The RouterOS route requires traffic redirection and a public trusted-root certificate; the Artifactory route requires only network reachability to an instance retaining the shipped blank key.
The attack needs control or redirection of a RouterOS-initiated TLS connection and the public certificate of a trusted RSA root using exponent 3.
MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.
Impersonation of arbitrary TLS servers to RouterOS without a trusted CA private key
This removes trusted-authority authentication from every outbound TLS service that relies on the affected RouterOS certificate check.
CERT Polska validated the certificate-forgery behavior on real RouterOS systems.
Incomplete PKCS#1 v1.5 validation lets the attacker forge a chain under the trusted root, name an arbitrary server, and have RouterOS accept it as the intended peer.
Fixed release ranges are public and complete revocation on updated supported systems; pre-fix images still accept the forged chains, and the fixes do not reach end-of-life hardware.
The Access service accepts attacker-authored HS256 join claims and returns a non-expiring administrator token.
JFrog Artifactory, a self-hosted artifact repository and CI/CD package control plane.
Unauthenticated platform-administrator takeover
We move this above the higher-ranked HPE scope expansion because a shipped default turns anonymous network reachability into administrator access, with runnable code confirming the complete path.
An attacker signs chosen join claims with the public blank key, submits them to the registry join endpoint, and receives administrator scope without authenticating.
That token can reset the built-in administrator password, mint more tokens, and modify repositories or artifacts.
The request sequence has been reproduced, and JFrog has published a fixed-version matrix.
HPE Alletra, Apollo, Edgeline, MicroServer, ProLiant Gen10, Gen10 Plus and Gen11, and Synergy systems using affected Intel CSME or SPS firmware.
The paths require privileged local access to the TPM command interface: object-slot reuse can expose key-certification credentials, while RSA-OAEP timing leaks information about managed ciphertexts.
HPE published model-level affected ranges and firmware resolutions for both flaws.
MediaTek chipset video-decoder firmware and drivers used across Android mobile devices and other embedded products.
The vendor establishes a local out-of-bounds write but does not identify the calling API or precisely describe the caller’s starting privilege.
We do not know whether browser, messenger, or media-framework input can reach the decoder without an existing local foothold.
Nacos 3.x, a service-discovery and configuration-management control plane used by distributed applications.
Misclassified management controllers inherit open-API handling and a separately disabled-by-default authentication switch.
A reachable anonymous caller can create an account, grant it global wildcard permissions, and then read or alter dependent-service configuration.
Nacos 3.2.4 contains the hardening, but pre-fix images remain accepted and revocation is incomplete.
MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.
The stale authorization pointer and encrypted-URI traversal were already tracked; today’s change establishes their reach into root-owned, credential-bearing configuration files.
WebFig must be reachable, with WAN exposure determined by firewall configuration; pre-fix images remain accepted, and fixes do not reach end-of-life hardware.
Phones and other connected devices using the affected MediaTek modem chipsets and firmware
The target must connect to the attacker-controlled base station, after which malformed modem input reaches one of two missing bounds checks and a system crash.
No patch status has been established for either flaw.
OpenStack Glance, the image-management service used by private and public OpenStack clouds.
Weak destination filtering, DNS-rebinding gaps, and an unfiltered HTTP image store let an authorized importer select an internal resource.
The HTTP-store path saves the response as downloadable image data, and OpenStack has published coordinated patches.
Langflow, a self-hosted Python platform for building and deploying AI agents and workflows, commonly run in Linux containers.
An Internet-reachable validate endpoint executes unauthenticated Python supplied through its code parameter.
Observed payloads search environment variables and local files for Langflow administrator secrets, cloud credentials, API keys, SSH material, and shell history; no fixed release is known.
PassMark PerformanceTest, BurnInTest and OSForensics, Windows benchmarking, stress-testing and forensic utilities that install a signed kernel helper driver.
The vulnerable driver must be loaded and its device obtainable, but its permissive ACL then exposes physical-memory, MSR, PCI, I/O-port, and privileged-file operations.
Public code uses those operations to locate kernel process structures, bypass write gates, and replace the caller’s process token with SYSTEM.
PassMark release notes identify a corrected DirectIO driver.
libheif, the cross-platform HEIF and AVIF decoding library used by image applications and server-side processors.
An unsupported auxiliary item receives a null context that verify_decodable dereferences when a consumer traverses or decodes it.
Upstream published a complete regression-file generator, but released-version scope and receipt-only reachability remain unverified.
MojoX::Authentication, a Perl authentication library used by Mojolicious applications for local and SAML2 login.
The parser lacked a configured trust anchor, so an attacker could sign an assertion naming the target account and have it checked against the certificate embedded in that response.
MojoX::Authentication 0.006 and later contain the fix.
D-Link DIR-882 wireless routers running end-of-life embedded firmware.
An anonymous request stores shell syntax in an NVRAM field that the router later concatenates into a twsystem command.
The evidence is ten honeypot connections recorded as attempts; it does not establish successful compromise or execution as root.
The product is end of life and will receive no fix.
JimuReport, a Java/Spring Boot web-based reporting and dashboard server.
A caller needs a valid report identifier but no account, then uses the hard-coded signing secret to reach Aviator evaluation and escape its sandbox.
No patch is available for the documented JimuReport path.
Tenda HG10 GPON optical-network terminals and routers running embedded firmware.
From the LAN, an anonymous caller can place shell syntax in fmgpon_loid; the published benign payload powers off the appliance.
We do not know whether the route is WAN-reachable or which operating-system identity executes the command.
FreeIPMI management clients on Linux and Unix hosts used to query server baseboard-management controllers.
A compromised BMC returns more FRU bytes than requested, and the client copies them beyond a fixed-size stack buffer when an administrator reads inventory.
Controlled execution remains unproved; FreeIPMI 1.6.19’s announcement says it fixes stack overflows caused by nonconforming BMC responses.
HPE Alletra, Apollo, Edgeline, ProLiant, and Synergy servers; HPE's September revision added Gen11, Gen10 Plus, and Gen10 systems to the previously listed Gen12 scope.
HPE added Gen10, Gen10 Plus, and Gen11 systems to the affected scope, but access already requires privileged local system software and additional conditions.
The public material does not identify the retained buffer, the exposed data, or the operation used to retrieve it.
No additional findings today.
No cheaper access path, demonstrated consequence, wider affected scope, fix bypass, or exploitation emerged from the Bluetooth work.
No new Wi-Fi access path, consequence, affected scope, fix bypass, or exploitation was established.
PassMark’s signed driver exposed physical-memory and kernel-control operations to a standard Windows user when the device is available.
RouterOS certificate forgery and root-file disclosure were demonstrated, and Langflow exploitation moved into observed secret probing.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.