❌

Normal view

Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in XPressEntry 3.7.7454 (Telaeris Inc). The research
is published and a proof-of-concept is available.

Pre-authentication RCE (SQL injection) (CVSS 9.8, pre-authentication)

Telaeris XPressEntry 3.7.7454 runs its main HTTP API without authentication when RequireReaderCredentials is False,
which is the default. The SaveVerifyActivity handler concatenates the sNotes parameter into...

Security advisory: Authenticated RCE (SQL injection) in Scrutinizer 19.7.0 (Plixer)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in Scrutinizer 19.7.0 (Plixer). The research is
published and a proof-of-concept is available.

Authenticated RCE (SQL injection) (CVSS 8.8, authenticated)

Plixer Scrutinizer 19.7.0 concatenates the HTTP orderBy parameter directly into a SQL ORDER BY clause with no escaping
in the adminEditLang handler. The default configuration includes the pg_cron extension and a PostgreSQL...

Security advisory: Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax Software (Output Technology))

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in Output Messenger Server 2.0.x (>= 2.0.63) (Srimax
Software (Output Technology)). The research is published and a proof-of-concept is available.

Pre-authentication SYSTEM RCE (Zip-Slip plugin planting) (CVSS 9.8, pre-authentication)

Output Messenger Server 2.0.x accepts XMPP connections on TCP 14121 with no SASL and no credentials; every connection
is treated as...

Security advisory: Pre-authentication RCE (arbitrary file write) in RapidDeploy 5.2.2 (MidVision)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in RapidDeploy 5.2.2 (MidVision). The research is
published and a proof-of-concept is available.

Pre-authentication RCE (arbitrary file write) (CVSS 9.8, pre-authentication)

MidVision RapidDeploy 5.2.2 ships a remote-agent template (midvision-remoting-server.xml) with host=0.0.0.0 and
auth.servers commented out, making the JBoss Remoting layer network-reachable with no...

Security advisory: Authenticated RCE (second-order SQL injection) in Lansweeper 12.2.1.0 (web reports 12.2.1.6) (Lansweeper)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in Lansweeper 12.2.1.0 (web reports 12.2.1.6)
(Lansweeper). The research is published and a proof-of-concept is available.

Authenticated RCE (second-order SQL injection) (CVSS 8.8, authenticated)

Lansweeper 12.2.1.0 contains a second-order SQL injection in the LicenseActions console. A SQL Server sub-server name
containing a single quote is stored and later concatenated...

Security advisory: Authenticated RCE (command injection) in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI Software)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in Kerio Connect 10.0.9 Patch 2 (build 10320) (GFI
Software). The research is published and a proof-of-concept is available.

Authenticated RCE (command injection) (CVSS 8.8, authenticated)

Kerio Connect 10.0.9 Patch 2 contains a command-injection vulnerability in the WebAdmin JSON-RPC method
Server.startEncryption. The password parameter is double-quoted and concatenated...

Security advisory: Pre-authentication RCE (default credentials + path traversal) in PulseNET Enterprise 6.0.3 (build 6975) (GE Vernova)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in PulseNET Enterprise 6.0.3 (build 6975) (GE
Vernova). The research is published and a proof-of-concept is available.

Pre-authentication RCE (default credentials + path traversal) (CVSS 9.8, pre-authentication)

GE Vernova PulseNET Enterprise 6.0.3 is the network-management software electric utilities use to monitor and manage
the industrial wireless networks connecting...

Security advisory: Pre-authentication RCE (BinaryFormatter deserialization) in Cinegy Cinegize 2026-02-05 installer (Cinegy GmbH)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in Cinegy Cinegize 2026-02-05 installer (Cinegy
GmbH). The research is published and a proof-of-concept is available.

Pre-authentication RCE (BinaryFormatter deserialization) (CVSS 9.8, pre-authentication)

Cinegy Cinegize (2026-02-05 installer) registers a Windows service listening on TCP 51140 with a DotNetty pipeline that
deserializes .NET BinaryFormatter objects before the...

Security advisory: Pre-authentication RCE in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity))

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in Wyn Enterprise 9.1.00145.0 (Mescius (GrapeCity)).
The research is published and a proof-of-concept is available.

Pre-authentication RCE (CVSS 9.8, pre-authentication)

Wyn Enterprise 9.1.00145.0 exposes an unauthenticated root RCE chain of three vulnerabilities: JWT signature validation
is skipped (parse-only ReadToken) with a hardcoded integration client secret, producing an...

Security advisory: Pre-authentication RCE (default credentials) in ObjectDB 2.9.5 server mode (ObjectDB Software)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in ObjectDB 2.9.5 server mode (ObjectDB Software).
The research is published and a proof-of-concept is available.

Pre-authentication RCE (default credentials) (CVSS 9.8, pre-authentication)

ObjectDB 2.9.5 server mode (port 6136, proprietary binary protocol) has a critical remote code execution vulnerability:
JDOQL query filter evaluation allows arbitrary static-method...

Security advisory: Pre-authentication RCE in nanoDLP stable build #10729 (Nano3Dtech)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in nanoDLP stable build #10729 (Nano3Dtech). The
research is published and a proof-of-concept is available.

Pre-authentication RCE (CVSS 9.8, pre-authentication)

nanoDLP exposes an unauthenticated remote code execution vulnerability. The Guest (unauthenticated) endpoint POST
/formula evaluates user-supplied JavaScript in an embedded Otto JS sandbox, which exposes a live nanoDLP...

Security advisory: Pre-authentication SYSTEM RCE in MAPS SCADA 4.0.5.5 (Adroit Technologies)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in MAPS SCADA 4.0.5.5 (Adroit Technologies). The
research is published and a proof-of-concept is available.

Pre-authentication SYSTEM RCE (CVSS 9.8, pre-authentication)

MAPS SCADA 4.0.5.5 exposes an IIS WebService (default port 8878) whose WSDataProvider.asmx endpoints deserialize the
caller-supplied byte array before any authentication. Serializer.BinaryDeserialization...

Security advisory: Pre-authentication RCE in Confluent Platform (ksqlDB) 7.9.1-ce (Confluent, Inc.)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in Confluent Platform (ksqlDB) 7.9.1-ce (Confluent,
Inc.). The research is published and a proof-of-concept is available.

Pre-authentication RCE (CVSS 9.8, pre-authentication)

Confluent Platform 7.9.1-ce exposes an unauthenticated remote code execution chain in its default configuration. ksqlDB
(HTTP 8089), the Kafka broker (9092 PLAINTEXT, no SASL) and Kafka Connect (8083) all...

Security advisory: Pre-authentication SYSTEM RCE in iMonnit Express 4.0.5.5 (Monnit / iMonnit)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in iMonnit Express 4.0.5.5 (Monnit / iMonnit). The
research is published and a proof-of-concept is available.

Pre-authentication SYSTEM RCE (CVSS 9.8, pre-authentication)

iMonnit Express 4.0.5.5 is an ASP.NET Core application running as a Windows service with LocalSystem privileges, with
no global [Authorize] filter. Three flaws combine into a fully unauthenticated root RCE...

Security advisory: Pre-authentication RCE in Ontotext GraphDB 11.4.3 Free edition (Ontotext / Graphwise)

18 August 2026 at 06:17

Posted by disclosure via Fulldisclosure on Aug 17

0day Rubbish Research Team is publicly disclosing a vulnerability in Ontotext GraphDB 11.4.3 Free edition (Ontotext /
Graphwise). The research is published and a proof-of-concept is available.

Pre-authentication RCE (CVSS 9.8, pre-authentication)

Ontotext GraphDB 11.4.3 Free edition defaults to security=false, which bypasses the entire Spring Security filter
chain. As a result, /rest/repositories/ruleset/upload and /repositories/* are...

APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9

13 August 2026 at 21:54

Posted by Apple Product Security via Fulldisclosure on Aug 13

APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9

macOS Sequoia 15.7.9 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/148171.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Screen Sharing
Available for: macOS Sequoia
Impact: An attacker on the network may be able to authenticate to...

APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9

13 August 2026 at 21:54

Posted by Apple Product Security via Fulldisclosure on Aug 13

APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9

macOS Sonoma 14.8.9 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/148172.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Screen Sharing
Available for: macOS Sonoma
Impact: An attacker on the network may be able to authenticate to...

Dangling DNS record for bastion.certb.cdp.bethesda.net

6 August 2026 at 19:40

Posted by shed riot on Aug 06

# Summary

The hostname resolved to an address within a dynamic cloud IP pool.
The address had been released and was no longer controlled by the
organisation operating the hostname.

This condition is referred to as an "afterlife" issue.

Unlike a conventional CNAME-based subdomain takeover, the DNS record
pointed directly to a reusable cloud IP address. An attacker obtaining
that address could receive traffic intended for the...

CL.0 desync in www.microsoft.com

6 August 2026 at 19:40

Posted by shed riot on Aug 06

# Summary

I reported the issue to the Microsoft Security Response Center twice:

* VULN-165381, MSRC case 102964
* VULN-165876, MSRC case 103259

In both cases, they do not appear to have even looked at the PoCs, and so
have failed to adequately investigate before reaching a decision.

# Vulnerability

CWE-444: HTTP Request/Response Smuggling

The observed behaviour was consistent with CL.0 HTTP desync within the
request-processing chain.

#...

CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)

6 August 2026 at 19:36

Posted by Γ–ner Efe GΓΌngΓΆr on Aug 06

Hello Full Disclosure,

I'd like to share an independent lab Proof-of-Concept for CVE-2026-15013.

### CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated
Authentication Bypass

SAML Signature Algorithm Confusion vulnerability. An unauthenticated
attacker can forge a valid SAMLResponse by forcing HMAC-SHA1 verification
against the IdP's public key, allowing full account takeover (including
administrators).

Root cause:...
❌