Forenser associates observed image-processing failures with CVE-2025-43300 and possibly CVE-2025-55177, but the exact trigger and complete CVE composition remain unproved publicly. Red Hat reproduced full administrator compromise twice, including against a stock FreeIPA installation from a zero-access client. The result invalidates the administrative trust root for users and systems governed by an affected FreeIPA domain. Directory Manager is the directory's highest authority, so the sequence collapses authentication and authorization for services relying on the affected directory.
Anonymous LDAP access to an IPA master or replica is sufficient.
FreeIPA and Red Hat Identity Management servers, which centrally manage Linux identities, Kerberos credentials, access policy and related services.
Unauthenticated FreeIPA administrator-group membership
The path replaces an identity server's administrative trust root from outside the domain.
The primitive composes FreeIPA's permissive ADD ACI with 389 Directory Server's treatment of an anonymous empty bind DN as matching empty owner fields.
Red Hat reproduced full compromise twice, including from a zero-access client against a stock installation.
FreeIPA 4.13.4 hardens the vulnerable ACI composition.
The first two fields are effectively not-applicable questions for this server-side access-control fix, so they are recorded as unknown rather than forcing a misleading definite value.
One failed privileged bind followed by an anonymous bind installs the stale privileged identity.
389 Directory Server, the Linux LDAP identity server used directly and by Red Hat directory products.
Unauthenticated Directory Manager authority
The two-bind sequence yields the directory's highest authority and compromises the trust root used by relying services.
The attacker first submits an incorrect password in a SASL PLAIN bind as Directory Manager, leaving the privileged DN in a Cyrus SASL auxiliary property.
A SASL ANONYMOUS bind on the same connection then installs that stale identity.
Pre-fix images remain accepted, and revocation is incomplete despite publication of a fixed upstream version.
The tracker lists additional relevant errata beyond the four supplied, including RHSA-2026:64771 for RHEL 7 ELS and RHSA-2026:64811 for RHEL 6 ELS Extension.
MikroTik RouterOS, the operating system on MikroTik routers, switches and wireless appliances.
CERT Polska confirms successful takeovers since at least September 2, including creation of a highly privileged ops account on exposed routers.
MikroTik has fixed releases, and public code distinguishes vulnerable 7.23.3 from rejecting 7.23.4; pre-fix images remain accepted.
JetBrains Hub, a self-hosted identity and access-management server used by JetBrains development products.
The registration surface grants the rogue service control over Hub's identity and authorization system without requiring administrator credentials.
JetBrains published a fix, but revocation is not complete.
WHMCS, a web-hosting billing and customer-management application deployed on PHP web servers.
A forged request to an affected public WHMCS application reaches an executable context without credentials and runs with the web-server process's privileges.
WHMCS has published a fix.
Samsung Galaxy mobile devices using Samsung's libimagecodec.quram.so image-decoding library on Android.
The underlying heap overflows affect libimagecodec.quram.so on Android 14 through 17, with Samsung's fix in September Release 1.
We do not know which default application reaches the decoder or whether receipt alone triggers it.
LiteLLM, an AI-model gateway and proxy commonly deployed on Linux servers and in containers.
Failed key validation falls through OAuth2 passthrough to an empty authentication object, allowing the caller to list and invoke tools and connected services behind an exposed Streamable HTTP endpoint.
CISA has determined that the flaw is under active exploitation.
Samsung Galaxy mobile devices running Android 14 through 17 with the GalaxyDiagnostics system component.
Samsung confirms the path traversal and published a September fix, but does not identify the accessible file set or show that the path crosses locked-device credential encryption.
Samsung Galaxy mobile devices running Samsung's IMS telephony service.
Samsung does not establish the cheapest remote position, controlled bytes, overwrite behavior, or a useful writable destination.
JetBrains YouTrack, a hosted or self-managed issue-tracking and helpdesk system used by development and support teams.
An unauthenticated caller who can reach affected Helpdesk functionality can claim a target user's email address without proving mailbox ownership and receive that account's authority.
SAP Cloud Application Programming Model multitenant applications using the @sap/cds-mtxs Node.js library in cloud deployments.
The path applies to multitenant applications using @sap/cds-mtxs with extensibility enabled, and the disclosed credentials can be used to replace or delete tenant data.
SAP's September material identifies affected release lines and a remediation note.
Netgear Orbi RBR850 routers and RBS850 satellites sold in RBK852 through RBK855 mesh kits.
The public OpenWrt implementation uses an NMRP-flashed factory image and embedded U-Boot script to replace the stock signed-image boot path persistently.
It requires gigabit LAN access while an RBR850 or RBS850 is power-cycled into recovery.
SAP GUI for Java, the cross-platform desktop client used to operate SAP NetWeaver backend systems.
The client fails to enforce its trust policy when manipulated backend content invokes affected GUI functionality, crossing an existing backend foothold into the operator's command context.
Red Hat Directory Server deployments that include Cockpit 389 Console, the web administration interface for the LDAP directory server on Linux.
The chain requires a separate privileged operator to view the entry, after which Cockpit embeds the unescaped name in a shell command executed through its superuser channel.
AMD 7-Series and Zynq-7000 FPGAs used as programmable logic in embedded and hardware systems.
The practical demonstration remains limited to an XC7A200T, while AMD says the same partial-reconfiguration path makes additional families susceptible in principle.
The technique requires backside silicon access and specialized optical equipment.
Tenda AC9, an embedded dual-band Wi-Fi router.
An authentication-exempt prefix exposes fast_setting_wifi_set, which writes the supplied password into sys.userpass and commits it to flash.
The attacker needs LAN or Wi-Fi access to TCP port 8080 but no session or current password.
Nordic Semiconductor nRF Connect SDK, an embedded SDK used to build Bluetooth Low Energy devices.
The RACP handler copies the full ATT value into a 20-byte static buffer, making the overwritten target dependent on the firmware's BSS layout.
Affected finished products and an exact fixed release remain unidentified.
Bifrost HTTP transport, an open-source gateway for routing requests among AI-model providers, on dynamically linked Linux builds.
With dashboard authentication disabled or unconfigured, a caller can register a custom plugin URL that a dynamically linked, plugin-capable build downloads and passes to Go's plugin loader.
JFrog demonstrated the chain with a canary shared object whose Init function ran in the Bifrost process.
WhatsApp for iOS on iPhones running vulnerable iOS 16 releases.
Forenser demonstrated the result with the current WhatsApp application on iOS versions earlier than 16.7.12 and without victim interaction.
The researchers associate image-processing failures with CVE-2025-43300 and possibly CVE-2025-55177, but they did not publish the initial artifact or prove the complete composition.
The demonstrated boundary is iOS 16.7.12; revocation of previously exposed session material remains unknown, and affected versions reach end-of-life hardware.
MikroTrick takeovers are active, GalaxyDiagnostics exposes system-privileged files to physical access, and Orbi recovery can persist unsigned firmware.
WhatsApp session cloning was demonstrated; Samsung disclosed decoder execution and GalaxyDiagnostics file access, with remote delivery details incomplete.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.