-webshell</category><category>Joomla</category><category>CMS</category><category>access-control</category><category>Python</category><category>CVSS-10</category><category>kev</category><category>backdoor</category><category>cwe-434</category></item><item><title>Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_jenkins-cli-arbitrary-file-read-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_jenkins-cli-arbitrary-file-read-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2024-23897. Status: Weaponized. Affects: Jenkins controller (CLI endpoint). Tags: arbitrary-file-read, Jenkins, CLI, credential-theft, RCE, unauthenticated, KEV.</description><category>web</category><category>Critical</category><category>arbitrary-file-read</category><category>Jenkins</category><category>CLI</category><category>credential-theft</category><category>RCE</category><category>unauthenticated</category><category>KEV</category></item><item><title>Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_fortimanager-fortijump-rce-cve-2024-47575/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_fortimanager-fortijump-rce-cve-2024-47575/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2024-47575. Status: Weaponized. Affects: Fortinet FortiManager / FortiManager Cloud (fgfmd daemon). Tags: RCE, unauthenticated, FortiManager, fgfmd, zero-day, KEV.</description><category>network</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>FortiManager</category><category>fgfmd</category><category>zero-day</category><category>KEV</category></item><item><title>VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-16_vmware-vcenter-dcerpc-heap-overflow-rce/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-16_vmware-vcenter-dcerpc-heap-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2024-37079. Status: Weaponized. Affects: VMware vCenter Server. Tags: RCE, heap-overflow, DCE/RPC, vCenter, unauthenticated, KEV.</description><category>network</category><category>Critical</category><category>RCE</category><category>heap-overflow</category><category>DCE/RPC</category><category>vCenter</category><category>unauthenticated</category><category>KEV</category></item><item><title>Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-sslvpn-rce-cve-2024-21762/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-sslvpn-rce-cve-2024-21762/</guid><description>Critical severity (CVSS 9.6) — web · CVE-2024-21762. Status: Weaponized. Affects: Fortinet FortiOS SSL VPN (sslvpnd). Tags: RCE, out-of-bounds-write, SSL-VPN, FortiOS, edge-appliance, unauthenticated, KEV.</description><category>web</category><category>Critical</category><category>RCE</category><category>out-of-bounds-write</category><category>SSL-VPN</category><category>FortiOS</category><category>edge-appliance</category><category>unauthenticated</category><category>KEV</category></item><item><title>Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-fortiproxy-auth-bypass-cve-2024-55591/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-16_fortios-fortiproxy-auth-bypass-cve-2024-55591/</guid><description>Critical severity (CVSS 9.6) — web · CVE-2024-55591 (Fortinet FG-IR-24-535). Status: Weaponized — public PoC exploit code available, listed in CISA KEV (added 2025-01-14), confirmed used in ransomware intrusions. Affects: Fortinet FortiOS/FortiProxy management interfaces. Tags: auth-bypass, websocket, race-condition, FortiOS, FortiProxy, unauthenticated, super-admin, kev, known-ransomware-use, cwe-288.</description><category>web</category><category>Critical</category><category>auth-bypass</category><category>websocket</category><category>race-condition</category><category>FortiOS</category><category>FortiProxy</category><category>unauthenticated</category><category>super-admin</category><category>kev</category><category>known-ransomware-use</category><category>cwe-288</category></item></channel></rss>