This week, the team developed an exploit for CVE-2026-88771, an unauthenticated command injection that yields root on Citrix NetScaler ADC and Gateway installations. It was exploited in the wild as a zero-day pre-disclosure and added to VulnCheck KEV on September 27, 2026. Exploitation evidence has continued to mount since then, with multiple security firms publishing incident and attack observations. VulnCheck Target Intelligence finds roughly 38,300 internet-facing NetScaler Gateway and NetScaler ADC instances. Our exploit ships with a version scanner, PCAPs, Suricata and Snort rules, a YARA rule, and ASM queries.
The team also developed an exploit for CVE-2026-88772, a critical pre-authentication memory corruption vulnerability that yields root on Citrix NetScaler ADC and NetScaler Gateway. Like CVE-2026-88771, CVE-2026-88772 is a zero-day with ongoing exploitation, including to drop webshells and malware. The vulnerability needs no session, no client certificate, and no credentials of any kind, and it is reachable on the DTLS service that the standard Gateway deployment publishes alongside the TLS listener. VulnCheck Target Intelligence finds roughly 38,300 internet-facing NetScaler instances. Our exploit ships with a version scanner, PCAPs, Suricata and Snort rules, a Sigma rule, a YARA rule, and ASM queries.
To complete this week's Citrix coverage, the team added an exploit for CVE-2026-19490, an authentication bypass in Citrix NetScaler ADC and NetScaler Gateway that takes a single unauthenticated request to exploit. VulnCheck added this CVE to the KEV catalog on September 3, 2026, six days before CISA. VulnCheck Target Intelligence finds roughly 38,300 internet-facing NetScaler instances. Our exploit ships with a version scanner, PCAPs, Suricata and Snort rules, a Sigma rule, a YARA rule, and ASM queries.
The team developed an exploit for CVE-2026-76504, an unauthenticated auth bypass in Cisco Catalyst SD-WAN Manager, providing first to market coverage for this emerging threat that was disclosed as a zero-day on September 30. Target Intelligence counts roughly 1,500 exposed instances. A full write-up on the exploit is available on the VulnCheck blog. Our exploit ships with a PCAP, queries, and Snort, Suricata, and YARA rules.
The team developed an exploit for CVE-2026-35273, an unauthenticated SSRF in Oracle PeopleSoft PeopleTools that enables RCE. The vuln was exploited as a zero-day earlier this year, prompting an out-of-band patch from Oracle. Google attributed exploitation to ShinyHunters and observed attacks as early as May 2026 before it was published and added to KEV lists starting June 11. Exploitation has remained active, with ShadowServer reporting activity as recently as September 30 and Google reporting recent exploitation using a WAF bypass. VulnCheck Target Intelligence identifies roughly 200 internet-facing PeopleSoft instances. Our exploit comes with PCAPs, network signatures, and ASM queries.
The team added an exploit chaining CVE-2026-102489 and CVE-2026-102490 for unauthenticated RCE in Zammad, a widely used open-source help desk and ticketing platform. The vulnerability takes an attacker from no credentials to root on the host. Both CVEs were added to VulnCheck KEV on September 30, 2026 on the back of reported exploitation. A Zammad install holds customer tickets, support mailboxes, and agent credentials, so an unauthenticated foothold that escalates to root exposes all of it. VulnCheck Target Intelligence identifies roughly 4,930 internet-facing Zammad instances. Our exploit ships with a Docker target, PCAPs, Snort and Suricata rules, YARA rules, and ASM queries.
The team developed an exploit for CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin. Roundcube is widely deployed and has a track record as a target for credential theft and email espionage; a Roundcube login page is almost always internet-facing, making it a broad and low-barrier attack surface. VulnCheck added it to our KEV on September 21, 2026 on the back of reported in-the-wild exploitation. VulnCheck Target Intelligence identifies roughly 9,200 internet-facing Roundcube instances. Our exploit ships with a version scanner, a Docker target, PCAPs, Snort and Suricata rules, and ASM queries.
The team developed an exploit for CVE-2026-65660, an unauthenticated RCE vulnerability in Microsoft SharePoint that was added to VulnCheck KEV on September 24, 2026 after reported honeypot exploitation. CISA KEV followed a day later. SharePoint servers hold documents, credentials, and a path into the wider domain, and this vulnerability is reachable pre-auth on a default install. VulnCheck Target Intelligence identifies roughly 1,100 internet-facing SharePoint instances. Our exploit ships with a version scanner, PCAPs, Suricata and Snort rules, a Sigma rule, and ASM queries.
CVE-2026-61500 is an unauthenticated RCE vulnerability in Rejetto HFS (HTTP File Server), which is a recurring exploitation target: CVE-2024-23692 was mass-exploited last year, and this new flaw hits the current 3.x line through a predictable session signing key that an unauthenticated attacker uses to forge an administrator session. It was discovered by Horizon3 with Anthropic's "Mythos" AI model. VulnCheck Canary Intelligence began observing exploitation of CVE-2026-61500 on October 1, 2026, prompting its addition to VulnCheck KEV. VulnCheck Target Intelligence identifies roughly 100 internet-facing HFS instances. Our exploit ships with a version scanner, a Docker target, PCAPs, Suricata and Snort rules, a YARA rule, and ASM queries.
CVE-2026-97359 is a(nother) unauthenticated RCE vulnerability in Rejetto HFS that runs commands as the account owning the HFS process. It reaches the same macro engine that was mass-exploited last year as CVE-2024-23692, this time through a new unauthenticated path; the affected line has no vendor fix. No in-the-wild exploitation has been reported yet. VulnCheck Target Intelligence identifies roughly 100 internet-facing HFS instances. Our exploit ships with PCAPs, Suricata and Snort rules, and ASM queries.
CVE-2026-42608 is an unauthenticated path traversal in Grav CMS that was reportedly exploited to hack and deface the Cl0p ransomware group's data leak server. Through the core FormFlash component, an attacker with no credentials can write a file with attacker-controlled content anywhere under the Grav install, a strong foothold on a live site. VulnCheck added it to VulnCheck KEV on September 25, 2026; it is not on CISA KEV. VulnCheck Target Intelligence identifies roughly 1,445 internet-facing Grav instances. Our exploit ships with a Docker target, PCAPs, Snort and Suricata rules, and ASM queries.
CVE-2026-76570 is an unauthenticated arbitrary SQL read/write in JCTables, a JoomCode data-table component for Joomla, that yields RCE as the web server user. It was found and disclosed by VulnCheck's own Valentin Lobstein and detailed in our disclosure blog. JoomCode has since patched it; no in-the-wild exploitation has been reported. JCTables has no reliable public fingerprint, but it rides on Joomla, one of the most widely deployed CMS platforms. Our exploit ships with a version scanner, a Docker target, PCAPs, Snort and Suricata rules, and a YARA rule.
CVE-2026-88062 is an unauthenticated RCE vulnerability in the OmniRoute AI gateway. We covered it because it is already under active exploitation, including against VulnCheck Canaries. AI gateways are becoming core routing infrastructure for LLM and agent traffic, and an unauthenticated RCE at that layer gives an attacker control over an organization's model access. Our exploit ships with a Docker target, PCAPs, Snort and Suricata rules, and ASM queries.
CVE-2026-72137 is a double-free local privilege escalation in the Linux kernel's xfrm nat_keepalive handling. It needs no credentials and no network position, so it is a reliable escalation primitive on top of any foothold: a compromised service account, a container breakout, or a shell from one of our remote access exploits turns into full root. No in-the-wild exploitation has been reported yet. Our exploit ships as a self-contained Go binary with a check for the affected kernels; as a local escalation with no network footprint, it has no PCAPs, detection rules, or ASM queries.
CVE-2026-5430 is an unauthenticated authentication bypass in WSO2 API Manager (and API Control Plane, Traffic Manager and Universal Gateway) that is reportedly under active exploitation. A JWT algorithm confusion flaw lets an attacker forge an admin token and read the management API with no credentials, disclosing the tenant configuration, every Key Manager configuration (identity-provider issuers, OAuth endpoints and bind service accounts) and the gateway environments. VulnCheck added it to VulnCheck KEV on September 15, 2026, nine days before CISA. VulnCheck Target Intelligence identifies roughly 50 vulnerable internet-facing instances. Our exploit ships with a Docker target, PCAPs, Snort and Suricata rules, a YARA rule, and ASM queries.
CVE-2026-39363 is an unauthenticated file read in the Vite development server, reachable over its Hot Module Reload WebSocket, that lets an attacker pull arbitrary files off the host as the Node process user: .env files, credentials, private keys, anything sitting alongside the codebase. Vite dev servers are routinely exposed beyond loopback (started with --host or server.host), and VulnCheck Target Intelligence finds roughly 11,750 Vite instances already in that state. Our exploit ships with a version scanner, PCAPs, and Suricata and Snort rules.
CVE-2026-39364 is an unauthenticated file disclosure vulnerability in the Vite dev server that bypasses the server.fs.deny filesystem access control and reads files such as .env and TLS private keys as the dev-server process. It was added to VulnCheck KEV on September 11, 2026, following reports of mass scanning for exposed Vite dev servers. Only dev servers explicitly bound to the network with the --host flag or the server.host option are reachable, since the default loopback-only binding is not remotely exposed. Our exploit ships with a version scanner, a Docker target, PCAPs, Suricata and Snort rules, and ASM queries.
CVE-2026-86121 is an unauthenticated RCE vulnerability in Cua's computer-server, the sandbox host behind the Cua computer-use agent framework. We covered it because computer-use and MCP agent tooling is being wired into developer and enterprise workflows faster than it is hardened, and an unauthenticated code execution endpoint on the sandbox host is a useful foothold. No in-the-wild exploitation has been reported yet. Our exploit ships with a Docker target, PCAPs, and Snort and Suricata rules.
CVE-2026-61600 is an unauthenticated RCE vulnerability in Chamilo. An unauthenticated attacker runs code as the web server user, so a single exposed portal puts student and staff data and the server behind it at risk. No in-the-wild exploitation has been reported yet. VulnCheck Target Intelligence identifies roughly 500 internet-facing Chamilo instances. Our exploit ships with a Docker target, PCAPs, Snort and Suricata rules, and ASM queries.
CVE-2026-45140 is an unauthenticated RCE vulnerability in the 2.0.x line of Chamilo. It allows an unauthenticated attacker to write a file into the web root and run code as the web server user. No in-the-wild exploitation has been reported yet. Our exploit ships with a Docker target, PCAPs, Suricata and Snort rules, a YARA rule, and ASM queries.
CVE-2026-103040 and CVE-2026-103041 are both unauthenticated RCE vulns that VulnCheck's CNA assigned in LightLLM, a high-performance LLM inference and serving framework. We covered them because LightLLM exposes internal services with no authentication that let anyone who can reach them run code as the service account, on the kind of GPU inference host that holds models, data, and credentials. The team shipped an exploit, a Docker target, a PCAP, and Suricata and Snort rules.
CVE-2026-100382 is an unauthenticated OS command injection in the MediaWiki ExternalData extension that runs code as the web server user. MediaWiki runs tens of thousands of public wikis, so a single exposed instance hands an attacker the server. No exploitation has been reported yet. VulnCheck Target Intelligence identifies roughly 2,450 internet-facing MediaWiki instances. Our exploit ships with a Docker target, PCAPs, and Suricata and Snort rules.
CVE-2026-49869 is a critical authentication bypass that yields unauthenticated RCE in Kestra, a widely self-hosted orchestration platform for data and AI pipelines that is frequently exposed to the internet as a workflow UI and API. It is under active exploitation, per Microsoft, and was added to VulnCheck KEV on August 26, 2026, a week ahead of CISA. VulnCheck Target Intelligence sees roughly 230 internet-facing Kestra instances. Our exploit ships with a Docker target, a PCAP, and Snort and Suricata rules.
CVE-2026-27180 is a critical unauthenticated RCE vulnerability in MajorDoMo, an open-source home and building automation platform. It was discovered and disclosed by VulnCheck's own Valentin Lobstein. An unauthenticated attacker can gain code execution as the web server user, turning the product's update mechanism into a supply chain RCE with no creds and two GET requests. No in-the-wild exploitation has been reported yet. Our exploit ships with a Docker target, PCAPs, and Snort and Suricata rules.
CVE-2026-55559 is an unauthenticated RCE vulnerability in Yamcs, an open-source mission control framework used for spacecraft and ground-segment operations. We covered it because deployments that run without a security.yaml expose instance creation through a guest superuser, so an attacker with no credentials executes commands as the Yamcs service account on a host driving live mission operations. No in-the-wild exploitation has been reported.
CVE-2025-31700 is an unauthenticated stack buffer overflow in the ONVIF handler of Dahua network cameras and recorders. Dahua's advisory leans on ASLR to argue the realistic outcome is just a crash, but our team built a working unauthenticated reverse shell that runs as root against a specific firmware build, with other builds likely exploitable. Dahua cameras are consumer and prosumer IoT exposed at massive scale, which is why they are a perennial botnet target. Our Shodan query finds roughly 6,500 internet-exposed Dahua instances. Our exploit ships with a PCAP, Snort and Suricata rules, and ASM queries.