<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ransomware — PoC Archive</title><link>https://poc.intelseclab.com/tags/ransomware/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/ransomware/index.xml" rel="self" type="application/rss+xml"/><item><title>Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025). Status: Patched (Oracle out-of-band Security Alert, October 2025). Affects: Oracle E-Business Suite — Oracle Concurrent Processing product, BI Publisher Integration component (reached via the /OA_HTML/ web tier: configurator/UiServlet and ieshostedsurvey.jsp). Tags: oracle-ebs, oracle-concurrent-processing, bi-publisher-integration, pre-auth, rce, ssrf, crlf-injection, request-smuggling, path-traversal, auth-bypass, xslt, java, cisa-kev, ransomware, cl0p, watchtowr.</description><category>web</category><category>Critical</category><category>oracle-ebs</category><category>oracle-concurrent-processing</category><category>bi-publisher-integration</category><category>pre-auth</category><category>rce</category><category>ssrf</category><category>crlf-injection</category><category>request-smuggling</category><category>path-traversal</category><category>auth-bypass</category><category>xslt</category><category>java</category><category>cisa-kev</category><category>ransomware</category><category>cl0p</category><category>watchtowr</category></item><item><title>Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD). Status: Patched (Ivanti EPMM 11.8.1.1, 11.9.1.1, 11.10.0.2 and later). Affects: Ivanti Endpoint Manager Mobile (EPMM), previously branded MobileIron Core — the /mifs/aad/api/ administrative API surface. Tags: ivanti, epmm, mobileiron-core, mdm, authentication-bypass, cwe-287, unauthenticated, api, pii-disclosure, cisa-kev, ransomware, scanner.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron-core</category><category>mdm</category><category>authentication-bypass</category><category>cwe-287</category><category>unauthenticated</category><category>api</category><category>pii-disclosure</category><category>cisa-kev</category><category>ransomware</category><category>scanner</category></item><item><title>Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</guid><description>Critical severity (CVSS 9) — network · CVE-2025-22457. Status: Patched. Affects: Ivanti Connect Secure, Pulse Connect Secure (end of support), Ivanti Policy Secure, Ivanti ZTA Gateways — the /home/bin/web HTTPS front-end process. Tags: ivanti, connect-secure, pulse-connect-secure, policy-secure, zta-gateway, vpn, stack-overflow, CWE-121, buffer-overflow, rce, unauthenticated, rop, heap-spray, aslr-bruteforce, x-forwarded-for, cisa-kev, ransomware, ruby, edge-device.</description><category>network</category><category>Critical</category><category>ivanti</category><category>connect-secure</category><category>pulse-connect-secure</category><category>policy-secure</category><category>zta-gateway</category><category>vpn</category><category>stack-overflow</category><category>CWE-121</category><category>buffer-overflow</category><category>rce</category><category>unauthenticated</category><category>rop</category><category>heap-spray</category><category>aslr-bruteforce</category><category>x-forwarded-for</category><category>cisa-kev</category><category>ransomware</category><category>ruby</category><category>edge-device</category></item><item><title>GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2021-22205 (chains CVE-2021-22204 in ExifTool). Status: Patched (GitLab 13.8.8, 13.9.6, 13.10.3). Affects: GitLab Community Edition and Enterprise Edition (via bundled ExifTool, invoked by GitLab Workhorse). Tags: gitlab, exiftool, djvu, rce, preauth, unauthenticated, workhorse, perl, qx, reverse-shell, metadata-injection, kev, ransomware, python, cve-2021-22205, cve-2021-22204.</description><category>web</category><category>Critical</category><category>gitlab</category><category>exiftool</category><category>djvu</category><category>rce</category><category>preauth</category><category>unauthenticated</category><category>workhorse</category><category>perl</category><category>qx</category><category>reverse-shell</category><category>metadata-injection</category><category>kev</category><category>ransomware</category><category>python</category><category>cve-2021-22205</category><category>cve-2021-22204</category></item><item><title>CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2024-51378. Status: Patched (commit 1c0c6cb; CyberPanel 2.3.8 and later). Affects: CyberPanel (aka Cyber Panel), by CyberPersons — Django-based hosting control panel. Tags: cyberpanel, rce, command-injection, preauth, unauthenticated, options-method, secmiddleware-bypass, statusfile, kev, ransomware, psaux, python, httpx, cve-2024-51378.</description><category>web</category><category>Critical</category><category>cyberpanel</category><category>rce</category><category>command-injection</category><category>preauth</category><category>unauthenticated</category><category>options-method</category><category>secmiddleware-bypass</category><category>statusfile</category><category>kev</category><category>ransomware</category><category>psaux</category><category>python</category><category>httpx</category><category>cve-2024-51378</category></item><item><title>SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48558. Status: Weaponized — forges valid privileged sessions with no credentials. Affects: SimpleHelp — remote support / RMM (remote monitoring and management) platform, OIDC authentication flow. Tags: simplehelp, rmm, oidc, jwt, alg-none, cwe-347, authentication-bypass, unauthenticated, remote, kev, actively-exploited, ransomware.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>rmm</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>cwe-347</category><category>authentication-bypass</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category><category>ransomware</category></item><item><title>Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-35616-forticlient-ems-auth-bypass/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-35616-forticlient-ems-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-35616. Status: Weaponized. Affects: Fortinet FortiClient Endpoint Management Server (EMS). Tags: authentication-bypass, header-spoofing, Fortinet, FortiClient-EMS, FortiBleed, credential-theft, CISA-KEV, active-exploitation, ransomware.</description><category>network</category><category>Critical</category><category>authentication-bypass</category><category>header-spoofing</category><category>Fortinet</category><category>FortiClient-EMS</category><category>FortiBleed</category><category>credential-theft</category><category>CISA-KEV</category><category>active-exploitation</category><category>ransomware</category></item><item><title>Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-50751-checkpoint-ikev1-bypass/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-50751-checkpoint-ikev1-bypass/</guid><description>Critical severity (CVSS 9.3) — network · CVE-2026-50751. Status: PoC. Affects: Check Point Remote Access VPN / Mobile Access / Spark Firewall. Tags: auth-bypass, VPN, IKEv1, Check-Point, Remote-Access, certificate-bypass, Qilin, ransomware, CISA-KEV, unauthenticated.</description><category>network</category><category>Critical</category><category>auth-bypass</category><category>VPN</category><category>IKEv1</category><category>Check-Point</category><category>Remote-Access</category><category>certificate-bypass</category><category>Qilin</category><category>ransomware</category><category>CISA-KEV</category><category>unauthenticated</category></item><item><title>ToolShell - SharePoint Unauthenticated RCE Chain</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_toolshell-sharepoint-chain/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_toolshell-sharepoint-chain/</guid><description>Critical severity — web · CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706. Status: Weaponized. Affects: Microsoft SharePoint Server. Tags: RCE, SharePoint, unauthenticated, deserialization, auth-bypass, APT27, APT31, ransomware, Windows, IIS.</description><category>web</category><category>Critical</category><category>RCE</category><category>SharePoint</category><category>unauthenticated</category><category>deserialization</category><category>auth-bypass</category><category>APT27</category><category>APT31</category><category>ransomware</category><category>Windows</category><category>IIS</category></item><item><title>Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-nftables-uaf-lpe/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-nftables-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2024-1086. Status: Weaponized. Affects: Linux kernel (netfilter nf_tables subsystem). Tags: LPE, UAF, Linux kernel, nf_tables, netfilter, CISA KEV, ransomware, x64.</description><category>binary</category><category>High</category><category>LPE</category><category>UAF</category><category>Linux kernel</category><category>nf_tables</category><category>netfilter</category><category>CISA KEV</category><category>ransomware</category><category>x64</category></item><item><title>Confluence SSTI RCE - CVE-2023-22527</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_confluence-ssti-rce-cve-2023-22527/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_confluence-ssti-rce-cve-2023-22527/</guid><description>Critical severity (CVSS 10) — web · CVE-2023-22527. Status: Weaponized. Affects: Atlassian Confluence Data Center and Confluence Server. Tags: RCE, Confluence, SSTI, Freemarker, OGNL, unauthenticated, Java, Atlassian, ransomware.</description><category>web</category><category>Critical</category><category>RCE</category><category>Confluence</category><category>SSTI</category><category>Freemarker</category><category>OGNL</category><category>unauthenticated</category><category>Java</category><category>Atlassian</category><category>ransomware</category></item><item><title>VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-16_vmware-esxi-ad-auth-bypass/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-16_vmware-esxi-ad-auth-bypass/</guid><description>Medium severity (CVSS 6.8) — network · CVE-2024-37085. Status: Weaponized. Affects: VMware ESXi hosts joined to Microsoft Active Directory. Tags: auth-bypass, Active Directory, ESXi, vCenter, ransomware, unauthenticated-esxi.</description><category>network</category><category>Medium</category><category>auth-bypass</category><category>Active Directory</category><category>ESXi</category><category>vCenter</category><category>ransomware</category><category>unauthenticated-esxi</category></item></channel></rss>