<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ldap — PoC Archive</title><link>https://poc.intelseclab.com/tags/ldap/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/ldap/index.xml" rel="self" type="application/rss+xml"/><item><title>Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-25177-ad-spn-unicode-collision-detector/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-25177-ad-spn-unicode-collision-detector/</guid><description>High severity (CVSS 8.8) — network · CVE-2026-25177. Status: Patched. Affects: Microsoft Active Directory Domain Services, Service Principal Name (SPN) validation. Tags: windows, active-directory, kerberos, spn, unicode, homoglyph, privilege-escalation, detection, scanner, ldap, CWE-641, microsoft, CVE-2026-25177.</description><category>network</category><category>High</category><category>windows</category><category>active-directory</category><category>kerberos</category><category>spn</category><category>unicode</category><category>homoglyph</category><category>privilege-escalation</category><category>detection</category><category>scanner</category><category>ldap</category><category>CWE-641</category><category>microsoft</category><category>CVE-2026-25177</category></item><item><title>Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54253-aem-forms-xxe-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54253-aem-forms-xxe-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-54253. Status: Weaponized. Affects: Adobe Experience Manager (AEM) Forms (JEE). Tags: adobe, aem, aem-forms, xxe, xml-external-entity, jndi, ldap, rce, python, cve-2025-54254.</description><category>web</category><category>Critical</category><category>adobe</category><category>aem</category><category>aem-forms</category><category>xxe</category><category>xml-external-entity</category><category>jndi</category><category>ldap</category><category>rce</category><category>python</category><category>cve-2025-54254</category></item><item><title>YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42568-yamcs-ldap-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42568-yamcs-ldap-injection/</guid><description>Medium severity — network · CVE-2026-42568 / GHSA-cqh3-jg8p-336j. Status: PoC. Affects: YAMCS (org.yamcs.security.LdapAuthModule). Tags: ldap-injection, authentication-bypass, yamcs, ldap, python, cwe-90.</description><category>network</category><category>Medium</category><category>ldap-injection</category><category>authentication-bypass</category><category>yamcs</category><category>ldap</category><category>python</category><category>cwe-90</category></item><item><title>LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-15_ldap-nightmare-cve-2024-49113/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-15_ldap-nightmare-cve-2024-49113/</guid><description>Critical severity — network · CVE-2024-49113. Status: Weaponized. Affects: Microsoft Windows LDAP client / Netlogon interaction path. Tags: LDAP, NRPC, Windows Server, unauthenticated, DoS, potential-RCE.</description><category>network</category><category>Critical</category><category>LDAP</category><category>NRPC</category><category>Windows Server</category><category>unauthenticated</category><category>DoS</category><category>potential-RCE</category></item></channel></rss>