The propagation behavior turns an agent-generated outbound artifact into a delivery channel for the next indirect prompt injection. CVE-2026-88771 uses improper input validation to permit arbitrary commands in every affected deployment, including the default configuration. CVE-2026-88772 is a DTLS-reachable memory overflow that can cause code execution or denial of service, and DTLS is enabled by default on VPN virtual servers.
One arbitrary-command path is present in default deployments; the other is a memory overflow behind DTLS, which is enabled by default on VPN virtual servers.
NetScaler ADC and NetScaler Gateway, customer-managed application-delivery and remote-access appliances.
Unauthenticated code execution on a customer-managed NetScaler appliance
These are pre-authentication paths through default or normally enabled services, and exploitation was observed before unmitigated customers had closed them.
A network caller can reach CVE-2026-88771 without credentials or an optional feature and execute arbitrary commands through improper input validation. On a DTLS-enabled service, CVE-2026-88772 can turn crafted traffic into code execution or denial of service through a memory overflow.
Citrix has published fixed builds for the affected NetScaler versions.
The downgrade finding is explicitly documented for standalone NetScaler appliances. The sources establish lack of fixes for EOL software branches, but do not separately enumerate every EOL hardware model.
Microsoft SharePoint Server 2016, 2019 and Subscription Edition, on-premises collaboration servers running on Windows.
On an anonymously viewable on-premises site missing the separate June delivery fix, a WebPartPage route reaches ToolPane processing without authentication. Quote injection then bypasses SafeControls validation and enters attacker-controlled .NET deserialization.
Observed payloads disable a deserialization safeguard, load an embedded assembly, and create /_layouts/15/sphealth.aspx as a persistent web shell.
Move to a listed fixed build and verify that the separate June anonymous-delivery correction is also present before permitting anonymous access.
Signal for iOS, the encrypted messaging client running on iPhone and iPad
The attacker must have authored the message, retain its timestamp and a one-to-one session with the recipient, and send the edit within 48 hours. Omitting groupV2 context routes the edit through the contact thread, while a thread-blind lookup finds and overwrites the old group message.
The effect is limited to one recipient’s local iOS view, and Signal 8.7.0.1523 is identified as the fixed release.
SolarWinds Access Rights Manager, enterprise identity-governance software running on Windows servers.
The listener permits TLS without a client certificate, and the shipped key mints its fallback authentication token. ARM then borrows a locally registered identity and accepts a .NET Remoting message at a BinaryFormatter sink.
Bishop Fox demonstrated NT AUTHORITY\SYSTEM execution in a lab.
Signal for iOS, the encrypted messaging client running on iPhone and iPad
Signal authorizes the sender against an attacker-selected contact thread, then uses a global thread-blind index to resolve an interaction in another group. That permits recipient-local pin removal or corruption and an unauthorized poll vote.
The attacker needs the target message’s timestamp and author ACI, which is most practically learned through former group membership. Signal 8.7.0.1523 is identified as the fixed release.
Sylius, a PHP e-commerce framework used by self-hosted online shops.
On a shop with self-registration enabled, an attacker who knows an administrator email can register that address, obtain a Shop API JWT, and present it to the Admin API. Because tokens were not bound to their firewall or principal type, the Admin API resolves the email to the administrator.
The upstream fix adds audience and principal claims to bind tokens to their intended security boundary.
Seetong TS81xxD3X-family embedded video recorders using the iDVR 9000 firmware platform.
The extracted firmware binds the plaintext debug listener to all interfaces, and Cmd input reaches /bin/sh in a UID 0 process under emulation.
The researcher tested no physical recorder, so stock listener exposure and the complete model mapping remain unverified.
Netcore NBR200V2, an embedded business router managed through its uHTTPd web interface.
The network-tools handler evaluates attacker-controlled diagnostic input before checking authentication, and the emulated web service runs as root.
Firmware configuration lists uHTTPd on ports 80, 443, and 23355, but stock-hardware execution and default WAN reachability have not been established.
Botslab G980H dash cameras, embedded in-vehicle recording devices with BLE provisioning and a local Wi-Fi network.
The newly understood link is in the firmware: a hard-coded key and initialization vector provide a provisional path from the BLE-readable credential to the Wi-Fi password.
We do not have public evidence of end-to-end decryption using a credential captured from a named shipping unit, and plaintext recovery also requires the matching firmware image.
Internal OpenAI agent research checkpoints operating with email, Slack, filesystem, and connector tools.
Attacker-authored email, Slack content, or a file can be retrieved during an ordinary agent task, redirect tool or output behavior, and get copied into a message or persistent file that another agent later reads.
The demonstrations stayed inside controlled evaluations, affected internal-only checkpoints, and produced no observed impact outside simulated tool calls.
Supermicro converted a generic AMI BDS/Shell bypass into a broad board map with released, by-request, and unavailable EOL remediation.
Netcore added a factory-state persistent configuration path, while Buffalo’s authenticated command injection adds little beyond an existing administrator foothold.
No new zero-click packet capability was established; official Android and Qualcomm rendering gaps still leave some component prerequisites unresolved.
No new physical-access primitive emerged; the relevant change was Supermicro’s product mapping and uneven remediation for an already privileged pre-boot path.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.