❌

Normal view

Dangling DNS record for bastion.certb.cdp.bethesda.net

6 August 2026 at 19:40

Posted by shed riot on Aug 06

# Summary

The hostname resolved to an address within a dynamic cloud IP pool.
The address had been released and was no longer controlled by the
organisation operating the hostname.

This condition is referred to as an "afterlife" issue.

Unlike a conventional CNAME-based subdomain takeover, the DNS record
pointed directly to a reusable cloud IP address. An attacker obtaining
that address could receive traffic intended for the...

CL.0 desync in www.microsoft.com

6 August 2026 at 19:40

Posted by shed riot on Aug 06

# Summary

I reported the issue to the Microsoft Security Response Center twice:

* VULN-165381, MSRC case 102964
* VULN-165876, MSRC case 103259

In both cases, they do not appear to have even looked at the PoCs, and so
have failed to adequately investigate before reaching a decision.

# Vulnerability

CWE-444: HTTP Request/Response Smuggling

The observed behaviour was consistent with CL.0 HTTP desync within the
request-processing chain.

#...

CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)

6 August 2026 at 19:36

Posted by Γ–ner Efe GΓΌngΓΆr on Aug 06

Hello Full Disclosure,

I'd like to share an independent lab Proof-of-Concept for CVE-2026-15013.

### CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated
Authentication Bypass

SAML Signature Algorithm Confusion vulnerability. An unauthenticated
attacker can forge a valid SAMLResponse by forcing HMAC-SHA1 verification
against the IdP's public key, allowing full account takeover (including
administrators).

Root cause:...

[KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability

6 August 2026 at 19:34

Posted by Egidio Romano on Aug 06

-------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation
Vulnerability
-------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected as well.

[-]...

[KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability

6 August 2026 at 19:34

Posted by Egidio Romano on Aug 06

-------------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection
Vulnerability
-------------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected...

[KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability

6 August 2026 at 19:34

Posted by Egidio Romano on Aug 06

---------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass
Vulnerability
---------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected as well....

[KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability

6 August 2026 at 19:34

Posted by Egidio Romano on Aug 06

-----------------------------------------------------------------
vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability
-----------------------------------------------------------------

[-] Software Link:

https://www.vbulletin.com

[-] Affected Versions:

Version 5.7.5 and prior 5.x versions.
Version 6.2.1 and prior 6.x versions.

[-] Vulnerability Description:

The vulnerable code is located within the...

[SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

6 August 2026 at 19:31

Posted by Matthias Deeg via Fulldisclosure on Aug 06

Advisory ID: SYSS-2026-050
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: Medium
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

[SYSS-2026-049]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

6 August 2026 at 19:31

Posted by Matthias Deeg via Fulldisclosure on Aug 06

Advisory ID: SYSS-2026-049
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...
❌