Happy Friday! The VulnCheck Initial Access Intelligence team's deliverables for the past week are below.
This week, the team developed an exploit for CVE-2026-16232, a critical authentication bypass vulnerability in Check Point's Security Management and Multi-Domain Security Management servers, which are used to administer Check Point firewalls. An attacker who can reach the management server over the network can bypass authentication entirely and obtain a full administrator session without any credentials, giving them control over the security policy that gets pushed to every firewall the server manages. Check Point disclosed the flaw as a zero-day on July 19, 2026; it was added to VulnCheck KEV the same day and CISA KEV three days later. The team's Censys query finds 5,500+ potentially affected systems online.
Coverage includes an exploit, PCAPs, Suricata and Snort rules, and ASM queries.
_trust/default.aspx SecurityToken Cookie Deserialization Pre-Auth RCEThe team also developed an exploit for CVE-2026-50522, a critical unauthenticated RCE in on-premises Microsoft SharePoint Server's WS-Federation sign-in handler. Reports of exploitation began rolling in on July 20 after a public PoC dropped, with watchTowr noting that attackers are stealing ASP.NET machine keys for persistence. VulnCheck Target Intelligence shows 78 vulnerable SharePoint servers on the public internet and a broader internet-exposed SharePoint population of 8,300+.
Our coverage includes an exploit, a version scanner, encrypted and unencrypted PCAPs, and ASM queries. Network signatures aren't provided, as the gadget is DEFLATE-compressed and base64-encoded inside the cookie, which neither Suricata nor Snort can re-inflate to inspect.
The team developed an exploit for CVE-2026-16723, an unauthenticated remote code execution vulnerability in Alibaba Fastjson, a Java JSON library. A single unauthenticated web request lets an attacker take full control of the underlying server, with no login or token required and no special configuration on the target. The vulnerability was added to VulnCheck KEV on July 23 after Imperva began reporting widespread exploitation. It is not yet on CISA KEV. Our exploit ships with a Docker target, PCAPs, Suricata and Snort rules, and a YARA rule.
The team added an exploit for CVE-2026-58635, a local privilege escalation vulnerability in the Windows Braille Narrator accessibility feature that was patched on July 14, 2026. On systems where the vulnerable feature is installed, an unprivileged user can pass an arbitrary executable to the Braille API, which will be executed as NT AUTHORITY\LOCAL SERVICE. The vulnerability has not yet been observed to be exploited in the wild. The team's exploit comes with an EVTX log and a Sigma rule.
The team developed an exploit for CVE-2026-61511, a critical unauthenticated remote code execution in vBulletin, one of the most widely deployed commercial forum platforms. The template runtime's runMaths() method evaluates attacker-supplied input from the pagenavpagenumber parameter as PHP, so an unauthenticated request reaches code execution as the web server user with no token or login. No exploitation has been reported yet. VulnCheck Target Intelligence surfaces around 385 exposed vBulletin hosts. Our exploit ships with PCAPs, Snort and Suricata rules, and ASM queries.
The team developed an exploit for CVE-2026-43503 aka "DirtyClone", a local privilege escalation in the Linux kernel. This completes our coverage (so far) of the "DirtyFrag" family, a cluster of related kernel flaws including CVE-2026-43284, CVE-2026-43500, and CVE-2026-46300. The vulnerability makes a strong post-exploitation escalation primitive, taking any unprivileged local user to full root. We expect it to be picked up by attackers for several reasons: Public proof-of-concept code already exists, it affects a wide range of kernel versions, and the escalation happens entirely in memory, never touching disk, which leaves behind none of the file modification artifacts defenders typically hunt for. The vulnerability is not yet in CISA KEV and we have seen no in-the-wild exploitation to date.
As a local kernel bug with no exposed network surface, network signatures and ASM queries do not apply. Our exploit ships with a version scanner.
The team added an exploit for CVE-2026-56121, an unauthenticated remote code execution vulnerability in Feast, a widely used open-source feature store for machine learning. Feast's registry server, which runs unauthenticated by default, mishandles data sent by a client, allowing anyone who can reach the service over the network to run commands on it and take full control of the server. The vulnerability was disclosed in June 2026 and fixed in Feast 0.63.0, with public proof-of-concept code appearing the same month. No exploitation has yet been observed in the wild. Because the affected registry service is not currently fingerprinted by Shodan or Censys, no ASM queries ship with this release.
Coverage includes an exploit, target Docker container, a packet capture, and Suricata and Snort detection rules.
The team also added coverage for an authenticated sandbox escape vulnerability impacting multiple versions of n8n. No in-the-wild exploitation of CVE-2026-27577 has been observed as of yet, but previous n8n vulnerabilities like CVE-2025-68613 and CVE-2026-21858 have seen threat activity, with CVE-2025-68613 exploits attributed to Iranian state-sponsored actor Static Kitten. VulnCheck Target Intelligence finds just under 15K n8n instances vulnerable to CVE-2026-27577. Coverage includes an exploit, version scanner, Docker target, PCAPs, network signatures, and ASM queries.
The team developed an exploit for CVE-2026-65883, a critical unauthenticated PHP object injection in Aimy Captcha-Less Form Guard, a Joomla anti-spam plugin. The vulnerability was discovered by VulnCheck's own Valentin Lobstein. Any unauthenticated visitor to a form the plugin protects can forge its hidden state token and reach a PHP deserialization sink, which chains to remote code execution as the web user on Joomla 3.9 through 5.2.1. It ironically turns an anti-spam plugin, whose whole job is to harden public forms, into an unauthenticated code execution endpoint on every form it guards. It affects Aimy Captcha-Less Form Guard 18.0 through 20.0 and is fixed in 20.1. The full write-up is on our blog. The captcha renders only on the forms an administrator wired it to, never on a homepage, so internet-wide scanners under-report results for the plugin.
Our exploit ships with a Docker target, encrypted and unencrypted PCAPs, Snort and Suricata detection rules, and a YARA rule.
The team developed an exploit for CVE-2026-58138, an unauthenticated remote code execution vulnerability in Conductor, a widely used open-source workflow orchestration platform originally built at Netflix and now maintained by Orkes. The vulnerability was added to VulnCheck KEV on July 27, 2026, after exploitation was reported; it is not yet on CISA KEV. Our Shodan query finds around 29 internet-exposed Conductor instances. Our exploit ships with a Docker target, encrypted and unencrypted PCAPs, and Suricata and Snort detection rules, along with ASM queries.
The team developed an exploit for CVE-2026-1492, a critical unauthenticated privilege escalation in User Registration & Membership, a WordPress registration and membership plugin by WPEverest with 50K+ active installations. It was added to VulnCheck KEV on March 2, 2026; it is not on CISA KEV. VulnCheck Target Intelligence surfaces around 280 internet-exposed hosts running the plugin. Our exploit ships with a Docker target, encrypted and unencrypted PCAPs, and Snort and Suricata detection rules, along with ASM queries.