Posts tagged Emergent Threat Response

Vulnerabilities and Exploits
CVE-2022-41080, CVE-2022-41082: Rapid7 Observed Exploitation of `OWASSRF` in Exchange for RCE
Glenn Thorpe

Exposure Management
CVE-2022-27518: Critical Fix Released for Exploited Citrix ADC, Gateway Vulnerability
Glenn Thorpe

Vulnerabilities and Exploits
CVE-2022-42475: Critical Unauthenticated Remote Code Execution Vulnerability in FortiOS; Exploitation Reported
Glenn Thorpe

Threat Research
CVE-2022-27510: Critical Citrix ADC and Gateway Remote Authentication Bypass Vulnerabilities
Rapid7

Vulnerabilities and Exploits
Rapid7’s Impact from OpenSSL Buffer Overflow Vulnerabilities (CVE-2022-3786 & CVE-2022-3602)
Rapid7

Vulnerabilities and Exploits
Rapid7’s Impact from Apache Commons Text Vulnerability (CVE-2022-42889)
Rapid7

Exposure Management
CVE-2022-3786 and CVE-2022-3602: Two High-Severity Buffer Overflow Vulnerabilities in OpenSSL Fixed
Rapid7

Vulnerabilities and Exploits
CVE-2021-39144: VMware Cloud Foundation Unauthenticated Remote Code Execution
Caitlin Condon

Exposure Management
CVE-2022-42889: Keep Calm and Stop Saying "Text4Shell"
Erick Galinkin

Vulnerabilities and Exploits
CVE-2022-40684: Remote Authentication Bypass Vulnerability in Fortinet Firewalls, Web Proxies
Glenn Thorpe

Exposure Management
Exploitation of Unpatched Zero-Day Remote Code Execution Vulnerability in Zimbra Collaboration Suite (CVE-2022-41352)
Ron Bowes

Exposure Management
CVE-2022-41040 and CVE-2022-41082: Unpatched Zero-Day Vulnerabilities in Microsoft Exchange Server
Caitlin Condon

Exposure Management
CVE-2022-36804: Easily Exploitable Vulnerability in Atlassian Bitbucket Server and Data Center
Ron Bowes

Exposure Management
Active Exploitation of Multiple Vulnerabilities in Zimbra Collaboration Suite
Caitlin Condon

Exposure Management
Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26138
Glenn Thorpe

Exposure Management
Exploitation of Mitel MiVoice Connect SA CVE-2022-29499
Caitlin Condon

Exposure Management
CVE-2022-27511: Citrix ADM Remote Device Takeover
Erick Galinkin

Exposure Management
Active Exploitation of Confluence CVE-2022-26134
Rapid7

Exposure Management
CVE-2022-30190: "Follina" Microsoft Support Diagnostic Tool Vulnerability
Rapid7

Exposure Management
CVE-2022-22972: Critical Authentication Bypass in VMware Workspace ONE Access, Identity Manager, and vRealize Automation
Jake Baines

Vulnerabilities and Exploits
CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection
Jake Baines