Bishop Fox
bishopfox-blog · B · candidate
Added 2026-10-04 (FU2): weaponization write-ups with public safe patch-state detection tools for KEV-class edge products, usually within about ten days of the vendor advisory (Check Point management CVE-2026-93616 on 2026-10-01, plus NetScaler, MikroTik, SolarWinds ARM, Veeam VSPC and JFrog earlier). It was cited by the 2026-10-04 Check Point changelog record. Working recipe: `fetch_source.py feed https://bishopfox.com/feeds/blog.rss` (direct, dated), then `extract <link>`; /feed/rss returns 404. Promote to active after 3 contributing runs.
Cited in 3 entries
Citation cadence
Citation days per ISO week (21 weeks of coverage span, total 2).
- CVE-2026-93616, Check Point Security Management: pre-authentication path traversal to arbitrary script execution, exploited as a zero-day, with attacks observed on 2026-07-23 (CVSS 9.8)2026-09-23
- CVE-2026-42208, LiteLLM Proxy pre-authentication SQL injection: CISA KEV deadline 2026-05-11; all upstream LLM API keys at risk2026-05-09
- CVE-2025-68670, xrdp pre-authentication stack overflow, arbitrary code execution2026-05-09