Jenkins roll up, LibreNMS, Pi-Hole, Mediawiki, and many more!

Happy Friday! This week the team provided coverage for more than 25 CVEs. For full details, please see the Initial Access API. Below are some of the highlights.

Jenkins Remote Code Execution: CVE-2026-84645, CVE-2026-92122, CVE-2026-92127

This week the team added exploits for three Jenkins remote code execution vulnerabilities. CVE-2026-84645 is an XStream configuration deserialization flaw that leads to RCE on the controller. CVE-2026-92122 and CVE-2026-92127 are both Script Security Plugin sandbox escapes: the first is a method-check bypass in the SandboxInterceptor, the second auto-approves classpath entries, and each lets a user who can submit a Groovy (Pipeline) script execute arbitrary code outside the sandbox. VulnCheck Target Intelligence identifies roughly 30,000 internet-facing Jenkins instances vulnerable to these issues. Our exploits ship with version scanners, Docker targets, PCAPs, Suricata and Snort rules, and ASM queries.

CVE-2026-33765: Pi-hole Admin Web Interface Unauthenticated OS Command Injection RCE

The team developed an exploit for CVE-2026-33765, an unauthenticated OS command injection in the Pi-hole admin web interface that yields a shell as the web server user. VulnCheck Target Intelligence identifies roughly 7000 internet-facing Pi-hole instances. Our exploit ships with a Docker target, PCAPs, Suricata and Snort rules, and ASM queries.

CVE-2026-6204: LibreNMS Unauthenticated SNMP RCE via Injected OID Polling

The team developed an exploit for CVE-2026-6204, an unauthenticated RCE in LibreNMS reachable through injected OID data during SNMP polling. An attacker who can return attacker-controlled values for the OIDs LibreNMS polls injects into the handling path and executes commands as the service account. LibreNMS is a widely self-hosted network monitoring platform that sits central to the network with broad reach into the devices it polls, so code execution there is a strong pivot point. VulnCheck Target Intelligence identifies roughly 3,000 internet-facing LibreNMS instances. Our exploit ships with version scanners, Docker target, PCAPs, Suricata and Snort rules, ASM queries.

CVE-2026-8857: MediaWiki EasyTimeline Perl Script OS Command Injection RCE

The team developed an exploit for CVE-2026-8857, an OS command injection in the MediaWiki EasyTimeline extension that runs commands as the web server user. VulnCheck Target Intelligence identifies approximately 1,000 MediaWiki instances vulnerable to this CVE. Our exploit ships with version scanner, Docker target, PCAPs, Suricata and Snort rules, and ASM queries.