important2 findings, 17 signals, 1 noted6 min read

A demonstrated zero-click chain on unpatched iOS 16 ended in an invisible WhatsApp clone, while unauthenticated LDAP paths separately yielded FreeIPA administrator and 389 Directory Manager authority.

Forenser associates observed image-processing failures with CVE-2025-43300 and possibly CVE-2025-55177, but the exact trigger and complete CVE composition remain unproved publicly. Red Hat reproduced full administrator compromise twice, including against a stock FreeIPA installation from a zero-access client. The result invalidates the administrative trust root for users and systems governed by an affected FreeIPA domain. Directory Manager is the directory's highest authority, so the sequence collapses authentication and authorization for services relying on the affected directory.

Priority findings2
01
High
Privilege escalation
Confirmed
CVE-2026-76578

An unauthenticated LDAP client can mint a genuine FreeIPA administrator on a stock server.

Anonymous LDAP access to an IPA master or replica is sufficient.

Affects

FreeIPA and Red Hat Identity Management servers, which centrally manage Linux identities, Kerberos credentials, access policy and related services.

What it enables

Unauthenticated FreeIPA administrator-group membership

Reach an IPA master or replica's LDAP service without credentialsUse an anonymous bind to add an OTP-shaped entry with empty owner fields and attacker-chosen Kerberos principal attributesThe 389 Directory Server SELFDN check accepts the empty fields as the anonymous client's own identityFreeIPA's permissive ADD ACI admits the extra principal and group-related attributesAuthenticate as the attacker-controlled principal with genuine FreeIPA administrator-group authority
Why this matters

The path replaces an identity server's administrative trust root from outside the domain.

Detail and 3 sources
Required access

Unauthenticated network reachability to the FreeIPA server's LDAP service on TCP/389 or TCP/636

Affected versions

FreeIPA server releases before 4.13.4 that contain the vulnerable self-managed-token ACI and use an affected 389 Directory Server, Red Hat IdM packages still listed as affected or under investigation on 2026-09-08

Proof of concept

Demonstrated by the researcher

The primitive composes FreeIPA's permissive ADD ACI with 389 Directory Server's treatment of an anonymous empty bind DN as matching empty owner fields.

Red Hat reproduced full compromise twice, including from a zero-access client against a stock installation.

FreeIPA 4.13.4 hardens the vulnerable ACI composition.

Evidence
Red Hat independently reproduced full administrator compromise twice, including on a stock installation from a zero-access clientFreeIPA 4.13.4 documents the vulnerable ACI composition and the shipped hardening
Share this finding
02
High
Research
Confirmed
CVE-2026-18922

An unauthenticated LDAP client can become Directory Manager on 389 Directory Server.

One failed privileged bind followed by an anonymous bind installs the stale privileged identity.

Affects

389 Directory Server, the Linux LDAP identity server used directly and by Red Hat directory products.

What it enables

Unauthenticated Directory Manager authority

Connect to the LDAP service without credentials.Attempt a SASL PLAIN bind as cn=Directory Manager with an incorrect password; the bind fails but leaves the privileged DN in a Cyrus SASL auxiliary property.Complete a SASL ANONYMOUS bind on the same connection.The server installs the stale Directory Manager identity and grants full directory authority.
Why this matters

The two-bind sequence yields the directory's highest authority and compromises the trust root used by relying services.

Detail and 2 sources
Required access

Network reachability to an affected 389 Directory Server over LDAP or LDAPS

Affected versions

389-ds-base 2.9.0 confirmed; the vulnerable logic was unchanged from commit 33c0e0115c03017ba94ee02f144383704de32a25, Affected Red Hat Enterprise Linux 6, 7, 8, 9 and 10 and Red Hat Directory Server 11 and 12 streams identified by Red Hat errata

Proof of concept

Demonstrated by the researcher

The attacker first submits an incorrect password in a SASL PLAIN bind as Directory Manager, leaving the privileged DN in a Cyrus SASL auxiliary property.

A SASL ANONYMOUS bind on the same connection then installs that stale identity.

Pre-fix images remain accepted, and revocation is incomplete despite publication of a fixed upstream version.

Evidence
Red Hat CNA documents the zero-credential bind sequence and resulting Directory Manager identityRed Hat Product Security independently reproduced the result against 389-ds-base 2.9.0Exact fixed upstream version is public
Share this finding
Signals17
important · Edge devices

MikroTrick has moved from public lab code to observed RouterOS takeovers.

Affects

MikroTik RouterOS, the operating system on MikroTik routers, switches and wireless appliances.

CERT Polska confirms successful takeovers since at least September 2, including creation of a highly privileged ops account on exposed routers.

Detail and 4 sources
important · Edge devices

An unauthenticated caller can register a trusted JetBrains Hub service and become superuser.

Affects

JetBrains Hub, a self-hosted identity and access-management server used by JetBrains development products.

The registration surface grants the rogue service control over Hub's identity and authorization system without requiring administrator credentials.

Detail and 4 sources
important · Edge devices

Unauthenticated requests can execute code in the WHMCS server context.

Affects

WHMCS, a web-hosting billing and customer-management application deployed on PHP web servers.

A forged request to an affected public WHMCS application reaches an executable context without credentials and runs with the web-server process's privileges.

Detail and 1 source
important · Zero-click

Samsung says crafted DNG or JPEG data can execute code in a Galaxy image-decoder process.

Affects

Samsung Galaxy mobile devices using Samsung's libimagecodec.quram.so image-decoding library on Android.

The underlying heap overflows affect libimagecodec.quram.so on Android 14 through 17, with Samsung's fix in September Release 1.

Detail and 1 source

We do not know which default application reaches the decoder or whether receipt alone triggers it.

Chain to watch
Deliver a crafted DNG or JPEG through a default applicationDetermine whether receipt or preview invokes libimagecodec.quram.soMap decoder execution into its UID and sandboxThe delivery application, automatic invocation path, UID, and sandbox remain unidentified.
Unverified chainTrace the decoder while delivering files through Samsung Messages, RCS/MMS, email, Quick Share, cloud synchronization, and gallery indexing.
important · Edge devices

An exploited LiteLLM authentication fallback accepts fabricated bearer tokens for configured MCP tools.

Affects

LiteLLM, an AI-model gateway and proxy commonly deployed on Linux servers and in containers.

Failed key validation falls through OAuth2 passthrough to an empty authentication object, allowing the caller to list and invoke tools and connected services behind an exposed Streamable HTTP endpoint.

Detail and 2 sources
important · Physical access

Physical access to a Galaxy phone can expose files with Android system privilege through GalaxyDiagnostics.

Affects

Samsung Galaxy mobile devices running Android 14 through 17 with the GalaxyDiagnostics system component.

Samsung confirms the path traversal and published a September fix, but does not identify the accessible file set or show that the path crosses locked-device credential encryption.

Detail and 1 source
important · Zero-click

A remote Samsung ImsService traversal can create image files with system-server privilege.

Affects

Samsung Galaxy mobile devices running Samsung's IMS telephony service.

Samsung does not establish the cheapest remote position, controlled bytes, overwrite behavior, or a useful writable destination.

Detail and 1 source
Chain to watch
Reach an undisclosed remote ImsService inputEscape the intended image destination with traversalCreate an image file at system-server privilegeThe access position, controllable content, destination set, and composition into execution or persistence remain unresolved.
Unverified chainTrace IMS, MMS, and RCS inputs on a pre-patch device to identify the endpoint, authentication requirements, and writable destinations.
important · Privilege escalation

YouTrack Helpdesk can accept a self-asserted email address as account identity.

Affects

JetBrains YouTrack, a hosted or self-managed issue-tracking and helpdesk system used by development and support teams.

An unauthenticated caller who can reach affected Helpdesk functionality can claim a target user's email address without proving mailbox ownership and receive that account's authority.

Detail and 2 sources
important · Research

Unauthenticated SAP CAP requests can expose multitenancy credentials and alter tenant data.

Affects

SAP Cloud Application Programming Model multitenant applications using the @sap/cds-mtxs Node.js library in cloud deployments.

The path applies to multitenant applications using @sap/cds-mtxs with extensibility enabled, and the disclosed credentials can be used to replace or delete tenant data.

Detail and 1 source

SAP's September material identifies affected release lines and a remediation note.

important · Boot chain

Orbi RBx850 recovery can persist a boot command that runs unsigned firmware.

Affects

Netgear Orbi RBR850 routers and RBS850 satellites sold in RBK852 through RBK855 mesh kits.

The public OpenWrt implementation uses an NMRP-flashed factory image and embedded U-Boot script to replace the stock signed-image boot path persistently.

Detail and 2 sources
important · Research

A low-privileged SAP backend user can make SAP GUI for Java execute commands on an operator's workstation.

Affects

SAP GUI for Java, the cross-platform desktop client used to operate SAP NetWeaver backend systems.

The client fails to enforce its trust policy when manipulated backend content invokes affected GUI functionality, crossing an existing backend foothold into the operator's command context.

Detail and 2 sources
important · Remote code execution

A delegated LDAP administrator can plant a distinguished name that Cockpit later executes as root.

Affects

Red Hat Directory Server deployments that include Cockpit 389 Console, the web administration interface for the LDAP directory server on Linux.

The chain requires a separate privileged operator to view the entry, after which Cockpit embeds the unescaped name in a shell command executed through its superuser channel.

Detail and 1 source
important · Physical access

AMD widened a known optical plaintext-recovery exposure to more 7-Series and Zynq-7000 FPGAs.

Affects

AMD 7-Series and Zynq-7000 FPGAs used as programmable logic in embedded and hardware systems.

The practical demonstration remains limited to an XC7A200T, while AMD says the same partial-reconfiguration path makes additional families susceptible in principle.

Detail and 2 sources

The technique requires backside silicon access and specialized optical equipment.

Chain to watch
Prepare the FPGA for unrestricted backside accessObserve decrypted partial-bitstream transfer during reconfigurationRecover plaintext through optical measurementPractical recovery has not been demonstrated across every newly named family.
Unverified chainReproduce the technique on devices from each added family and measure layout-specific feasibility.
important · Wi-Fi

An unauthenticated LAN client can replace a Tenda AC9 administrator password persistently.

Affects

Tenda AC9, an embedded dual-band Wi-Fi router.

An authentication-exempt prefix exposes fast_setting_wifi_set, which writes the supplied password into sys.userpass and commits it to flash.

Detail and 1 source

The attacker needs LAN or Wi-Fi access to TCP port 8080 but no session or current password.

important · Bluetooth

An authenticated BLE peer can overwrite adjacent BSS memory through Nordic's glucose-monitoring service.

Affects

Nordic Semiconductor nRF Connect SDK, an embedded SDK used to build Bluetooth Low Energy devices.

The RACP handler copies the full ATT value into a 20-byte static buffer, making the overwritten target dependent on the firmware's BSS layout.

Detail and 3 sources

Affected finished products and an exact fixed release remain unidentified.

Chain to watch
Authenticate to a CGMS-enabled device over BLEWrite an oversized value to the Record Access Control PointOverwrite objects adjacent to the 20-byte static bufferThe device-specific consequence depends on the linker-assigned BSS layout.
Unverified chainBuild representative affected firmware, inspect linker maps, and replay oversized RACP writes against concrete adjacent objects.
important · Remote code execution

An unauthenticated Bifrost management API can load attacker-supplied native code under narrow build conditions.

Affects

Bifrost HTTP transport, an open-source gateway for routing requests among AI-model providers, on dynamically linked Linux builds.

With dashboard authentication disabled or unconfigured, a caller can register a custom plugin URL that a dynamically linked, plugin-capable build downloads and passes to Go's plugin loader.

Detail and 4 sources
important · Zero-click

A demonstrated zero-click chain on unpatched iOS 16 can silently clone a WhatsApp session.

Affects

WhatsApp for iOS on iPhones running vulnerable iOS 16 releases.

Forenser demonstrated the result with the current WhatsApp application on iOS versions earlier than 16.7.12 and without victim interaction.

Detail and 4 sources

The researchers associate image-processing failures with CVE-2025-43300 and possibly CVE-2025-55177, but they did not publish the initial artifact or prove the complete composition.

The demonstrated boundary is iOS 16.7.12; revocation of previously exposed session material remains unknown, and affected versions reach end-of-life hardware.

Chain to watch
Attacker remotely targets a WhatsApp account on an iPhone running iOS earlier than 16.7.12.An unpublished zero-click trigger compromises the device at the OS level; Forenser associates the observed image-processing failures with CVE-2025-43300 and possibly CVE-2025-55177.Critical WhatsApp session-handshake material is extracted from the compromised device.A malicious PC client authenticates as the victim without creating a visible Linked Devices entry.The attacker reads recent chats and sends messages that recipients see as coming from the victim.The public demonstration does not reveal the initial delivery artifact or prove that CVE-2025-43300 and CVE-2025-55177 are the complete chain.
Unverified chainObtain Forenser's trigger artifact or technical report, reproduce the attacker-to-device transition, and test session cloning separately across the iOS 16.7.12 boundary.
Also noted1
Wi-Fi
A nearby Wi-Fi attacker can write beyond wpa_supplicant memory on Samsung Galaxy devices.
demoted by the reviewer
SecondarySamsung GalaxyDiagnostics path traversal exposes system-privileged files to a physical attacker
What was checked · 2 quiet
FirmwareQuiet

MikroTrick takeovers are active, GalaxyDiagnostics exposes system-privileged files to physical access, and Orbi recovery can persist unsigned firmware.

MobileQuiet

WhatsApp session cloning was demonstrated; Samsung disclosed decoder execution and GalaxyDiagnostics file access, with remote delivery details incomplete.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 8, 2026