important2 findings, 16 signals, 1 noted5 min read

Branch Target Reuse defeats deployed Spectre-v2 isolation on affected Intel Linux hosts, while one pre-authentication RouterOS request can reach root.

One invalidates a widely deployed cross-privilege defense; the other makes web-management reachability sufficient for root execution, although CISA's records conflict on the first fixed RouterOS release.

Priority findings2
01
High
Research — privilege
Confirmed
CVE-2026-64507

Branch Target Reuse lets an unprivileged Linux process read arbitrary host memory despite deployed Spectre-v2 defenses.

Public artifacts demonstrate the cross-privilege break end to end.

Affects

The Linux kernel cBPF JIT on x86 systems, demonstrated on stock Ubuntu 24.04.

What it enables

Cross-privilege disclosure of arbitrary host memory from an unprivileged process

Run unprivileged native code and install cBPF filters through seccomp or Linux socket filtering.→↓Train the cBPF dispatcher’s indirect branch, free the JIT allocation and force controlled reuse of its address.→↓Reuse the stale branch-predictor target to enter newly generated code at an obsolete or misaligned offset.→↓Reach a speculative disclosure gadget, recover KASLR state and follow kernel aliases into arbitrary process memory.→↓Recover the root password hash from a live su process in an average of three to five minutes on the demonstrated Intel systems.
Why this matters

Deployed Spectre-v2 defenses no longer close this path: public artifacts demonstrate arbitrary host-memory recovery from an unprivileged process.

Detail, proof-of-concept code and 5 sources
Required access

Unprivileged native code execution on an affected Intel Linux host with the cBPF JIT available

Affected versions

Linux kernel 5.18 and later before the applicable stable backport, Demonstrated on Ubuntu 24.04 kernel 6.14.0-27, SpiderMonkey and GraalVM expose the underlying reuse primitive, but the paper does not demonstrate equivalent end-to-end disclosure there

Proof of concept

Public exploit code →

An unprivileged process that can install cBPF filters trains the dispatcher, frees its JIT allocation and forces controlled address reuse; a stale indirect-branch prediction then enters newly generated code at an obsolete or misaligned offset.

The demonstrated chain recovers KASLR state, follows kernel aliases into arbitrary process memory and extracts a live su process's root password hash in an average of three to five minutes on the tested systems.

The upstream Linux mitigation issues an indirect branch prediction barrier when a JIT allocation is reused.

Evidence
The ACM CCS paper demonstrates two end-to-end cBPF exploits and arbitrary process-data recovery on stock Ubuntu.The public VUSec repository contains the microarchitectural experiments, attack-surface analysis and Linux end-to-end exploit artifacts.The upstream Linux CVE record identifies affected ranges, fixes and the IBPB-on-JIT-reuse mitigation.
Share this finding
02
High
Firmware — edge
Confirmed
CVE-2026-84411

One pre-authentication HTTP request can execute code as root on MikroTik RouterOS.

Web-management reachability is the only remote prerequisite established in the public record.

Affects

MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.

What it enables

Unauthenticated arbitrary code execution as root

Reach the RouterOS web-management service.→↓Send one crafted HTTP request body before authentication.→↓Trigger the request-body integer underflow.→↓Execute attacker-controlled code as root.
Why this matters

RouterOS takes the second slot over Firefox because its chain is established from one unauthenticated request to root, while Mozilla's advisory does not establish direct web reachability or host-operating-system execution for any listed flaw.

Detail and 2 sources
Required access

Network reachability to the RouterOS web-management service

Affected versions

RouterOS versions earlier than 7.24, according to CISA's affected-product boundary

A crafted request body reaches an integer underflow before authentication and turns it into attacker-controlled execution as root.

CISA's remediation text says 7.23 or later, while its product-status data marks versions earlier than 7.24 affected; the first fixed release is therefore not settled in the public record.

Evidence
CISA's September 29 CSAF record says the flaw is reachable before authentication and a single crafted request can achieve arbitrary code execution as root.CISA's remediation paragraph says 7.23 or later while its product-status data marks versions earlier than 7.24 affected, so the exact first fixed release is withheld.No public exploit or reported exploitation was found in the completed searches.
Share this finding
Signals16
important · Privilege — browser

Firefox 157 fixes twelve newly disclosed sandbox-escape or privilege-boundary failures.

Affects

Firefox, a cross-platform web browser.

Mozilla labels the flaws as sandbox escapes or privilege escalations, but its public advisory does not establish direct web delivery or host-operating-system execution for any individual CVE.

Detail and 1 source
important · Edge — virtualization

Public exploit code turns vCenter's unauthenticated syslog file write into repeatable root command execution.

Affects

VMware vCenter Server, the virtualization-management appliance used by vSphere, VMware Cloud Foundation and related platforms.

A traversal-bearing RFC 5424 APP-NAME makes the dynamic rsyslog template write a root-owned cron entry outside its intended directory.

Detail and 5 sources
important · Edge — identity

An empty JWS signature array makes Authlib return attacker-controlled payloads as verified.

Affects

Authlib, a Python OAuth, OpenID Connect and JOSE library used by web applications and microservices.

Authlib initializes verification as successful and performs zero signature checks, so a consumer that trusts the result can accept forged identity, authorization, inter-service or configuration claims.

Detail and 2 sources
important · Edge — remote access

An authenticated TeamViewer remote party can override features the target explicitly denied.

Affects

TeamViewer Full Client and Host, cross-platform remote-support clients on Windows, Linux and macOS.

Attacker-controlled access parameters override the target's configured feature permissions during session establishment.

Detail and 3 sources

TeamViewer says code execution can follow, but it does not identify the affected feature, resulting process or execution context.

important · Research — edge

New public exploit code turns nginx's capture-clobbering bug into pre-authentication code execution with ASLR enabled.

Affects

nginx Open Source and NGINX Plus web, reverse-proxy and stream servers on affected configurations.

The attack applies only when a configuration evaluates a regex capture before an attacker-influenced regex map variable in the same two-pass buffer; we do not know how common that pattern is.

Detail and 4 sources
important · Mobile — firmware

A public Viidure Android APK exposes credentials that can modify or delete shared firmware and application binaries.

Affects

Viidure Dashcam Android Application, the Android companion app and cloud-storage client for Viidure dashcams

Anyone with the APK and internet access can recover permanent plaintext storage credentials and alter the shared binary store without a Viidure account.

Detail and 2 sources
important · Mobile

A permissionless Android app can silently redirect OsmAnd requests and disclose a user's locations.

Affects

OsmAnd for Android, a navigation and offline-mapping application

Crafted intent extras silently replace map-tile or routing endpoints, sending viewed coordinates and route origins and destinations to an attacker-controlled service.

Detail and 2 sources

The current upstream manifest still exports the activity, but exact affected and fixed releases remain unknown.

important · Firmware — industrial

Unauthenticated requests can upload arbitrary firmware to end-of-life Hitachi Energy RTU500 controllers.

Affects

Hitachi Energy RTU500 Series CMU firmware, used by substation remote terminal units.

Network reachability to the update endpoint is enough to submit attacker-selected firmware content.

Detail and 3 sources
important · Firmware — RTOS

A protected ThreadX user module can make the RTOS kernel execute its callback with kernel privilege.

Affects

Eclipse ThreadX, an embedded real-time operating system used in microcontrollers and connected devices.

On builds with event tracing enabled, a user module can register its own trace-buffer-full callback and make privileged kernel code invoke it when the buffer wraps.

Detail and 2 sources
important · Boot chain — physical

A fastboot command can turn a locked Poco M7 Plus into a temporarily rooted device.

Affects

Poco M7 Plus 5G smartphones running Xiaomi HyperOS on the Qualcomm SM6375 platform.

The command injects androidboot.selinux=permissive through an unsanitized ABL parameter while the bootloader remains locked.

Detail and 6 sources
important · Privilege — FreeBSD

Three FreeBSD descriptor-handling flaws let a jailed process escape its filesystem root.

Affects

FreeBSD jails, operating-system-level isolation on FreeBSD hosts.

A jailed process must first receive a directory descriptor from another jail; the variants then clear, lose or bypass FD_RESOLVE_BENEATH through fdescfs, renameat handling or SCM_RIGHTS passing.

Detail and 1 source
important · Boot chain — firmware

Fragmented IP traffic can redirect execution inside U-Boot before the operating system starts.

Affects

Das U-Boot, an embedded bootloader used by network appliances and other devices, when built with CONFIG_IP_DEFRAG=y.

Exposure requires adjacent traffic during use of a CONFIG_IP_DEFRAG-enabled U-Boot network stack.

Detail and 2 sources

A duplicated final fragment reaches stale reassembly state, turns payload bytes into hole metadata and drives out-of-bounds writes that redirect control flow into attacker-supplied pkt_buff data.

important · Wi-Fi — edge

An adjacent DHCP packet can execute code in a WatchGuard Firebox fingerprinting daemon.

Affects

WatchGuard Firebox network-security appliances running Fireware OS, including appliances serving adjacent wired or wireless networks.

A crafted unauthenticated DHCP packet triggers a stack overflow in Fireware OS fingerd, yielding code execution in the daemon context.

Detail and 2 sources
important · RCE — ML

A malicious model configuration executes Python as the Unsloth training or inference user.

Affects

Unsloth and Unsloth Zoo, Python libraries used to load, fine-tune and serve machine-learning models.

When a workflow selects an attacker-controlled model, a newline-bearing model_type survives normalization, enters generated Python source and reaches exec().

Detail and 4 sources
important · Edge — VPN

A malicious BOVPN over TLS server can execute commands as root on a connecting Firebox.

Affects

WatchGuard Firebox network-security appliances running Fireware OS and configured as BOVPN over TLS clients.

The Firebox must already be configured to connect to the attacker-controlled server; improper certificate validation and code injection then turn server-supplied configuration into root commands.

Detail and 2 sources
important · Privilege — Linux

A low-privileged Linux user can plant input that a PFU scanner workflow turns into commands or an arbitrary-file overwrite.

Affects

PFU Image Scanner Driver for Linux, software supporting PFU fi Series and SP Series document scanners on Linux

The path requires an affected scanner driver, local access and user interaction with the vulnerable workflow.

Detail and 1 source

The public record does not identify the workflow, the interacting user's role or whether either primitive reaches root.

Also noted1
Research — DTLS
An unauthenticated DTLS peer can make OpenSSL retransmit process-heap contents as plaintext handshake data.
every source is a publisher ruled unable to originate; not published as a finding
SecondaryOpenSSL DTLS retransmission can disclose process heap to an unauthenticated peer
What was checked · 3 quiet
Boot chain & TPMQuiet

U-Boot fragment reassembly now has an adjacent-network control-flow chain; Poco added a device-specific locked-bootloader root route with a preinstalled-manager prerequisite.

BluetoothQuiet

No recent BlueZ, NimBLE, Linux or Chrome item established a new radio-reachable attacker capability; the ESP-IDF primitives remain September 3 disclosures without a newer widening event.

Physical accessQuiet

Poco's USB route reaches temporary root only with a compatible manager already installed; PFU added local command and file-overwrite primitives whose execution identity remains unclear.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026