New exploits for Microsoft Windows, Monsta FTP, Progress ShareFile, 9Router, FUXA, Apache Zeppelin, and a host of WordPress plugins. Signatures and queries for SonicWall SMA1000.

Happy Friday! We've got another jam-packed exploit release, so we'll cut to the chase. The following are the Initial Access Intelligence team's deliverables for the past week.

CVE-2026-50656: Windows Defender TOCTOU Race Condition Local Privilege Escalation "RoguePlanet"

By customer request, the team developed an exploit for RoguePlanet, a high-severity TOCTOU vulnerability in Windows Defender that was dropped as a zero-day last month. The vulnerability allows unprivileged users to escalate to SYSTEM on desktop versions of Windows with Defender engine versions below 1.1.26060.3008 installed. No exploitation has been reported yet. VulnCheck coverage includes a version scanner and an improved exploit written using a new, minimized C++ version of our go-exploit framework. As this is a local privilege escalation exploit for the Windows operating system, there are no ASM queries, network rules, or PCAPs included with this exploit.

CVE-2026-60105: Monsta FTP Unauthenticated SSRF via IPv4-Mapped IPv6 Blocklist Bypass

The team also added an exploit this week for a VulnCheck-discovered vulnerability in Monsta FTP that our team disclosed on July 14 after the supplier silently patched it. CVE-2026-60105 is an unauthenticated SSRF vulnerability that functions as a useful primitive for mapping internal networks or stealing IAM creds from cloud environments. The team's Censys query finds 3K+ Monsta FTP instances online — full vulnerability details are available in our disclosure blog. Coverage includes a version scanner, network rules, a PCAP, and a target Docker container.

CVE-2026-2699 and CVE-2026-2701: Progress ShareFile Storage Zones Controller Pre-Auth Remote Code Execution Chain

The team developed an exploit chaining CVE-2026-2699 and CVE-2026-2701 for unauthenticated RCE against Progress ShareFile's on-premises Storage Zones Controller (SZC), a secure content collaboration and file transfer product that commonly houses sensitive data and has a prior history of exploitation. An unauthenticated attacker can abuse the CVE-2026-2699 authentication bypass to reach the controller's restricted admin surface, repoint its storage, and then leverage the CVE-2026-2701 file upload flaw to drop and execute a webshell as the IIS service account — a short hop from full SYSTEM. watchTowr published original research on this chain in April 2026. CVE-2026-2699 is on VulnCheck KEV as of July 10, after Shadowserver began reporting exploitation. Our Censys query identifies roughly 25,000 potentially vulnerable ShareFile servers online.

Our coverage includes a PCAP, Suricata and Snort rules, a Sigma rule, a YARA rule, and ASM queries.

CVE-2026-59800: 9Router Unauthenticated Tailscale Install Command Injection RCE

The team developed an exploit for CVE-2026-59800, an unauthenticated OS command injection leading to remote code execution in 9Router, decolua's 9router-app dashboard for managing AI provider infrastructure. A gap in its authentication leaves the Tailscale-install tunnel endpoint reachable without a session, and because a service that manages system tunnels typically runs as root or with passwordless sudo, an exposed instance is a direct unauthenticated path to a root shell. VulnCheck assigned this CVE and added it to VulnCheck KEV on July 7, 2026, after Shadowserver confirmed in-the-wild exploitation. Our Shodan query identifies around 900 exposed instances online.

Our exploit ships with a Docker target, encrypted and unencrypted PCAPs, Suricata and Snort rules, and ASM queries.

CVE-2026-25895: frangoteam FUXA Unauthenticated Upload Path Traversal File Write

The team developed an exploit for CVE-2026-25895, an unauthenticated path traversal file write vulnerability in version 1.2.9 of frangoteam's FUXA SCADA/OT management dashboard. Our exploit allows an attacker to gain a root shell on the vendor-provided Docker container or exercise the raw file-write primitive. The vulnerability isn't yet known to be exploited in the wild, though VulnCheck's Canary Intelligence network has observed exploitation of a different FUXA vulnerability (CVE-2023-33831) as recently as yesterday. Our FOFA query shows over 500 internet-facing FUXA instances.

Our exploit ships with a Docker target, unencrypted PCAPs, Suricata and Snort rules, and ASM queries.

CVE-2026-1357: WPvivid Backup and Migration Unauthenticated Null-Key Arbitrary File Upload RCE

The team developed an exploit for CVE-2026-1357, an unauthenticated arbitrary file upload leading to RCE in WPvivid Backup & Migration, a widely deployed WordPress backup plugin. On any site with an active WPvivid transfer key, the flaw lets an unauthenticated attacker drop a webshell and take over the server. Wordfence reported the vulnerability affects over 800,000 WordPress sites. VulnCheck added this CVE to its KEV on February 11, 2026. Our exploit ships with a Docker target, encrypted and unencrypted PCAPs, Suricata and Snort rules, and a YARA rule.

CVE-2026-3844: Breeze Cache for WordPress Unauthenticated Gravatar SSRF Arbitrary File Upload RCE

The team developed an exploit for CVE-2026-3844, an unauthenticated server-side request forgery leading to arbitrary file upload and remote code execution in Breeze, Cloudways' WordPress cache plugin with around 100,000 active installs. On a vulnerable site, an unauthenticated attacker can plant a webshell and run code, giving full control of the host. VulnCheck added this CVE to its KEV on April 23, 2026. Our Shodan query surfaces around 20 exposed instances online. Our exploit ships with a Docker target, encrypted and unencrypted PCAPs, Suricata and Snort rules, a YARA rule, and ASM queries.

CVE-2025-15030: Cozmoslabs Profile Builder WordPress Plugin Unauthenticated Password Reset

The team developed an exploit for CVE-2025-15030, an unauthenticated arbitrary password reset in Cozmoslabs' Profile Builder, which is a widely deployed WordPress user registration and profile plugin. Because the reset can target any account, an unauthenticated attacker can seize an administrator login and take over the entire site. VulnCheck added this CVE to our KEV list on February 3, 2026. Our Shodan query surfaces around 150 exposed instances online. Our exploit ships with a Docker target, encrypted and unencrypted PCAPs, Suricata and Snort rules, and ASM queries.

CVE-2025-11749: AI Engine WordPress Plugin MCP Unauthenticated Admin Creation to RCE

The team also developed an exploit for CVE-2025-11749, an unauthenticated privilege escalation-to-RCE in AI Engine, a popular WordPress AI-assistant plugin. VulnCheck added this CVE to its KEV on November 5, 2025. Our Shodan query surfaces around 5 exposed instances online. Our exploit ships with a Docker target, encrypted and unencrypted PCAPs, Suricata and Snort rules, and ASM queries.

CVE-2024-31866: Apache Zeppelin Environment Variable Injection

The team added an exploit this week for an improper encoding vulnerability that allows for arbitrary code execution in Apache Zeppelin, an open-source web-based notebook. Public PoCs have demonstrated that Apache Zeppelin supports a variety of interpreters that could be used to trigger payload execution; instead of requiring the user to manually choose which interpreter to use, our exploit queries the interpreter list from the server and picks one automatically. No exploitation has been reported yet. Our exploit includes a version scanner, Suricata and Snort rules, PCAPs, and a target Docker container.

CVE-2026-15409: SonicWall SMA1000 WorkPlace wsproxy SSRF-to-Erlang RPC Unauthenticated RCE via Hardcoded BMID (Signatures and Queries Only)

The team developed network signatures and ASM queries for a recently disclosed zero-day (CVE-2026-15409) in SonicWall SMA1000 network appliances. Disclosed on July 14, it was added to both VulnCheck KEV and CISA KEV on the same day, with multiple organizations reporting exploitation in the wild. The team's Censys query finds roughly 1,600 potentially vulnerable devices online.