Vulnerabilities’ home

Joined July 2025
Secure Boot in Windows: completing the core chain-of-trust transition Read on dbugs: dbu.gs/news/secure-boot-in-w… Microsoft is completing the transition (support.microsoft.com/en-us/…) to new Secure Boot certificates. The final and most significant stage is the replacement of Microsoft Windows Production PCA 2011, which is used to sign the Windows boot loader. It will be replaced by the new Windows UEFI CA 2023 on October 19, 2026. In parallel, Microsoft is strengthening its signing algorithms and moving to stronger cryptography (support.microsoft.com/en-us/…), including RSA-3072 and SHA-384, by the end of 2026. In addition, a move to post-quantum signatures (Post-Quantum Cryptography, PQC) is planned for 2027. How Secure Boot trust works Secure Boot verifies the signature of everything that runs in the early boot stage against keys embedded in the UEFI firmware. Its trust rests on four components stored in UEFI variables: • PK (Platform Key) — the platform owner's key; • KEK (Key Exchange Key) — the keys that authorize updates to DB and DBX; • DB (Signature Database) — the "allow list": a database of trusted certificates, keys and hashes; • DBX (Revoked Signatures Database) — the "deny list" (revocation): a database of revoked or forbidden certificates, keys and hashes. It is this combination that prevents a bootkit from loading: a malicious or revoked boot loader fails the DB/DBX check. For example, if a vulnerability is found in a boot loader, Microsoft can add its signature to the DBX "deny list"; after that, Secure Boot will block it while verifying the boot loader's signature, before Windows even starts. Devices that do not receive the new certificates will keep booting and keep getting regular Windows updates, but over time they may stop receiving new protections for early-boot components, including DB/DBX updates and mitigations for new boot-chain vulnerabilities. A few important nuances to keep in mind: 1. Without an updated KEK, devices may lose the ability to receive future DB and DBX updates, including revocation records for vulnerable boot loaders. 2. Secure Boot updates are historically deferred over the risk of a device failing to boot, so many devices end up in different trust states. 3. The root of boot trust is changed very rarely, so the rotation itself becomes an attack surface. During the transition, new keys are written to the DB and KEK UEFI variables, and the old and new chains coexist for a while. Old signatures stay valid until they are revoked, and mistakes in the rollout can open a window for attack. 4. Microsoft explicitly notes that an outdated chain weakens, over time, scenarios that rely on Secure Boot trust — in particular BitLocker hardening and trust in third-party boot loaders.
179
OpenAI introduces watermarking for AI-generated text Read on dbugs: dbu.gs/news/openai-introduce… In response to the EU AI Act requirements mandating that AI-generated text be identifiable in a machine-readable way, OpenAI introduced textGrain (openai.com/index/eu-text-pro…), a text watermarking system (cdn.openai.com/pdf/e9508624-…) that adds an invisible statistical signal to the model’s word choices. Rather than inserting hidden characters, textGrain influences which words the model chooses at each step of generation. The system slightly alters the statistical pattern of word selection, creating a signal that is imperceptible to humans but detectable by a detector. Because the signal is embedded in the words themselves, it does not depend on metadata and survives ordinary copying. However, editing and translation can significantly weaken the watermark, so detection reliability depends on the length and content of the text. The technology has several limitations, which is why OpenAI is not making the detector publicly available: • shorter or more constrained text is harder to detect; • replacing 10% of words with synonyms reduces the detection rate from about 92% to 66%, while replacing 25% of words reduces it to 17%; • the absence of a detected watermark does not prove human authorship. The text may have been edited, translated, generated by another model, or created before watermarking was introduced. API customers globally can opt in to text watermarking for select models. Text watermarking is off by default in the API. Over the coming weeks, OpenAI will add an invisible watermark to eligible ChatGPT and Codex text output in the European Union. Access to the text watermark detector will initially be limited to approved researchers and expert organizations.
1
1
237
Sale of 4 0day exploits for Windows and enterprise infrastructure Read on dbugs: dbu.gs/news/sale-of-4-0day-e… 1. 0day exploit for Windows Vulnerability type: LPE Affected versions: Windows 11 2. 0day exploit for Ivanti Connect Secure SSLVPN Vulnerability type: pre-auth RCE Ivanti Connect Secure is an enterprise SSL VPN gateway that provides employees with remote access to internal company resources. It is typically deployed at the network perimeter, making vulnerabilities in it particularly critical. 3. 0day exploit for Zimbra Collaboration Vulnerability type: pre-auth RCE Zimbra Collaboration is an email and collaboration platform for businesses. It includes email, calendars, contacts, and a web interface. Companies often deploy it as an alternative to Microsoft Exchange. 4. 0day exploit for Switchvox Vulnerability type: RCE Switchvox is an enterprise IP telephony/VoIP platform based on Asterisk. It is used for internal and external calls, SIP, voicemail, and office PBX features.
1
1
273
A PoC/exploit has been discovered for vulnerability CVE-2026-59346 PT ID: PT-2026-85031 Read on dbugs: dbu.gs/vulnerability/PT-2026… Vendor: VMware Products: • VMware Workstation • VMware Fusion Description: VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1) Link: github.com/0xCyberstan/CVE-2…
2
332
A PoC/exploit has been discovered for vulnerability CVE-2026-102489 PT ID: PT-2026-103453 Read on dbugs: dbu.gs/vulnerability/PT-2026… Vendor: Zammad GmbH Product: Zammad Description: Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions. Link: github.com/hunt-benito/the-c…
244
A PoC/exploit has been discovered for vulnerability CVE-2026-82531 PT ID: PT-2026-106715 Read on dbugs: dbu.gs/vulnerability/PT-2026… Vendor: smarty-php Product: smarty Description: Smarty before 4.5.8 and 5.x before 5.8.5 contains a code injection vulnerability where the top-level nocache_hash is never restored during extends:/multi-component template inheritance, leaving it null. Attackers can supply assigned data containing a forged SmartyNocache marker that is copied verbatim into the regenerated PHP cache file, executing arbitrary PHP on include for remote code execution. Link: github.com/murrez/cve-2026-8…
2
3
307
A PoC/exploit has been discovered for vulnerability CVE-2026-57967 PT ID: PT-2026-89272 Read on dbugs: dbu.gs/vulnerability/PT-2026… Vendor: Apache Software Foundation Products: • Apache Artemis • Apache ActiveMQ Artemis Description: An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. Link: github.com/c0dem4sters/cve-2…
2
4
416
A PoC/exploit has been discovered for vulnerability CVE-2026-21589 PT ID: PT-2026-106255 Read on dbugs: dbu.gs/vulnerability/PT-2026… Vendor: Atlassian Products: • Bitbucket Data Center • Confluence Data Center • Jira Service Management Data Center • Jira Software Data Center • Bamboo Data Center • Crowd Data Center • Crucible • Fisheye Description: This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents. Link: github.com/marcusprogram/cve…
2
8
628
Google Cloud Application Integration JavaScript sandbox escape Read on dbugs: dbu.gs/news/google-cloud-app… Google Cloud Application Integration lets users add JavaScript tasks to integration workflows. Legacy tasks ran on Rhino, a Java-based JavaScript engine, with a custom permission checker restricting access to the surrounding execution environment. An authorized workflow author combined permissions that remained available inside the sandbox to execute system commands as the task service account. • Disabling the Rhino thread checks — The allowed permission set included "ReflectPermission("suppressAccessChecks")", which made private Java fields accessible through reflection. The script opened the private static "COMMON_PERMISSIONS" field and added "AllPermission" and "modifyThread". This neutralized the checks applied to the untrusted Rhino thread, although a separate policy still restricted file and process access. • Escaping through a child JVM — The remaining policy allowed writes to "/tmp" and execution of "$JAVA_HOME/bin/java". The script saved a compiled Java class under "/tmp" and launched it with "java -cp /tmp ExecuteCommands". The child JVM was not marked as an untrusted Rhino thread, so it could run system commands and return their output through a file and "event.log()". Exploitation required permission to create and run JavaScript tasks and affected only the former Rhino engine. Google tracks the issue as CVE-2025-0982; new tasks moved to V8 in January 2025, and Rhino execution was fully blocked on March 30, 2026. The demonstrated result was command execution inside the managed task environment, not an escape to the underlying host or cluster control plane. Article: nopnop.pro/2026/08/26/escapi… CVE-2025-0982 — PT-2025-5810: dbu.gs/vulnerability/PT-2025…
243
Telerik RadAsyncUpload RCE through forged encrypted upload settings Read on dbugs: dbu.gs/news/telerik-radasync… "RadAsyncUpload", the file-upload component in Telerik UI for ASP.NET AJAX, stored its upload rules in an AES-CBC-encrypted JSON blob returned by the browser. Because the blob was not authenticated, distinguishable decryption and JSON parsing failures created a padding oracle. The researchers used it to change the allowed file extensions, upload a DLL, and execute code as the IIS application pool identity. • Forging the upload configuration — Invalid PKCS#7 padding raised a cryptographic error, while valid padding followed by malformed JSON reached a parsing error. Repeated queries exposed enough information to recover and modify the configuration without the encryption key. A fixed IV prevented the exploit from replacing the JSON from its first byte, so it kept a genuine prefix and forged only the suffix. The suffix added a second "AllowedFileExtensions" field, and "JavaScriptSerializer" accepted its final value, allowing DLL uploads. • Turning the upload into code execution — The upload metadata let the client select the .NET type used to process the result. The exploit set "AsyncUploadTypeName" to "System.Configuration.Install.AssemblyInstaller" and pointed "Path" to the uploaded DLL. When the application read "UploadResult", Telerik instantiated the selected class and loaded the file through "Assembly.LoadFrom". Windows then invoked "DllMain", executing the payload. The chain requires an exposed page containing "RadAsyncUpload", an explicit "Telerik.AsyncUpload.ConfigurationEncryptionKey", and a server-side upload handler that reads "UploadResult". Progress lists versions "2010.1.309" through "2026.2.519" as affected and fixes the issue in "2026.2.708" by replacing AES-CBC with AES-GCM. The public exploit automates the error-based oracle; the researchers also confirmed a timing oracle when detailed errors are hidden, but have not published that mode. Article: tantosec.com/blog/2026/09/te…
2
2
342
OAuth code leakage through CSS preserved by DOMPurify Read on dbugs: dbu.gs/news/oauth-code-leaka… After login, an OAuth provider redirects the user to a URL such as "/callback?code=...". If that page renders attacker-controlled HTML after sanitizing it with DOMPurify, scripts are removed but inline CSS may remain. That CSS can leak the authorization code without executing JavaScript. • CSS request modifier — Chrome 150 added "referrer-policy()" to CSS "url()". An attacker can inject "
". The browser requests the image and includes the callback path and query string, including "code", in the "Referer" header. DOMPurify preserves the payload because it keeps the "style" attribute and does not sanitize the CSS inside it. • DOMParser side effect — The second technique used "". On affected Chromium builds, the browser applied the policy from "" while parsing the HTML, before DOMPurify removed the tag. The remaining image then triggered a request whose "Referer" contained the callback path, query string, and OAuth code. This bug is tracked as CVE-2026-79185 and has been fixed. The attack requires the application to render attacker-controlled data on the callback page, DOMPurify to preserve "style", CSP to allow an external resource request, and the OAuth code to remain in the path or query string. Secrets placed after "#" are never sent in "Referer". The researchers demonstrated the leakage mechanism, but not an end-to-end attack against a named OAuth provider. Article: blog.voorivex.team/oauth-tok… CVE-2026-79185 — PT-2026-81745: dbu.gs/vulnerability/PT-2026…
1
275
Monster333 — 401/403 bypass testing with control requests Read on dbugs: dbu.gs/news/monster333-401-4… Monster333 is a Python CLI for testing access-controlled routes with trust headers, path and encoding variants, HTTP method changes, and separate raw probes for h2c and request smuggling. Capabilities: • runs 318 request variants across 13 technique groups; • compares responses with the blocked baseline and a random path; • rejects known WAF block pages and behavior reproduced by harmless control headers; • replays stable "2xx" candidates; • writes JSON, Markdown, and HTML reports with a reproducible "curl" command. Its useful distinction is the validation sequence around each candidate. These checks reduce routine response noise but cannot guarantee zero false positives; h2c and request-smuggling signals still require manual confirmation. Tool: github.com/shafiquljob333-rg…
235
PostMessage Tracker — live postMessage inspection in Chrome DevTools Read on dbugs: dbu.gs/news/postmessage-trac… PostMessage Tracker is a Chrome extension that adds a DevTools panel for observing messages exchanged between a page and its frames. It records sent and received "postMessage" events in real time and displays their origin, timestamp, metadata, and payload. Capabilities: • filter events by origin, type, or payload content; • pretty-print JSON payloads; • pause, resume, and clear the event log; • block selected messages based on origin or data. The extension is useful for reconstructing cross-window flows and selecting messages for manual checks of "event.origin", sensitive data exposure, or unsafe payload handling. The store listing does not claim listener source inspection, message editing and replay, automated origin-bypass testing, or PoC generation. Tool: chromewebstore.google.com/de…
229
The XSS inside your favorite iOS app Read on dbugs: dbu.gs/news/the-xss-inside-y… A WKWebView without explicit download handling can render a response marked "Content-Disposition: attachment" instead of downloading or blocking it. When a service hosts user uploads on a trusted origin, an attacker can upload HTML and distribute a direct file URL that becomes active content inside an application's embedded browser. The default behavior demonstrated in the article is sandboxed HTML and CSS rendering. That is sufficient for trusted-origin UI spoofing and state-changing GET requests through elements such as "". JavaScript execution is not universal: the authors observed full XSS only in specific application and response combinations. Firefox and Firefox Focus for iOS confirmed the broader mechanism. Firefox ignored the attachment disposition, while Focus also rendered binary MIME types; Mozilla tracked the issues as CVE-2025-55030 and CVE-2025-55032 and fixed both. The article also reports affected social in-app browsers, wallet dApp browsers, and PlayStation browsers, but not every listed application has a published independent advisory. Exploitation requires attacker-controlled file contents on a useful origin and a victim opening the direct URL in an affected embedded browser. Applications can prevent the transition by handling "decidePolicyFor navigationResponse" and choosing ".download" or ".cancel" for attachment or unsupported MIME responses. Article: v12.sh/blog/webkit CVE-2025-55030 — PT-2025-33826: dbu.gs/vulnerability/PT-2025… CVE-2025-55032 — PT-2025-33827: dbu.gs/vulnerability/PT-2025…
1
3
389
Unauthenticated RCE in GeoNetwork through an uploaded XSLT formatter Read on dbugs: dbu.gs/news/unauthenticated-… GeoNetwork is a Java application for publishing and searching geospatial metadata. It uses XSLT-based formatters to render public records. The main finding turns that feature into unauthenticated command execution by chaining a missing authorization check on formatter creation with Saxon's ability to call Java methods. The article also documents an independent SSRF and reflected XSS. • XSLT-to-RCE chain — Most "FormatterAdminApi" methods required "@PreAuthorize", but "addFormatter" did not. An anonymous user could upload a stylesheet and invoke it through the public rendering endpoint using any record UUID returned by GeoNetwork search. Saxon allowed external Java functions, so the stylesheet could call "java.lang.Runtime.exec()" or "java.lang.ProcessBuilder". The author demonstrated a reverse shell on version "4.4.11"; commands ran with the privileges of the GeoNetwork process. • SSRF — The SLD import endpoint issued an HTTP GET to a caller-controlled URL without validating the scheme or destination. This allowed requests to internal services. When the response contained valid XML, GeoNetwork returned its contents to the caller; other responses still provided a blind SSRF primitive. • Reflected XSS — "catalog.search" inserted "uiconfig" directly into an inline JavaScript call. An expression such as "(payload,{})" could execute the payload while returning the object expected by the surrounding code. Opening a crafted link therefore ran JavaScript in the GeoNetwork origin, where a script-readable XSRF token could be used for protected requests as the victim. Article: ethiack.com/info-hub/researc…
1
4
341
PowerLift API key escalation exposed diagnostic logs and a potential RCE path Read on dbugs: dbu.gs/news/powerlift-api-ke… PowerLift collects diagnostic data from Outlook Mobile and other Microsoft applications. The researchers had a key for a development instance that appeared limited to uploading logs, but "POST /api/tenant/settings/keys" returned every existing key and its permissions. One active key had read, write, and Gym access, unlocking the rest of the tested API. • Diagnostic archive access — "/gym/combo/incidents" listed uploaded incidents, while "/gym/incidents/:id/files.zip" returned their files. The sampled archives contained Microsoft employee email addresses, bearer tokens, Copilot chat data, and metadata for internal OneDrive and SharePoint files. • Potential server-side code execution — "/api/classifiers" accepted JavaScript classifiers that could be enabled and run against the next incoming incident. "importNamespace" was available, indicating Jint with CLR interop. If "System.Diagnostics.Process" was exposed by the target configuration, "System.Diagnostics.Process.Start()" could launch a process on the server. The researchers stopped before creating a malicious classifier or executing a command, so this remained a technically supported RCE path rather than a completed proof. The full-access key also exposed remedy management, including the "go_to_url" action shown in Outlook Mobile, and scrubber rules used to remove sensitive data from uploaded logs. Exploitation required a valid PowerLift API key for the development instance. Microsoft reported deploying a fix on May 6, 2026, but did not publish the patch details. Article: careful.net/blog/powerlift/
2
295
DOMPurify XSS caused by DOM serialization and HTML reparsing Read on dbugs: dbu.gs/news/dompurify-xss-ca… Both bugs appeared when an application passed a browser-created DOM tree to DOMPurify and then inserted the returned string with "innerHTML". DOMPurify inspected one tree, while the browser created a different one during the second parse. Passing the same payload as an HTML string did not work because the first parse normalized it before sanitization. • Raw-text elements — The attacker created an "xmp" or "iframe" element through the DOM API and placed "" inside its text. DOMPurify saw the payload as text. After serialization and insertion through "innerHTML", "" closed the text element and the following "img" became active markup. This route required the application to allow the affected element through "ADD_TAGS". • Attribute case mismatch — In DOMPurify "3.4.13", an XML-parsed node could preserve the uppercase attribute "ONERROR". DOMPurify recognized it as dangerous after normalizing the name, but the removal step did not match the case-preserved attribute. It remained in the output, and the later HTML parse turned it into an event handler. This route required no custom sanitizer options, although the node had to come from XML, XHTML, or another case-preserving parser. The researchers reproduced both bugs in Chromium, Firefox, and WebKit. DOMPurify "3.4.14" extended the raw-text check beyond "style" and changed attribute removal to target the exact "Attr" node. The maintainers classified the changes as hardening and did not publish a security advisory. Article: rh.hacktapus.ir/dompurify-ar…
1
239
Flyntor finds hidden frontend modules and reconstructs their source Read on dbugs: dbu.gs/news/flyntor-finds-hi… Flyntor collects the JavaScript files that make up a web application. It reads the bundler runtime to discover lazy-loaded modules that the current page never requests. When source maps include the original content, Flyntor rebuilds the source files and directory structure locally. Capabilities: • discovers regular and lazy-loaded modules from the bundler runtime; • extracts source files from inline and external source maps; • finds routes, GraphQL operations, DOM sinks, and "postMessage" listeners; • compares frontend code across application versions; • provides the collected code to external agents through MCP. This can reveal administrative UI code, client-side role checks, and API calls that a normal crawl may miss. Without source maps, Flyntor still analyzes the minified bundles but cannot reconstruct the original files. Network requests require an explicit scope, and every result still needs manual verification. Tool: github.com/flyntor/flyntor
228
h1-brain — HackerOne context for AI-assisted bounty sessions Read on dbugs: dbu.gs/news/h1-brain-hackero… h1-brain is a local Python MCP server that syncs a researcher's rewarded reports, accessible programs, and scopes from the HackerOne API into SQLite. It also ships with a searchable database described as containing more than 3,600 bounty-awarded public disclosures. Capabilities: • "hack(handle)" fetches the current program scope and combines it with personal and public report history; • personal reports can be filtered by program, weakness, and severity, then retrieved with their full write-ups; • the bundled disclosure database supports full-text search by query, program, or weakness; • the briefing highlights assets absent from personal report titles and weakness types rewarded on other programs; • attachment tools return fresh temporary download URLs from HackerOne. The distinction is the prebuilt briefing rather than raw API access: it puts current scope, past successful techniques, coverage gaps, and public disclosures into one result for the connected agent. h1-brain does not scan or exploit targets by itself, and its recommendations remain heuristics derived from stored report metadata. It requires Python 3.10+, a HackerOne API token, and an MCP-compatible client. Tool: github.com/PatrikFehrenbach/…
217
tturl — timeless timing and request races over HTTP/2 Read on dbugs: dbu.gs/news/tturl-timeless-t… tturl is a Go CLI for finding small request-processing differences and exercising race conditions. It releases same-origin HTTP/2 requests behind a shared TLS-record gate and compares response arrival order, making much of the network-path jitter common to the batch. Capabilities: • "race" preserves each response and its arrival order; • "measure" reports rank distributions without making a statistical finding; • "analyse" tests a fixed batch using Monte Carlo randomisation and Holm-adjusted pair evidence; • "detect" adaptively looks for one early or late outlier; • "--report json" emits schema-governed JSON Lines. The same release primitive can also exercise check-then-act races around quotas, balances, stock, and single-use operations. Arrival-order modes require HTTP/2 over TLS, and every request in a batch must use the same host and port. Proxies that terminate or reframe TLS or HTTP/2 can change the boundary being tested. Tool: github.com/tantosec/tturl
1
10
645