<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Zero-Day — PoC Archive</title><link>https://poc.intelseclab.com/tags/zero-day/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/zero-day/index.xml" rel="self" type="application/rss+xml"/><item><title>GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</guid><description>High severity — binary · N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27). Status: Unpatched. Affects: Windows Recovery Environment (WinRE) — Microsoft Defender Offline Scan launch path (ReAgent.xml scheduled operation). Tags: windows, bitlocker, winre, defender, offline-scan, trust-boundary-bypass, zero-day, unpatched, physical-access, local.</description><category>binary</category><category>High</category><category>windows</category><category>bitlocker</category><category>winre</category><category>defender</category><category>offline-scan</category><category>trust-boundary-bypass</category><category>zero-day</category><category>unpatched</category><category>physical-access</category><category>local</category></item><item><title>Google Chromium V8 Out-of-Bounds Read/Write — Crash PoC (CVE-2026-11645)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-11645-chrome-v8-oob-crash/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-11645-chrome-v8-oob-crash/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-11645. Status: Incomplete PoC (crash only — no confirmed public RCE chain). Affects: Google Chrome / Chromium — V8 JavaScript and WebAssembly engine. Tags: browser, chrome, v8, javascript, turbofan, out-of-bounds, memory-corruption, zero-day, incomplete-poc, active-exploitation.</description><category>web</category><category>High</category><category>browser</category><category>chrome</category><category>v8</category><category>javascript</category><category>turbofan</category><category>out-of-bounds</category><category>memory-corruption</category><category>zero-day</category><category>incomplete-poc</category><category>active-exploitation</category></item><item><title>Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_cve-2026-45586-ctfmon-greenplasma-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_cve-2026-45586-ctfmon-greenplasma-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-45586. Status: PoC. Affects: Windows Collaborative Translation Framework (CTFMON service). Tags: LPE, EoP, Windows, CTFMON, section-object, object-directory, link-following, zero-day, CTF-challenge, Windows-11, Windows-2022, Windows-2026, incomplete-poc.</description><category>binary</category><category>High</category><category>LPE</category><category>EoP</category><category>Windows</category><category>CTFMON</category><category>section-object</category><category>object-directory</category><category>link-following</category><category>zero-day</category><category>CTF-challenge</category><category>Windows-11</category><category>Windows-2022</category><category>Windows-2026</category><category>incomplete-poc</category></item><item><title>YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)</title><link>https://poc.intelseclab.com/pocs/misc/2026-06-26_yellowkey-bitlocker-bypass/</link><pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-06-26_yellowkey-bitlocker-bypass/</guid><description>Medium severity (CVSS 6.1) — misc · CVE-2026-45585. Status: Researched. Affects: Windows BitLocker / WinRE (autofstx.exe). Tags: BitLocker, bypass, physical-access, WinRE, TPM, autofstx, NTFS-transactions, FsTx, Windows-11, Windows-Server-2022, zero-day, full-disk-access.</description><category>misc</category><category>Medium</category><category>BitLocker</category><category>bypass</category><category>physical-access</category><category>WinRE</category><category>TPM</category><category>autofstx</category><category>NTFS-transactions</category><category>FsTx</category><category>Windows-11</category><category>Windows-Server-2022</category><category>zero-day</category><category>full-disk-access</category></item><item><title>Windows MMC MSC EvilTwin - CVE-2025-26633</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-mmc-eviltwin-cve-2025-26633/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-mmc-eviltwin-cve-2025-26633/</guid><description>High severity — binary · CVE-2025-26633. Status: Patched. Affects: Microsoft Management Console (MMC), Windows. Tags: RCE, Windows, MMC, MSC, ActiveX, EvilTwin, APT, EncryptHub, Water-Gamayun, zero-day, in-the-wild.</description><category>binary</category><category>High</category><category>RCE</category><category>Windows</category><category>MMC</category><category>MSC</category><category>ActiveX</category><category>EvilTwin</category><category>APT</category><category>EncryptHub</category><category>Water-Gamayun</category><category>zero-day</category><category>in-the-wild</category></item><item><title>Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_pan-os-globalprotect-unauth-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_pan-os-globalprotect-unauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2024-3400. Status: Weaponized. Affects: Palo Alto Networks PAN-OS GlobalProtect gateway. Tags: RCE, command-injection, path-traversal, PAN-OS, GlobalProtect, unauthenticated, zero-day.</description><category>web</category><category>Critical</category><category>RCE</category><category>command-injection</category><category>path-traversal</category><category>PAN-OS</category><category>GlobalProtect</category><category>unauthenticated</category><category>zero-day</category></item><item><title>Ivanti Connect Secure Pre-Auth RCE (Stack Overflow)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_ivanti-connect-secure-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_ivanti-connect-secure-rce/</guid><description>Critical severity (CVSS 9) — network · CVE-2025-0282. Status: Weaponized. Affects: Ivanti Connect Secure, Ivanti Policy Secure, Ivanti ZTA Gateways. Tags: RCE, stack-overflow, buffer-overflow, pre-auth, unauthenticated, VPN, zero-day, active-exploitation, Ivanti, TLS.</description><category>network</category><category>Critical</category><category>RCE</category><category>stack-overflow</category><category>buffer-overflow</category><category>pre-auth</category><category>unauthenticated</category><category>VPN</category><category>zero-day</category><category>active-exploitation</category><category>Ivanti</category><category>TLS</category></item><item><title>Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_fortimanager-fortijump-rce-cve-2024-47575/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_fortimanager-fortijump-rce-cve-2024-47575/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2024-47575. Status: Weaponized. Affects: Fortinet FortiManager / FortiManager Cloud (fgfmd daemon). Tags: RCE, unauthenticated, FortiManager, fgfmd, zero-day, KEV.</description><category>network</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>FortiManager</category><category>fgfmd</category><category>zero-day</category><category>KEV</category></item></channel></rss>