VulnCheck
vulncheck · B · active
https://www.vulncheck.com/blog
Exploitation evidence and KEV-adjacent intelligence. URL UPDATED 2026-05-08: vulncheck.com 301-redirects to www.vulncheck.com, using the canonical avoids the redirect. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://www.vulncheck.com/blog (listing has titles+dates+URLs), then WebFetch the /blog/<slug> article URL for the technical body.. AVOID: No working RSS, /blog/rss 404s. The WebFetch summariser may mangle one URL ('wwv.vulncheck.com' typo), use the canonical vulncheck.com/blog/<slug> form.. | 2026-07-05 admiralty audit: B, original exploitation/vuln research lab; WebFetch listing + article works, no RSS. No status change. | 2026-09-15 intel run: extract/bridge fetch of vulncheck.com/blog returned a stale cached snapshot (page metadata dated 2022-11-12); no current listing recovered.
Cited in 11 entries
Citation cadence
Citation days per ISO week (7 weeks of coverage span, total 10).
- Flowise ships three new CVEs into a sunset, an unauthenticated auth bypass that defeats an earlier fix, and cross-workspace credential access, with no vendor left to patch them2026-08-08
- ENDLESSDOORS (CVE-2026-66747); twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser's remedy is replacement2026-08-06
- CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0)2026-08-04
- CVE-2026-54363 and five siblings, Gladinet CentreStack: one cryptographic key shared across every installation forges a domain-administrator token, completing an unauthenticated RCE chain2026-08-03
- CVE-2026-65883, Aimy Captcha-Less Form Guard for Joomla: the anti-spam token is deserialized before any check, and the XOR keystream ships in the same page (CVSS 9.8)2026-08-01
- CVE-2026-0769, Langflow: an unpatched pre-auth eval-injection RCE that VulnCheck observes being exploited, and that CISA KEV does not list2026-07-29
- CVE-2026-61511, vBulletin: an arithmetic-only regex filter in front of eval() yields unauthenticated RCE, with a working exploit now public2026-07-28
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term2026-07-18
- CVE-2026-61500, Rejetto HFS < 3.2.1: predictable session-signing PRNG lets an unauthenticated attacker forge admin sessions to RCE (CVSS 9.3)2026-07-13
- CVE-2026-58053, Gitea act_runner Docker backend: container-hardening bypass to host escape (CVSS 9.4, public PoC)2026-06-28
- CVE-2026-55200, libssh2 heap out-of-bounds write in ssh2_transport_read() with public PoC; companion pre-auth DoS CVE-2026-551992026-06-28