important2 findings, 17 signals5 min read

Public NetScaler exploit code reaches root, and attackers are using FortiMail’s unauthenticated file-write path before the effective fix ships.

For the appliances, access is unauthenticated reachability to exposed DTLS or web-management services.

Priority findings2
01
High
Edge
Confirmed
CVE-2026-88772

Public exploit code turns NetScaler’s pre-authentication DTLS overflow into root-level execution.

A network caller needs only reachability to a DTLS-enabled Gateway VIP.

Affects

Citrix NetScaler ADC and NetScaler Gateway, customer-managed application-delivery and remote-access appliances.

What it enables

Unauthenticated root-level code execution on a VPN gateway

Unauthenticated caller completes the DTLS cookie exchange→↓Attacker sends 120 crafted DTLS records whose fragment lengths understate retained data→↓NSPPE reassembles roughly 174 KB into a smaller scratch buffer→↓Forged objects redirect control flow through a ROP chain→↓Shellcode executes with root-level appliance privileges
Why this matters

Version-specific public code converts a reported memory-corruption condition into a reusable unauthenticated root-execution path.

Detail, proof-of-concept code and 5 sources
Required access

Network reachability to a DTLS-enabled NetScaler virtual server, normally UDP on the Gateway VIP

Affected versions

NetScaler ADC and Gateway 14.1 before 14.1-73.37, NetScaler ADC and Gateway 13.1 before 13.1-64.23, NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS, NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.279

Proof of concept

Public exploit code →

An unauthenticated caller can complete the DTLS cookie exchange before sending the malicious fragments.

The exploit sends 120 records whose understated fragment lengths make reassembly overflow a smaller scratch buffer with roughly 174 KB of retained data.

Forged objects redirect control flow through a ROP chain and execute shellcode as root; crafted DTLS traffic was also tied to pre-disclosure web-shell activity.

Citrix has shipped a patch, but pre-fix appliance images remain accepted.

Evidence
Citrix confirms exploitation and the DTLS memory-overflow-to-RCE primitiveUnit 42 ties crafted DTLS traffic to pre-disclosure web-shell activitywatchTowr published version-specific code that builds a control-flow hijack and shellcode payload
Share this finding
02
High
Edge
Provisional
CVE-2026-104286

Attackers are exploiting an unauthenticated FortiMail path before the effective fix ships.

The public management interface yields arbitrary file write and command execution.

Affects

Fortinet FortiMail, a physical, virtual or cloud-deployed secure email gateway appliance.

What it enables

Unauthenticated arbitrary file write and command execution on a FortiMail appliance

An unauthenticated attacker reaches an affected FortiMail HTTP or HTTPS GUI.→↓A crafted request exploits path traversal and NULL-byte handling to escape the intended directory.→↓The attacker writes a file to the underlying appliance filesystem.→↓The written file is used to execute unauthorized commands in the FortiMail system context.
Why this matters

Observed exploitation and the absence of a shipped effective fix turn exposed management interfaces into an immediate containment problem.

Detail and 4 sources
Required access

Network reachability to the affected FortiMail HTTP or HTTPS GUI

Affected versions

FortiMail 8.0.0–8.0.1, FortiMail 7.6.0–7.6.6, FortiMail 7.4.0–7.4.8, FortiMail 7.2.0–7.2.9

An unauthenticated caller can reach the path through an affected FortiMail HTTP or HTTPS management interface.

Path traversal and NULL-byte handling let that caller write attacker-chosen files to the appliance filesystem.

The written file can then be used to execute unauthorized commands in the FortiMail system context.

Exploitation is occurring while the effective correction remains announced rather than shipped, and pre-fix images remain accepted.

Evidence
Fortinet's exploitation statement, primitive and workaround are independently relayed by Canadian, French and Italian government security authorities.The live Fortinet advisory was directly readable.
Share this finding
Signals17
important · Physical — macOS

An approved USB hub silently authorizes a composite device that can run commands and export credentials from an unlocked Mac.

Affects

macOS on Apple-silicon Macs using an approved USB hub, dock, or multi-port adapter

The demonstrated path requires brief physical access to a free port on a previously approved hub and an unlocked Apple-silicon Mac.

Detail and 4 sources

The composite device inherited approval, injected Terminal commands and copied credentials to its flash in about 24 seconds.

With the Mac locked and Lockdown Mode enabled, the interfaces still enumerated, but locked-state execution was not demonstrated.

Chain to watch
Attach a composite HID and CDC-ACM device behind a previously approved hub→↓Confirm that both interfaces enumerate while the Mac is locked under Lockdown Mode→↓Test whether either accepted interface can produce execution or data access without unlocking→↓Whether locked-state interface enumeration can become command execution or data access without an unlock.
Unverified chainRetest representative Apple-silicon Macs and common docks with the screen locked, focusing on non-HID consumers of the accepted serial interface.

Physical placement and an unlocked session keep the demonstrated execution path below today’s remote leads.

important · Zero-click

Any web page or embedded iframe can silently execute native code through a vulnerable Thales SConnect installation.

Affects

Thales SConnect, browser-extension middleware and a Windows native host used with eIDs, SWIFT 3SKey and other hardware signing tokens.

The path applies to Windows browsers with the vulnerable SConnect extension and native host installed.

Detail and 4 sources

Heap spraying after a failed RSA operation lets attacker content forge origin and package signatures, causing SConnect to load and invoke an attacker DLL.

The current Chrome Web Store listing shows the remediated 2.16.1.2 release.

The installed-helper requirement narrows the population, and a remediated release is available.

important · Mobile

A permissionless Android app can steal Wikipedia session cookies and authenticated account data.

Affects

Wikipedia for Android, Wikimedia's encyclopedia client running on Android phones and tablets.

An ordinary Android app can target a device with an authenticated Wikipedia session without requesting a privileged permission.

Detail and 1 source

Intent redirection reaches an internal WebView whose cookie proxy exposes CentralAuth cookies and authenticated API responses.

Public proof-of-concept application code demonstrates cookie capture and authenticated API access.

The material held here does not identify the production releases containing the correction.

important · Firmware

A newly shipped working exploit turns Dahua’s unauthenticated ONVIF overflow into a root shell.

Affects

Dahua IPC and SD-series embedded surveillance cameras and recorders running affected firmware builds.

The attacker needs reachability to the camera’s ONVIF HTTP handler, normally from the LAN but sometimes through port forwarding or UPnP.

Detail and 3 sources

A crafted Host header overwrites control data, and a ROP chain invokes attacker-supplied commands.

A patch exists, but the exact target build used by the new exploit is not established in the material held here.

important · Privilege

Unauthenticated network callers can impersonate charging stations connected to Monta’s cloud platform.

Affects

Monta's hosted electric-vehicle charging platform and charging stations connected to it through WebSockets.

The Internet-facing station WebSocket service accepts connections without an account or user interaction.

Detail and 2 sources

An accepted caller can act in a charging station’s authority context, access station data and perform unauthorized actions.

No complete shipped fix or demonstrated exploit appears in the held evidence.

important · Mobile

Google Play-distributed Joker variants can turn infected Android phones into proxy exit nodes.

Affects

Android.Joker, a family of trojanized Android applications distributed through Google Play and other app channels.

The victim must install and run a trojanized Android application.

Detail and 1 source

The newly reported module relays third-party traffic through the handset, giving its operator the victim’s mobile network identity as an exit point.

The capability change is the addition of proxy egress to variants that were distributed through Google Play.

important · RCE

Any authenticated UTMStack user can send operating-system commands to every connected monitoring agent.

Affects

UTMStack, a SIEM and endpoint-monitoring platform whose server dispatches commands to agents on managed Windows and Linux systems.

The attacker needs a valid UTMStack account of any role and access to the incident-command channel.

Detail and 6 sources
important · Edge

One low-privilege Dell CSM custom resource can compromise every Kubernetes node as root.

Affects

Dell Container Storage Modules, Kubernetes control software that connects clusters to Dell storage systems.

The attacker needs a Kubernetes identity permitted to submit a ContainerStorageModule custom resource.

Detail and 1 source

The privileged operator reconciles attacker-controlled resource data without preserving the caller’s privilege boundary, reaching root across all cluster nodes.

Dell has published a remediated CSM release, while pre-fix releases remain available and unrevoked.

The reach is cluster-wide, but only deployments delegating this uncommon resource permission expose the path.

important · Research

Two exploited Zammad flaws take an unauthenticated helpdesk caller to root.

Affects

Zammad, a self-hosted customer-support and ticketing platform commonly deployed on Linux.

The chain begins with unauthenticated Internet reachability to an affected self-hosted Zammad instance.

Detail and 4 sources

Session hijacking reaches code execution as the zammad service user, and a second flaw elevates that user to root.

DIVD reproduced both stages and observed the complete chain during its own compromise.

The available remediation is partial, leaving one stage of the observed root chain unresolved.

important · Firmware

An unauthenticated adjacent-network request can execute commands as root across Digi’s DAL OS appliance portfolio.

Affects

Digi Accelerated Linux, the embedded operating system used across Digi cellular routers, gateways, device servers, and XBee gateway products.

The attacker needs adjacent-network reachability to an enabled DAL OS web-administration interface.

Detail and 3 sources

A crafted unauthenticated HTTP POST reaches an operating-system command context and executes commands as root.

The held material establishes neither a shipped correction nor a public execution demonstration.

important · Wi-Fi

A same-LAN attacker can turn replayed Tapo onboarding data into command execution on C120 and C200 cameras.

Affects

TP-Link Tapo C120 and C200, Wi-Fi-connected home security cameras running embedded firmware.

The chain applies to Tapo C120 V1 and C200 V5 cameras reachable from the same local network.

Detail and 2 sources

Replayed login-challenge data yields an administrative session that can enable a privileged service and reach command execution through unsanitized MacTool input.

The chain is model-specific and same-LAN only; TP-Link published corrected firmware, but that fix was not read for this brief.

important · RCE

A normal GitLab Duo user can escape custom-flow templates and execute commands on a self-hosted AI Gateway.

Affects

GitLab Self-Hosted AI Gateway, the service that brokers GitLab Duo model and agent requests in self-managed installations.

The attacker needs a valid GitLab account with Duo Agent Platform access in a deployment using a self-hosted AI Gateway.

Detail and 2 sources

Crafted custom-flow configuration escapes the prompt-template sandbox and executes operating-system commands in the gateway’s service context.

The affected deployment intersection is narrow; GitLab published fixed releases, but the fix was not read for this brief.

important · Boot chain

A crafted RLE8 splash image can write outside U-Boot’s framebuffer before the next boot stage is authenticated.

Affects

U-Boot, the bootloader used by many embedded Linux and Android devices

The attacker must place a crafted image in a configured splash-screen or PXE-menu source.

Detail and 3 sources

Repeated EOL or DELTA operations desynchronize the cursor so later pixel runs write into adjacent bootloader memory.

No public work has yet shown a verified-boot bypass or control-flow hijacking on a representative device.

Chain to watch
Place a crafted RLE8 image in a configured U-Boot splash or PXE source→↓Desynchronize the framebuffer cursor with repeated EOL or DELTA operations→↓Direct later pixel runs into adjacent bootloader memory→↓Demonstrate corruption of verification state or program control flow→↓Reliable corruption of a security-relevant object or instruction pointer on a representative device.
Unverified chainBuild a reproducer, map framebuffer-adjacent objects on representative boards, and test whether the controlled writes alter verified-boot decisions or program control flow.

Upstream published a correction, but the fix was not read for this brief.

important · Wi-Fi

An unauthenticated LAN packet can exploit a stack overflow for code execution on a Deco M9 Plus during setup.

Affects

TP-Link Deco M9 Plus V2, an embedded whole-home mesh Wi-Fi router.

The attacker needs adjacent-network packet delivery to a Deco M9 Plus V2 while it is in its setup phase.

Detail and 2 sources

Attacker-controlled TDDPv2 subtype 0x91 data overflows a fixed-size stack buffer and permits code execution.

The exposure is limited to one older hardware revision during setup; TP-Link published corrected firmware, but the fix was not read for this brief.

important · Physical

Restoring severed UART traces on a Kasa EC70 or EC71 exposes a root shell at boot.

Affects

TP-Link Kasa EC70 and EC71, embedded Wi-Fi home security cameras.

The path requires physical possession, disassembly, restoration of the debug traces and interaction with the boot process.

Detail and 1 source

The production debug interface remains logically enabled and the bootloader remains unlocked despite the severed traces.

An attacker can interrupt boot, change boot parameters and obtain an unauthenticated root shell.

This defeats invasive-tamper resistance rather than a remote boundary; TP-Link published fixed firmware, but the fix was not read for this brief.

important · Browser

A crafted WebGL page can execute code outside Chrome’s sandbox.

Affects

Google Chrome desktop and Android browsers processing attacker-controlled WebGL content.

The victim need only load attacker-controlled HTML in an affected Chrome build.

Detail and 4 sources

The WebGL path performs an out-of-bounds write that permits arbitrary code execution outside the browser sandbox.

Chrome shipped corrected desktop builds 154.0.8037.97 and 154.0.8037.98, but the available evidence does not establish whether every route back to a pre-fix build is closed.

important · Mobile

A crafted page can execute code outside Chrome’s sandbox on Android.

Affects

Google Chrome for Android, the mobile web browser using ANGLE for graphics translation.

The user must load attacker-controlled HTML in an affected Chrome for Android build.

Detail and 2 sources

The page reaches ANGLE, triggers a heap buffer overflow and permits execution outside Chrome’s sandbox.

Also noted0

No additional findings today.

What was checked · 1 quiet
BluetoothQuiet

No reviewed change established a new Bluetooth capability; the useful movement was boundary and release evidence for already-known fixes.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026