important2 findings, 14 signals5 min read

Board-level access now opens protected data on 24 Galaxy Watch 4–6 models, while a rogue cellular base station can corrupt privileged MediaTek modem firmware without user interaction.

Separately, September’s emergency NetScaler fixes did not eliminate a repeatable SAML outage path that Citrix says is under targeted attack.

Priority findings2
01
High
Physical — Mobile
Confirmed

Board-level USB access now opens passcode-protected data on 24 Galaxy Watch models.

The method needs possession of the watch, disassembly and a connection to its USB test pads.

Affects

Samsung Galaxy Watch FE and Watch 4, 5, and 6 families running Wear OS, using Exynos W920 or W930 SoCs.

What it enables

Passcode recovery and decrypted application-data extraction

Obtain and disassemble a supported Galaxy Watch.→↓Connect the forensic workstation to the watch's USB test pads.→↓Use Passware Kit Mobile 2026 v5 to exercise the Exynos W920/W930 vulnerability and acquire the protected material.→↓Run GPU-accelerated passcode recovery.→↓Use the recovered passcode to decrypt application data.
Why this matters

A stolen locked watch can no longer be assumed to keep its application data confidential once an equipped examiner reaches the board.

Detail and 2 sources
Required access

Device in hand, watch disassembled, and a USB connection made to board test pads

Affected versions

Galaxy Watch FE on Wear OS 4.x–6.x, Galaxy Watch4 and Watch4 Classic on Wear OS 3.x–6.x, Galaxy Watch5 and Watch5 Pro on Wear OS 3.x–6.x, Galaxy Watch6 and Watch6 Classic on Wear OS 4.x–6.x

Proof of concept

Demonstrated by the researcher

Passware’s commercial tool exploits an undisclosed vulnerability in the Exynos W920 and W930 system-on-chips to acquire protected material.

It then performs GPU-accelerated passcode recovery and uses the recovered passcode to decrypt application data.

The reviewed announcement and device catalog do not identify a remediation for affected watches.

Evidence
Passware's October 1 release announcement states that the shipped commercial tool exploits the two SoCs after disassembly and test-pad connection, recovers passcodes, decrypts app data, and gives a measured Watch6 recovery rate.Passware's supported-device catalog names the model and Wear OS ranges.
Share this finding
02
High
Edge
Confirmed
CVE-2026-88779

September’s emergency NetScaler fixes did not eliminate repeatable unauthenticated SAML outages.

Citrix reports targeted attacks, and CISA has added the flaw to its exploited-vulnerability catalog.

Affects

Customer-managed NetScaler ADC and NetScaler Gateway appliances providing application delivery, AAA and remote-access VPN services.

What it enables

Unauthenticated persistent denial of service against SAML authentication gateways

Reach an affected Gateway or AAA virtual server configured to use NetScaler as a SAML SP or IdP.→↓Send traffic that triggers the SAML-path memory overflow and crashes the service.→↓Repeat the trigger to keep the authentication or remote-access service unavailable.
Why this matters

An unauthenticated client can still repeatedly crash SAML-enabled NetScaler gateways after the emergency fixes, and Citrix reports attacks against unmitigated deployments.

Detail and 2 sources
Required access

Unauthenticated network reachability to a Gateway or AAA virtual server using NetScaler as a SAML service provider or identity provider

Affected versions

NetScaler ADC and Gateway 14.1 before 14.1-73.41, NetScaler ADC and Gateway 13.1 before 13.1-64.28, NetScaler ADC 14.1-FIPS before 14.1-73.41-FIPS, NetScaler ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.282

An unauthenticated client can reach the memory-overflow path on a Gateway or AAA virtual server where NetScaler acts as a SAML service provider or identity provider, then repeat the trigger to keep the service unavailable.

Citrix has not identified an integrity impact, and reports calling the flaw remote code execution remain unconfirmed.

Evidence
Citrix confirms targeted attacks against unmitigated deployments and a denial-of-service consequence.Citrix says repeated triggering may keep the service unavailable.Citrix has not identified an integrity impact; reports characterizing the flaw as RCE remain unconfirmed.CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog.
Share this finding
Signals14
important · Edge — RCE

Attackers are using FortiMail’s public management interface for credential-free file writes and appliance code execution.

Affects

Fortinet FortiMail, a physical, virtual and cloud-deployed secure email gateway.

A crafted HTTP or HTTPS request combines path traversal with NULL-byte handling to write or replace files outside the intended path.

Detail and 4 sources

Observed compromises included attacker-added binaries, ld.so.preload modification and root cron activity.

A patch was announced, but current release availability could not be resolved from the retrieved vendor material.

Today’s change is the confirmed scope: the arbitrary-file-write primitive is now connected to persistence and command execution using root-level mechanisms.

important · Boot chain

An unprivileged normal-world client can make OP-TEE sign an attacker-selected attestation digest.

Affects

OP-TEE Core, a trusted execution environment commonly used on Arm-based embedded and Linux systems.

The path requires local userspace access to the OP-TEE device interface and a build with CFG_ATTESTATION_PTA enabled.

Detail and 1 source

A verifier can accept the valid device signature as a false claim about OP-TEE or a trusted application.

OP-TEE has published a patch for the shared-buffer race.

important · Physical — Edge

Armatura One’s default network listener can turn an unauthenticated connection into highest-privilege control of a physical-access system.

Affects

Armatura One, a Windows-hosted platform managing doors, elevators, visitors, parking, video, and other building-security functions.

A crafted OpenWire command causes attacker-selected object-graph deserialization before authentication, executing code with the service’s highest operating-system privilege.

Detail and 1 source
important · Identity — Edge

A low-privilege Dogtag EST account can mint CA-signed certificates for arbitrary identities.

Affects

Dogtag PKI enterprise certificate-authority services on Linux, including affected Red Hat Certificate System and RHEL deployments.

The path applies to an EST fullcmc endpoint using HTTP Basic authentication and requires only valid EST user credentials.

Detail and 1 source

Without an end-user TLS certificate, a stale subsystem-agent certificate causes downstream authorization to treat the request as agent-privileged.

Deployments that enforce mutual TLS are not susceptible to this path.

important · Firmware — RCE

A public demonstration turns Dahua’s ONVIF stack overflow into an unauthenticated root reverse shell.

Affects

Dahua IPC and SD-series embedded network and PTZ cameras.

The demonstration establishes execution control beyond the original advisory’s emphasis on disruption and exploit-protection assumptions.

Detail and 3 sources
important · Privilege

Apache 2.4.68’s tenant-boundary fix missed mod_ssl SSLRequire.

Affects

Apache HTTP Server 2.4 installations using mod_ssl and permitting lower-privileged users or hosting tenants to author .htaccess files.

A tenant who can write .htaccess rules in an eligible mod_ssl directory can still invoke file functions with the httpd process’s filesystem authority.

Detail and 2 sources
important · Backup infrastructure

AhsayCBS records describe unauthenticated command injection in the Replication Receiver API.

Affects

AhsayCBS, a self-hosted enterprise backup-management and replication server for Windows and Unix-like systems.

A network client can submit a crafted random parameter to UpdateReceivers.do over the Replication Receiver HTTP or HTTPS service, commonly on port 80 or 443.

Detail and 6 sources

We could not verify the cited exploit or determine the resulting process identity on Windows and Linux from a primary publication.

Chain to watch
Reach the Replication Receiver API without authenticating.→↓Submit a crafted random parameter to UpdateReceivers.do.→↓Determine whether the resulting command executes and under which service identity.→↓The cited exploit and the command’s execution identity remain unverified.
Unverified chainRetrieve the cited exploit, replay it in an authorized AhsayCBS 10.3.2-or-earlier lab, and record the process identity on Windows and Linux.
important · RCE

Active exploitation now makes HFS’s predictable session-signing keys an unauthenticated server-execution path.

Affects

Rejetto HFS, a self-hosted HTTP file server for Windows, Linux, macOS, FreeBSD and Android.

The attacker needs a network-reachable HFS 3.x server and a login-enabled username available through the documented enumeration oracle.

Detail and 3 sources

Consecutive Math.random outputs reveal recoverable xorshift128+ state, which yields the startup signing key used to forge an administrator session.

HFS 3.2.1 is published as the fixed release.

Today’s change is the complete root cause and execution chain, accompanied by observed exploitation.

important · Firmware — Privilege

An unauthenticated client on a Digi device’s default LAN can execute operating-system commands as root.

Affects

Digi Accelerated Linux, the embedded operating system used by Digi cellular routers, console servers, USB-over-IP devices and IoT gateways.

The administration service is LAN-only by default but can become WAN-reachable when reconfigured.

Detail and 2 sources

A crafted unauthenticated HTTP POST injects a command that runs with root privileges.

Today’s change is the recovery gap: affected devices still accept pre-fix images, preserving a route back to vulnerable code after an update.

important · Firmware

A privileged Moxa MGate administrator can install modified firmware that survives later updates.

Affects

Moxa MGate 3000 and 5000 Series industrial protocol gateways connecting serial and industrial protocols to Ethernet networks.

The path requires high-privilege credentials and access to the gateway’s firmware-update interface.

Detail and 1 source

Improper signature verification permits installation of a crafted image, and its unauthorized changes can persist across subsequent firmware updates.

important · Desktop — RCE

A LAN observer can turn Maestro’s plaintext Live Mode URL into command execution as the desktop user.

Affects

Maestro, a cross-platform desktop application for controlling AI coding agents and terminals.

Live Mode binds an HTTP and WebSocket control server to 0.0.0.0, embeds bearer tokens in URLs and exposes a terminal-capable API.

Detail and 1 source
important · Physical — Robotics

Unauthenticated path traversal exposes credentials and configuration on PackBot and FirstLook robots.

Affects

Teledyne FLIR Aware2 software used by PackBot and FirstLook unmanned ground robots.

A remote client can read arbitrary files through the Aware2 web service, including stored credentials and operational configuration.

Detail and 2 sources

Mandiant claims complete compromise and remote code execution, but the public material does not disclose the transition from file reading to execution.

Updated software is published, but the fix itself was not inspected for this brief.

Chain to watch
Reach the Aware2 web service without authenticating.→↓Use traversal components to read credentials and configuration.→↓Establish whether the exposed material yields code execution on each robot family.→↓The public record does not establish the claimed transition from arbitrary file reading to code execution.
Unverified chainObtain the fixed build or proof of concept and reproduce that transition on PackBot and FirstLook.
important · RCE

MindSearch contains an unrestricted Python exec sink, but its unauthenticated remote route remains unverified.

Affects

InternLM MindSearch, a Python-based AI search-agent application commonly exposed through a web service.

ExecutionAction.run strips optional Markdown fencing and passes its command argument directly to Python exec with server globals and locals.

Detail and 3 sources

The CNA record says a remote planner request reaches that sink, but the end-to-end dataflow from a stock unauthenticated request was not reproduced.

Chain to watch
Submit attacker-controlled input to a stock MindSearch 0.1.0 planner service.→↓Trace the planner-controlled command argument into ExecutionAction.run.→↓Confirm whether attacker-selected text reaches Python exec without authentication.→↓The sink is present, but the stock unauthenticated request-to-exec path remains unverified.
Unverified chainReplay the referenced exploit against stock MindSearch 0.1.0 while tracing the request handler, planner output and ExecutionAction.run argument.
important · Mobile — Zero-click

A rogue cellular base station can write outside two MediaTek modem buffers and remotely escalate privilege without user interaction.

Affects

MediaTek cellular modems used across phones, tablets, automotive systems and other embedded devices built on the listed chipsets.

Crafted cellular input reaches one of two parsing paths with a missing bounds check, producing an out-of-bounds write in privileged modem firmware.

Detail and 6 sources

MediaTek has announced a fix, but we could not retrieve the bulletin body, so the complete chipset matrix and device-level delivery status remain unresolved.

Chain to watch
Attacker operates a rogue cellular base station within range of the target.→↓The powered-on UE attaches to the attacker-controlled station.→↓Crafted cellular input reaches one of two modem parsing paths with a missing bounds check.→↓The input causes an out-of-bounds write in privileged modem firmware.→↓The vendor-assigned CVE records state that the condition permits remote escalation of privilege.→↓The precise radio message, resulting modem privilege, exploitability and behavior on a factory-stock bootloader-locked handset are not public
Unverified chainObtain MediaTek patches MOLY01778993 and MOLY01778988 or reproduce both issues on a stock handset while recording the over-the-air message and resulting execution context
Also noted0

No additional findings today.

What was checked · 4 quiet
BluetoothQuiet

Current BlueZ items remain crash-only in experimental or paired/local workflows, while kernel activity propagates older fixes.

Wi-FiQuiet

Recent ASUS, Buffalo and Wireshark items repeat known capabilities; inaccessible hostap diffs leave two peer-triggered questions unresolved.

Zero-clickQuiet

Two MediaTek modem write primitives are reachable after attachment to a rogue cellular base station; Android bulletin coverage remains incomplete.

MobileQuiet

The MediaTek modem findings are the sole new mobile capability delta; full platform-bulletin coverage remains unavailable.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026