T1190Exploit Public-Facing Application
T1190 — Exploit Public-Facing Application is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 343 detection use cases covering it and 1117 threat-intel articles citing it.
Initial Access
343Use cases
1117Articles
0Sub-techniques
1Tactic
Use cases covering this technique (343)
Authentication not detected on admin API endpoint Excessive resource consumption of third-party API JWT authentication bypass attempt Local File Inclusion (LFI) exploited Spring4Shell RCE attempts (CVE-2022-22963) AWS S3 bucket ACL / policy made public Command injection exploited (WAF detection) Distributed credential-stuffing campaign Log4Shell RCE attempts (CVE-2021-44228) SQL injection exploited (WAF detection) SSRF exploited (WAF detection) Asset exposure — vulnerability matches article CVE(s) [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Cisco IOS XE Request Platform Package Describe Shell Pattern Cisco IOS XE WebUI Login From IOSd Local Port Cisco IOS XE WebUI Programmatic Configuration CrushFTP Server Side Template Injection Ivanti VTM New Account Creation Ollama Possible RCE via Model Loading Ollama Suspicious Prompt Injection Jailbreak Suspicious Java Classes Cisco NVM - Webserver Download From File Sharing Website ConnectWise ScreenConnect Path Traversal ConnectWise ScreenConnect Path Traversal Windows SACL Detect Exchange Web Shell Exchange PowerShell Abuse via SSRF Java Writing JSP File Linux Suspicious React or Next.js Child Process Living Off The Land Detection Log4Shell CVE-2021-44228 Exploitation MOVEit Certificate Store Access Failure MOVEit Empty Key Fingerprint Authentication Attempt MS Exchange Mailbox Replication service writing Active Server Pages Outbound Network Connection from Java Using Default Ports PaperCut NG Suspicious Behavior Debug Log Web or Application Server Spawning a Shell Windows Identify PowerShell Web Access IIS Pool Windows Metasploit Confluence Plugin Execution Windows MOVEit Transfer Writing ASPX Windows PaperCut NG Spawn Shell Windows SharePoint Spinstall0 Webshell File Creation Windows Shell or Script Execution From IIS Directory Windows Shell Process from CrushFTP Windows Suspicious React or Next.js Child Process Windows TeamCity Payload Execution from Temp Directory Windows TeamCity Plugin Installed Windows Unusual File Creation in Confluence Directory Windows WSUS Spawning Shell WinRM Spawning a Process Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity Cisco SD-WAN - Low Frequency Rogue Peer Cisco SD-WAN - Peering Activity Cisco Secure Firewall - High Priority Intrusion Classification Cisco Secure Firewall - Lumma Stealer Activity Cisco Secure Firewall - Oracle E-Business Suite Correlation Cisco Secure Firewall - Oracle E-Business Suite Exploitation Cisco Secure Firewall - React Server Components RCE Attempt Cisco Secure Firewall - Static Tundra Smart Install Abuse Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity Cisco Smart Install Oversized Packet Detection Cisco Smart Install Port Discovery and Status Detect Outbound LDAP Traffic Detect Zerologon via Zeek F5 BIG-IP iControl REST Vulnerability CVE-2022-1388 Access to Vulnerable Ivanti Connect Secure Bookmark Endpoint Adobe ColdFusion Access Control Bypass Adobe ColdFusion Unauthenticated Arbitrary File Read Cisco IOS XE Implant Access Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure Citrix ADC and Gateway Unauthorized Data Disclosure Citrix ADC Exploitation CVE-2023-3519 Citrix ShareFile Exploitation CVE-2023-24489 Confluence CVE-2023-22515 Trigger Vulnerability Confluence Data Center and Server Privilege Escalation Confluence Pre-Auth RCE via OGNL Injection CVE-2023-22527 Confluence Unauthenticated Remote Code Execution CVE-2022-26134 ConnectWise ScreenConnect Authentication Bypass CrushFTP Authentication Bypass Exploitation Detect F5 TMUI RCE CVE-2020-5902 Exploit Public Facing Application via Apache Commons Text Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 Fortinet Appliance Auth bypass HTTP Duplicated Header HTTP Rapid POST with Mixed Status Codes HTTP Request to Reserved Name on IIS Server Hunting for Log4Shell Ivanti Connect Secure Command Injection Attempts Ivanti Connect Secure SSRF in SAML Component Ivanti Connect Secure System Information Access via Auth Bypass Ivanti EPM SQL Injection Remote Code Execution Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078 Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082 Java Class File download by Java User Agent Jenkins Arbitrary File Read CVE-2024-23897 JetBrains TeamCity Authentication Bypass CVE-2024-27198 JetBrains TeamCity Authentication Bypass Suricata CVE-2024-27198 JetBrains TeamCity Limited Auth Bypass Suricata CVE-2024-27199 JetBrains TeamCity RCE Attempt Juniper Networks Remote Code Execution Exploit Detection Log4Shell JNDI Payload Injection Attempt Log4Shell JNDI Payload Injection with Outbound Connection Nginx ConnectWise ScreenConnect Authentication Bypass PaperCut NG Remote Web Access Attempt ProxyShell ProxyNotShell Behavior Detected SAP NetWeaver Visual Composer Exploitation Attempt Spring4Shell Payload URL Request SQL Injection with Long URLs Tomcat Session Deserialization Attempt Tomcat Session File Upload Attempt VMWare Aria Operations Exploit Attempt VMware Server Side Template Injection Hunt VMware Workspace ONE Freemarker Server-side Template Injection Web JSP Request via URL Web Remote ShellServlet Access Web Spring4Shell HTTP Request Class Module Web Spring Cloud Function FunctionRouter Windows Exchange Autodiscover SSRF Abuse Windows IIS Server PSWA Console Access Windows SharePoint Spinstall0 GET Request Windows SharePoint ToolPane Endpoint Exploitation Attempt WordPress Bricks Builder plugin RCE WS FTP Remote Code Execution Ivanti Sentry Authentication Bypass Linux Java Spawning Shell Windows Java Spawning Shells [LLM] Unauthenticated POST to Splunk /v1/postgres/recovery/{backup,restore} endpoints [LLM] splunkd spawning shell interpreters (CVE-2026-20253 post-exploit RCE) [LLM] Splunk Enterprise host initiating outbound PostgreSQL (TCP/5432) to public IP [LLM] Splunk Enterprise vulnerable version inventory (CVE-2026-20253 exposure) [LLM] Budibase CVE-2026-48150: POST /api/public/v1/roles/assign with global builder/admin grant in body [LLM] Internet-facing web service spawning interactive SSH into management subnet [LLM] LangGraph get_state_history SQLi via metadata filter (CVE-2025-67644) [LLM] Ivanti Sentry CVE-2026-10520 handleMessage exploit attempt (commandexec XML) [LLM] Shell or recon binary spawned by Tomcat/Java on Ivanti Sentry (CVE-2026-10520 post-exploitation) [LLM] Ivanti Sentry instances vulnerable to CVE-2026-10520 / CVE-2026-10523 [LLM] External / non-internal HTTP access to Ivanti Sentry /mics admin portal [LLM] PeopleSoft CVE-2026-35273 exploit — POST to /PSEMHUB/hub or /PSIGW/HttpListeningConnector [LLM] Webserver process writes PHP-executable file to public web-root or upload directory (CVE-2026-48062) [LLM] Webserver / PHP interpreter spawns shell or LOLBin — post-upload RCE indicator [LLM] HTTP multipart upload: image Content-Type with PHP/executable filename extension (CVE-2026-48062 exploit shape) [LLM] Vulnerable CodeIgniter4 framework inventory (CVE-2026-48062, < 4.7.3) [LLM] Unauthenticated POST to /mcp endpoint on TCP 8080 (CVE-2026-48039) [LLM] meta-ads-mcp Streamable HTTP listener bound to non-loopback interface [LLM] Public-facing MSSQL sqlservr.exe spawns suspicious child (OceanLotus transport-construction intrusion vector) [LLM] Vulnerable Baileys npm package present on disk (CVE-2026-48063) [LLM] CVE-2026-35616 exploitation attempt against edge SOHO/IoT devices — JDY initial access [LLM] Ivanti Sentry command injection via /mics/api/v2/sentry/mics-config/handleMessage (CVE-2026-10520) [LLM] Fortinet FortiSandbox WEB UI command injection HTTP pattern (CVE-2026-25089) [LLM] SAP NetWeaver SAML XML signature wrapping anomaly (CVE-2026-44748) [LLM] Unpatched Ivanti Sentry / FortiSandbox / SAP NetWeaver in software inventory [LLM] Endpoint exposure to CISA KEV adds: Chrome V8, Cisco SD-WAN Manager, Arista EOS (June 2026) [LLM] Unpatched June 2026 Patch Tuesday CVE inventory (kernel TCP/IP, DHCP, HTTP.sys, BitLocker) [LLM] DHCP Client svchost anomalous child process (CVE-2026-44815 post-exploit) [LLM] HTTP.sys / IIS w3wp.exe spawning shell or LOLBin (CVE-2026-47291 post-exploit) [LLM] phpBB instance vulnerable to CVE-2026-29199 (3.3.16 and below / 4.0.0-a2) exposed on managed assets [LLM] phpBB password-reset Host header injection (CVE-2026-29199 exploitation) [LLM] phpBB OAuth account-binding CSRF — anomalous traffic to pre-3.3.17 OAuth callback path [LLM] Unpatched Assets Vulnerable to Chaotic Eclipse Defender CVE Cluster [LLM] Pheditor CVE-2026-48030 — web server spawning shell interpreter from terminal handler RCE [LLM] Pheditor CVE-2026-48030 — shell metacharacters in 'dir' POST parameter to pheditor.php [LLM] Pheditor CVE-2026-48030 — vulnerable Pheditor 2.0.1–2.0.3 asset inventory exposure [LLM] Unauthenticated WebSocket / HTTP 101 upgrade to phoenix_storybook playground routes [LLM] HEEx / Elixir Kernel injection markers in BEAM-spawned process command line (CVE-2026-8467) [LLM] BEAM / Erlang VM spawns shell or interpreter child (post-RCE — CVE-2026-8467) [LLM] Erlang .beam compiled module dropped to /tmp, /dev/shm, or %TEMP% by BEAM runtime [LLM] Hosts missing June 2026 Patch Tuesday critical RCE/EoP fixes [LLM] w3wp.exe spawning interpreter or LOLBin (http.sys exploitation / IIS RCE marker) [LLM] LiteLLM CVE-2026-42271 MCP test endpoint POST (preview command injection) [LLM] LiteLLM proxy (uvicorn/python) spawning shell or LOLBin — CVE-2026-42271 post-exploit [LLM] Anomalous Host header to LiteLLM (Starlette CVE-2026-48710 BadHost bypass) [LLM] nebula-mesh CVE-2026-47724 — cross-operator admin API key mint via POST /api/v1/operators/{id}/api-keys [LLM] osascript invoked with AppleScript breakout pattern (mismatched tell blocks + do shell script) [LLM] PHPSpreadsheet phar:/// three-slash wrapper in HTTP request (CVE-2026-45034) [LLM] Web-server process (php-fpm / apache / nginx / w3wp) spawning shell or network tooling [LLM] Phar archive or PHPSpreadsheet RCE marker written by web-server process [LLM] Check Point Remote Access VPN inbound auth from CVE-2026-50751 actor VPS IPs [LLM] HTTP access to Shopper admin team-settings / Livewire endpoints (CVE-2026-47744) [LLM] Unauthenticated POST to AIT-BSC /<name>/start with path-traversal form fields (CVE-2026-47731) [LLM] DbGate loadReader functionName code injection (CVE-2026-47670) [LLM] DbGate node process spawning shell child (post-exploit RCE) [LLM] DbGate Zip Slip (CVE-2026-47669): node process writes outside archive dir to OS-sensitive paths [LLM] DbGate exploit chain: anonymous /auth/login + /api/archive/unzip POSTs from same source (CVE-2026-47669) [LLM] DbGate CVE-2026-47668 — Node.js runner spawning shell/LOLBin children for egress [LLM] DbGate exploit web request — POST /runners/start or /runners/load-reader with child_process injection [LLM] DbGate anonymous auth-bypass token mint — POST /auth/login with amoid:none [LLM] Stata binary spawning OS shell (CVE-2026-47708 stata-mcp log_file_name injection) [LLM] Stata-authored log file written with shell metacharacters or path traversal in filename (CVE-2026-47708) [LLM] AVideo YPTSocket plugin XSS injection via webSocketSelfURI/page_title query strings [LLM] mcp-remote OAuth authorization_endpoint RCE (CVE-2025-6514) — node spawning shell [LLM] Vulnerable mcp-remote (CVE-2025-6514) version present on hosts [LLM] Jupyter Enterprise Gateway /api/kernels POST with KERNEL_* YAML-injection payload [LLM] Privileged or root pod created by Jupyter Enterprise Gateway ServiceAccount [LLM] Jinja2 SSTI payload to Jupyter Enterprise Gateway /api/kernels (CVE-2026-44181) [LLM] Jupyter Enterprise Gateway /api/kernels POST with KERNEL_UID/GID body (CVE-2026-44180) [LLM] Vitest UI server launched with non-loopback --api.host / --host (CVE-2026-47429 exposure) [LLM] Path-traversal exploit hitting Vitest /__vitest_attachment__ endpoint (CVE-2026-47429 PoC) [LLM] Post-exploit shell spawned by Vitest node.exe via rerun / saveTestFile (CVE-2026-47429) [LLM] Inbound TCP connection to Vitest UI port 51204 from non-loopback source [LLM] praisonai-platform CVE-2026-47416: PATCH /workspaces/{id}/members/{user_id} role-change request [LLM] Vulnerable praisonai-platform deployment hunt (uvicorn launching praisonai_platform.api.app) [LLM] praisonai-platform cross-tenant workspace operations from single source IP [LLM] PraisonAI Platform cross-workspace nested-resource enumeration (CVE-2026-47407 IDOR) [LLM] PraisonAI Platform open-registration burst followed by workspace privileged action [LLM] Unauthenticated JSON-RPC POST to PraisonAI /a2a endpoint (CVE-2026-47391 exploit) [LLM] Suspicious child process spawned by PraisonAI uvicorn/python A2A server (eval() RCE evidence) [LLM] PraisonAI A2A example server started with vulnerable 0.0.0.0 bind and no auth_token [LLM] Vulnerable PraisonAI package (≤1.6.39) installed on managed host [LLM] PraisonAI `deploy --type api` command execution — vulnerable server provisioned [LLM] Public inbound to PraisonAI Flask listener on TCP/8005 (default port, 0.0.0.0 bind) [LLM] Unauthenticated POST to PraisonAI `/chat` or `/agents` endpoint (incl. CVE-Detector scanner) [LLM] vm2 vulnerable version inventory (CVE-2026-47140) — NodeVM denylist bypass surface [LLM] Node.js process spawning native shell / interpreter — post-vm2-escape host execution [LLM] Node.js process spawning OS shell with enumeration commands — vm2 sandbox escape (CVE-2026-47137) [LLM] Vulnerable vm2 package (<=3.11.3) present on host — CVE-2026-47137 exposure surface [LLM] Vulnerable vm2 package (<=3.11.3) present on endpoints — CVE-2026-47208 exposure [LLM] vm2 sandbox-escape PoC strings observed in inbound HTTP request body / WAF [LLM] Vulnerable vm2 package (<=3.11.3) present in Defender software inventory [LLM] Web service in container spawning interactive shell (Redis/nginx RCE) [LLM] Yamcs MDB algorithm PATCH with embedded Jython java.lang.Runtime payload (CVE-2026-46621) [LLM] Yamcs JVM spawns shell or network utility (CVE-2026-46621 post-exploitation) [LLM] Yamcs MdbOverrideApi algorithm PATCH carrying Nashorn Java.type RCE payload [LLM] Yamcs JVM spawning a POSIX shell — Nashorn Runtime.exec post-exploitation [LLM] Hazy Scorpius (CL0P) Oracle EBS exploitation via CVE-2025-61882 — concurrent processing spawns shell/wget [LLM] LiquidJS SSTI gadget tokens in inbound HTTP (CVE-2026-45618) [LLM] Node.js web process spawning shell (LiquidJS RCE post-exploit) [LLM] Yamcs JVM spawning OS shell/interpreter (Janino RCE via CVE-2026-44632) [LLM] Yamcs MDB algorithm override PATCH with Java Runtime payload [LLM] XWiki unauthenticated XAR import via REST POST /rest/wikis/{wikiName} (CVE-2026-33137) [LLM] Nezha CVE-2026-46716 exploit: POST /api/v1/cron with empty servers + CronCoverAll [LLM] FileBrowser Quantum public share PATCH path traversal in fromPath/toPath (GHSA-qqqm-5547-774x) [LLM] Volumetric PATCH probing against FileBrowser Quantum public share endpoint [LLM] YesWiki Bazar form-import volumetric POST — CVE-2026-46670 blind SQLi extraction loop [LLM] Non-browser User-Agent against YesWiki Bazar form-import endpoint — CVE-2026-46670 exploit tooling [LLM] Vulnerable Twig package (CVE-2026-46633) installed (twig/twig < 3.26.0) [LLM] CVE-2026-46614: Unauthorized /fission-function/ invocation on Fission router public listener (port 8888) [LLM] Coder CVE-2026-46354 - Burst of azure-instance-identity POSTs (vmId enumeration / forged PKCS#7) [LLM] Coder CVE-2026-46354 - Agent token redemption: PKCS#7 POST followed by gitsshkey / external-auth GET [LLM] Coder CVE-2026-46354 - Inventory of vulnerable Coder v2 versions [LLM] 9router unauthenticated RCE — POST /api/cli-tools/cowork-settings with customPlugins.command [LLM] 9router CVE-2026-46339 — GET /api/mcp/{plugin}/sse triggers stored command spawn() [LLM] 9router Node.js process spawning shell binary (CVE-2026-46339 post-exploit) [LLM] Kopia process spawns ssh with -oProxyCommand= argument (CVE-2026-45695) [LLM] GlassFish java process spawning command shell (CVE-2026-2587 RCE) [LLM] Inbound HTTP request to GlassFish gadget.jsf handler (CVE-2026-2587 exploit attempt) [LLM] GlassFish java process outbound HTTP fetch to external host (gadget XML callback) [LLM] Unpatched GlassFish admingui/jsftemplating inventory (CVE-2026-2587 attack surface) [LLM] Inbound HTTP request with Camel-internal header or query param to CXF/Knative endpoint (CVE-2026-47323) [LLM] Apache Camel JVM spawning shell or command interpreter via camel-exec (CVE-2026-47323 post-exploit) [LLM] Apache Camel JVM writing files to sensitive paths via camel-file (CVE-2026-47323 arbitrary file write) [LLM] zrok ProxyShare SSRF — request path begins with absolute URL (CVE-2026-45568) [LLM] HAXcms CVE-2026-46395: unauthenticated GET to /system/api/connectionSettings [LLM] HAXcms CVE-2026-46395: forged-JWT admin write within 30m of connectionSettings leak [LLM] HAXcms CVE-2026-46395: vulnerable @haxtheweb/haxcms-nodejs <= 25.0.0 present [LLM] Algernon web server spawning shell child process (CVE-2026-45721 handler.lua RCE) [LLM] Algernon vulnerable installation discovery (CVE-2026-45721 exposure inventory) [LLM] Vulnerable MLflow 3.9.0 install — CVE-2026-2611 Assistant /ajax-api origin bypass [LLM] MLflow server process spawning Claude Code CLI or shell — CVE-2026-2611 RCE chain [LLM] Mass POSTs to Craft CMS Formie submission endpoint (CVE-2026-45697 SSTI exploitation scan) [LLM] Web-server process (w3wp/php/nginx) spawns shell or LOLBin (post-SSTI RCE chain) [LLM] PHP / IIS web-server writes .php/.phtml/.phar to webroot (post-SSTI webshell drop) [LLM] Cisco Secure FMC anomalous outbound HTTP PUT (Interlock CVE-2026-20131 callback) [LLM] phpMyFAQ /admin/check unauthenticated TOTP brute-force (CVE GHSA-9pq7-mfwh-xx2j) [LLM] phpMyFAQ 2FA bypass success: /admin/check brute burst followed by authenticated /admin/ access [LLM] Vulnerable vm2 npm package (<= 3.11.2) present on host — CVE-2026-45411 [LLM] Node.js process spawning shell or system utility — likely vm2 sandbox escape [LLM] utcp-cli command injection via UTCP_ARG substitution in python→bash -c CMD_N_OUTPUT script [LLM] Vulnerable utcp-cli package (<= 1.1.1) inventory hunt for CVE-2026-45369 [LLM] Marten CVE-2026-45288 regConfig SQL injection attempt in web traffic [LLM] Vulnerable Marten library (CVE-2026-45288) present on host — proactive exposure hunt [LLM] Marten CVE-2026-45288 injection observed executing in PostgreSQL audit log [LLM] MCPHub SSE endpoint accessed with arbitrary username in URL path (CVE-2025/GHSA-wf8q-wvv8-p8jf hunt) [LLM] MCPHub identity spoofing — admin-themed username in /<user>/sse path [LLM] MCPHub SSE user-segment fan-out — single source spawning sessions under multiple usernames [LLM] MCPHub tool execution via spoofed identity — POST to /<user>/messages with JSON-RPC body [LLM] sanitize-html xmp-tag XSS payload (CVE-2026-44990) in inbound HTTP request [LLM] Vulnerable sanitize-html <=2.17.3 / Apostrophe CMS asset inventory (CVE-2026-44990) [LLM] Portainer Swarm service create/update API access (CVE-2026-44849 exploitation path) [LLM] Portainer plugin management API access (CVE-2026-44848) [LLM] n8n host inventory hunt — surface vulnerable instances < 1.123.43 / 2.20.7 / 2.22.1 [LLM] n8n Node.js parent spawning OS shell — post-exploit RCE indicator for CVE-2026-44791 [LLM] n8n workflow API request body containing JS prototype pollution tokens (CVE-2026-44789) [LLM] Post-exploit RCE: node.js (n8n) spawning shell or scripting interpreter [LLM] Vulnerable n8n versions in TVM inventory (CVE-2026-44789) [LLM] Inbound exploit attempt to Cisco Catalyst SD-WAN Manager from known UAT-8616 / Cluster IPs [LLM] XenShell / Godzilla / Behinder JSP webshell file write on Cisco SD-WAN Manager [LLM] FlowiseAI POST /api/v1/node-custom-function with NodeVM Sandbox-Escape Payload (CVE-2026-46442) [LLM] Flowise node.exe Spawning OS Shell or Command-Line Utility - Post-Exploit RCE (CVE-2026-46442) [LLM] Strapi CVE-2026-27886 exploit — `where[admin-relation][private-field]` query parameter against public Content API [LLM] Strapi boolean-oracle hex-alphabet brute force from single source [LLM] Vulnerable Amazon Redshift JDBC Driver (CVE-2026-8178) inventory hunt — redshift-jdbc42 < 2.2.2 [LLM] CVE-2026-8178 exploit attempt: Redshift JDBC URL with class-loading parameter (socketFactory/sslfactory/sslhostnameverifier/sslpasswordcallb [LLM] Malformed CL-STA-1132 attacker User-Agent (Mozilla/5.5 + Safari/532.31) [LLM] Thymeleaf SpEL tab-character sandbox bypass payload in HTTP request (CVE-2026-40478) [LLM] Java/Tomcat process writes .jsp webshell file to disk (CVE-2026-40478 post-exploit drop) [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) [LLM] Qinglong CVE-2026-3965 auth bypass via /open/user/init credential reset [LLM] Qinglong CVE-2026-4047 case-mismatch auth bypass via /aPi/system/command-run [LLM] Mailcow Autodiscover endpoint receives unauthenticated XSS payload (GHSA-f9xf-vc72-rcgm) [LLM] Mailcow login with HTML/JS injected into X-Real-IP header (GHSA-jprq-w83q-q62h) [LLM] Hoppscotch device-login open redirect token theft via localhost.* / sslip.io bypass [LLM] Hoppscotch Mock Server stored XSS via GraphQL updateRESTUserRequest content-type override [LLM] Hoppscotch cross-team request injection via moveRequest GraphQL with null nextRequestID [LLM] Storybook WebSocket XSS/RCE — malicious .stories file written to src/stories (CVE-2026-27148) [LLM] Astro SSRF (CVE-2026-25545) — Node.js egress fetch for /404.html or /500.html with UA 'node' [LLM] Astro SSRF (CVE-2026-25545) — inbound Host header mismatch with 4xx/5xx response (trigger) [LLM] SvelteKit Vercel __pathname cache deception exploit request (CVE-2026-27118) [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic [LLM] ServiceNow Virtual Agent Invocation of Hidden AIA-Agent Invoker AutoChat Topic (CVE-2025-12420) [LLM] Node.js process downloads payload via curl/wget (React2Shell SNOWLIGHT/VShell deployment) [LLM] Vulnerable React Server Components or Next.js App Router versions present in inventory [LLM] Vulnerable react-server-dom-* package versions (CVE-2025-55182) in workload inventory [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server [LLM] Anomalous POST to Next.js Server Action / RSC endpoint with 5xx error clustering [LLM] Next.js CVE-2025-29927 middleware bypass via x-middleware-subrequest header [LLM] Inbound UDP/631 (CUPS IPP discovery) from external network [LLM] Linux assets with vulnerable CUPS packages and external exposure (CVE-2024-47175/76/77/076) [LLM] Vulnerable HTTP/2 server inventory: CONTINUATION flood CVE cluster (CVE-2024-27316 et al.) [LLM] HTTP/2 server crash-loop on internet-facing host (CONTINUATION flood DoS exploitation signal) [LLM] Vulnerable Jinja2 < 3.1.3 inventory pivot for CVE-2024-22195 (xmlattr XSS) [LLM] Jinja2 xmlattr XSS exploitation attempt in HTTP request parameters (CVE-2024-22195) [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt [LLM] Tomcat/Java process writes .jsp/.jspx webshell into webapp directory [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) [LLM] Browser extension folder write at vulnerable React DevTools 4.27.8 / Vue.js devtools 6.5.0 [LLM] Curl invoked with SOCKS5-hostname resolution (CVE-2023-38545 exploit precondition) [LLM] Vulnerable libcurl/curl version present on host (CVE-2023-38545) [LLM] Hosts exposed to libwebp heap overflow CVE-2023-4863 / CVE-2023-5129 (TVM)Articles citing this technique (1117)
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-14
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
high A tale of two eras art-40
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit CISA KEV: CVE-2026-11645 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerability art-93
crit CISA KEV: CVE-2026-50751 — Check Point Security Gateway Improper Authentication Vulnerability art-111
crit CISA KEV: CVE-2026-28318 — SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability art-121
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-130
med Microsoft Build 2026: Securing code, agents, and models across the development lifecycle art-147
high Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages art-159
crit [GHSA / CRITICAL] CVE-2026-47208: vm2 is Vulnerable to Sandbox Breakout Through Promise Species art-176
crit Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection art-178
med How Relay Network Adopted AI Coding Securely and Built the Foundation for Agentic Development art-181
crit CISA KEV: CVE-2026-0257 — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability art-184
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
crit [GHSA / CRITICAL] CVE-2026-46633: Twig: PHP code injection via `{% use %}` template name art-225
crit CISA KEV: CVE-2026-34926 — Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability art-233
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-238
crit CISA KEV: CVE-2009-3459 — Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability art-244
crit The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-248
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-254
crit [GHSA / CRITICAL] CVE-2026-46395: HAXcms: Private Key Disclosure via Broken HMAC Implementation art-261
crit From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat art-265
crit Malicious node-ipc versions published to npm in suspected maintainer account compromise art-284
crit CISA KEV: CVE-2026-42897 — Microsoft Exchange Server Cross-Site Scripting Vulnerability art-285
crit [GHSA / CRITICAL] CVE-2026-44789: n8n: HTTP Request Node Pagination Prototype Pollution to RCE art-301
crit CISA KEV: CVE-2026-20182 — Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability art-310
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-315
crit Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks art-331
med Bridging the Gap to Autonomous Fixes: Snyk and Atlassian Unveil Intelligent Remediation for Jira art-347
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-348
high Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478) art-349
crit CISA KEV: CVE-2026-32202 — Microsoft Windows Protection Mechanism Failure Vulnerability art-351
high Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers art-352
crit CISA KEV: CVE-2026-32201 — Microsoft SharePoint Server Improper Input Validation Vulnerability art-386
med Dev Machine Guard Is Now Open Source: See What's Really Running on Your Developer Machine art-402
crit CISA KEV: CVE-2026-1340 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability art-407
crit CISA KEV: CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Vulnerability art-411
high CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem art-429
crit Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys art-433
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-434
crit CISA KEV: CVE-2025-43520 — Apple Multiple Products Classic Buffer Overflow Vulnerability art-451
crit CISA KEV: CVE-2026-20963 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability art-462
crit Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Hundreds of Repositories art-468
high DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear art-470
crit CISA KEV: CVE-2026-1603 — Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability art-483
crit CISA KEV: CVE-2017-7921 — Hikvision Multiple Products Improper Authentication Vulnerability art-487
crit CISA KEV: CVE-2021-30952 — Apple Multiple Products Integer Overflow or Wraparound Vulnerability art-490
crit CISA KEV: CVE-2026-22719 — Broadcom VMware Aria Operations Command Injection Vulnerability art-496
crit CISA KEV: CVE-2026-25108 — Soliton Systems K.K FileZen OS Command Injection Vulnerability art-509
crit CISA KEV: CVE-2025-49113 — RoundCube Webmail Deserialization of Untrusted Data Vulnerability art-516
med Weaving Security into the Flow: New Snyk Studio Capabilities Power the AI Security Fabric art-528
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit CISA KEV: CVE-2025-15556 — Notepad++ Download of Code Without Integrity Check Vulnerability art-550
crit CISA KEV: CVE-2025-40536 — SolarWinds Web Help Desk Security Control Bypass Vulnerability art-551
crit CISA KEV: CVE-2026-21533 — Microsoft Windows Improper Privilege Management Vulnerability art-567
med The GRU illegals art-572
crit CISA KEV: CVE-2025-11953 — React Native Community CLI OS Command Injection Vulnerability art-575
crit CISA KEV: CVE-2026-1281 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability art-592
crit CISA KEV: CVE-2024-37079 — Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability art-607
crit CISA KEV: CVE-2026-20045 — Cisco Unified Communications Products Code Injection Vulnerability art-617
crit CISA KEV: CVE-2025-20393 — Cisco Multiple Products Improper Input Validation Vulnerability art-645
high How Harden Runner Detected the Sha1-Hulud Supply Chain Attack in CNCF's Backstage Repository art-652
med How Snyk Helps Federal Agencies Prepare for the Genesis Mission Era of AI-Driven Science art-665
crit CISA KEV: CVE-2025-66644 — Array Networks ArrayOS AG OS Command Injection Vulnerability art-669
crit CISA KEV: CVE-2025-55182 — Meta React Server Components Remote Code Execution Vulnerability art-670
high Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182) art-673
med Snyk and Continue Partner to Embed AI-Powered Security into Every Step of the Developer Workflow art-699
crit CISA KEV: CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability art-732
crit CISA KEV: CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability art-742
med Snyk Named a Leader in the 2025 Gartner® Magic Quadrant™ for Application Security Testing art-749
crit CISA KEV: CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability art-751
crit CISA KEV: CVE-2010-3765 — Mozilla Multiple Products Remote Code Execution Vulnerability art-763
crit CISA KEV: CVE-2025-59689 — Libraesva Email Security Gateway Command Injection Vulnerability art-772
crit CISA KEV: CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability art-800
crit CISA KEV: CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability art-803
crit CISA KEV: CVE-2024-8068 — Citrix Session Recording Improper Privilege Management Vulnerability art-809
crit CISA KEV: CVE-2025-43300 — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability art-811
crit CISA KEV: CVE-2013-3893 — Microsoft Internet Explorer Resource Management Errors Vulnerability art-822
crit CISA KEV: CVE-2020-25078 — D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability art-830
crit CISA KEV: CVE-2023-2533 — PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability art-835
crit CISA KEV: CVE-2025-6558 — Google Chromium ANGLE and GPU Improper Input Validation Vulnerability art-839
crit CISA KEV: CVE-2025-53770 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability art-844
crit CISA KEV: CVE-2025-5777 — Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability art-848
crit CISA KEV: CVE-2014-3931 — Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability art-852
crit CISA KEV: CVE-2025-6543 — Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability art-858
med Understanding CRA Compliance: Overcoming Challenges with an Integrated Security Testing Approach art-859
crit CISA KEV: CVE-2024-54085 — AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability art-862
crit CISA KEV: CVE-2025-24016 — Wazuh Server Deserialization of Untrusted Data Vulnerability art-875
crit CISA KEV: CVE-2025-5419 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerability art-880
crit CISA KEV: CVE-2025-21479 — Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability art-883
crit CISA KEV: CVE-2025-3935 — ConnectWise ScreenConnect Improper Authentication Vulnerability art-887
crit CISA KEV: CVE-2024-11182 — MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability art-902
crit CISA KEV: CVE-2025-4428 — Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability art-903
crit CISA KEV: CVE-2025-32756 — Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability art-906
crit CISA KEV: CVE-2025-30397 — Microsoft Windows Scripting Engine Type Confusion Vulnerability art-908
crit CISA KEV: CVE-2025-30400 — Microsoft Windows DWM Core Library Use-After-Free Vulnerability art-910
crit CISA KEV: CVE-2024-58136 — Yiiframework Yii Improper Protection of Alternate Path Vulnerability art-919
crit CISA KEV: CVE-2024-38475 — Apache HTTP Server Improper Escaping of Output Vulnerability art-921
crit CISA KEV: CVE-2023-44221 — SonicWall SMA100 Appliances OS Command Injection Vulnerability art-922
crit CISA KEV: CVE-2025-42599 — Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability art-926
crit CISA KEV: CVE-2025-24054 — Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability art-929
crit CISA KEV: CVE-2025-31201 — Apple Multiple Products Arbitrary Read and Write Vulnerability art-930
crit CISA KEV: CVE-2021-20035 — SonicWall SMA100 Appliances OS Command Injection Vulnerability art-933
crit CISA KEV: CVE-2024-20439 — Cisco Smart Licensing Utility Static Credential Vulnerability art-943
crit CISA KEV: CVE-2024-48248 — NAKIVO Backup and Replication Absolute Path Traversal Vulnerability art-951
crit CISA KEV: CVE-2025-24472 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-956
crit CISA KEV: CVE-2025-24201 — Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability art-961
med Snyk and ServiceNow: Streamlining Vulnerability Management with ServiceNow VR Assignment Rules art-962
crit CISA KEV: CVE-2025-24993 — Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability art-966
crit CISA KEV: CVE-2024-13161 — Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability art-971
crit CISA KEV: CVE-2025-22224 — VMware ESXi and Workstation TOCTOU Race Condition Vulnerability art-979
crit CISA KEV: CVE-2024-49035 — Microsoft Partner Center Improper Access Control Vulnerability art-990
crit CISA KEV: CVE-2025-0108 — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability art-997
crit CISA KEV: CVE-2024-53704 — SonicWall SonicOS SSLVPN Improper Authentication Vulnerability art-998
med Creating SBOMs with the Snyk CLI art-1013
crit CISA KEV: CVE-2018-19410 — Paessler PRTG Network Monitor Local File Inclusion Vulnerability art-1016
crit CISA KEV: CVE-2018-9276 — Paessler PRTG Network Monitor OS Command Injection Vulnerability art-1017
crit CISA KEV: CVE-2024-29059 — Microsoft .NET Framework Information Disclosure Vulnerability art-1018
crit CISA KEV: CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability art-1032
crit CISA KEV: CVE-2024-3393 — Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability art-1042
crit CISA KEV: CVE-2021-44207 — Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability art-1044
crit CISA KEV: CVE-2021-40407 — Reolink RLC-410W IP Camera OS Command Injection Vulnerability art-1047
crit CISA KEV: CVE-2019-11001 — Reolink Multiple IP Cameras OS Command Injection Vulnerability art-1048
crit CISA KEV: CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability art-1051
crit CISA KEV: CVE-2024-50623 — Cleo Multiple Products Unrestricted File Upload Vulnerability art-1054
med Snyk-Generated SBOMs Now Include License Details for the Open Source Libraries in Your Projects art-1059
crit CISA KEV: CVE-2024-44309 — Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability art-1072
crit CISA KEV: CVE-2024-38812 — VMware vCenter Server Heap-Based Buffer Overflow Vulnerability art-1075
crit CISA KEV: CVE-2021-26086 — Atlassian Jira Server and Data Center Path Traversal Vulnerability art-1085
crit CISA KEV: CVE-2024-43451 — Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability art-1088
crit CISA KEV: CVE-2024-49039 — Microsoft Windows Task Scheduler Privilege Escalation Vulnerability art-1089
crit CISA KEV: CVE-2024-5910 — Palo Alto Networks Expedition Missing Authentication Vulnerability art-1093
crit CISA KEV: CVE-2024-8956 — PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability art-1094
med Find, auto-fix, and prioritize intelligently, with Snyk's AI-powered code security tools art-1099
med Snyk announces commitment to Service for America, bringing security education access to all art-1110
crit CISA KEV: CVE-2024-28987 — SolarWinds Web Help Desk Hardcoded Credential Vulnerability art-1113
crit CISA KEV: CVE-2024-30088 — Microsoft Windows Kernel TOCTOU Race Condition Vulnerability art-1115
crit CISA KEV: CVE-2019-0344 — SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability art-1131
crit CISA KEV: CVE-2020-15415 — DrayTek Multiple Vigor Routers OS Command Injection Vulnerability art-1132
crit CISA KEV: CVE-2024-7593 — Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability art-1138
crit CISA KEV: CVE-2024-8963 — Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability art-1140
crit CISA KEV: CVE-2022-21445 — Oracle ADF Faces Deserialization of Untrusted Data Vulnerability art-1143
crit CISA KEV: CVE-2024-27348 — Apache HugeGraph-Server Improper Access Control Vulnerability art-1145
crit CISA KEV: CVE-2013-0643 — Adobe Flash Player Incorrect Default Permissions Vulnerability art-1149
crit CISA KEV: CVE-2024-8190 — Ivanti Cloud Services Appliance OS Command Injection Vulnerability art-1153
crit CISA KEV: CVE-2024-7965 — Google Chromium V8 Inappropriate Implementation Vulnerability art-1166
med A developer’s best friend: Lessons learned from our canine companions about AI code security art-1170
crit CISA KEV: CVE-2021-31196 — Microsoft Exchange Server Information Disclosure Vulnerability art-1174
crit CISA KEV: CVE-2024-23897 — Jenkins Command Line Interface (CLI) Path Traversal Vulnerability art-1177
crit CISA KEV: CVE-2024-38213 — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability art-1185
crit CISA KEV: CVE-2024-38178 — Microsoft Windows Scripting Engine Memory Corruption Vulnerability art-1186
crit CISA KEV: CVE-2024-5217 — ServiceNow Incomplete List of Disallowed Inputs Vulnerability art-1199
crit CISA KEV: CVE-2024-38080 — Microsoft Windows Hyper-V Privilege Escalation Vulnerability art-1214
med Talk to us about Snyk CLI art-1236
med Snyk sponsors Snowflake Summit art-1239
med AppSec spring cleaning checklist art-1247
crit The XZ backdoor CVE-2024-3094 art-1266
med Snyk's AppSec dream team art-1270
med AppSec Maturity Models art-1273
high Defense in Depth art-1278
med With Love, Your Applications art-1285
med Secure password hashing in Go art-1315
crit Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools art-1328
med File encryption in Python: An in-depth exploration of symmetric and asymmetric techniques art-1329
high Snyk Apps now GA: An easy, standardized, and secure framework for building custom integrations art-1332
med What’s new in CVSS 4.0 art-1340
med Rego 101: Introduction to Rego art-1345
high Dependency injection in Python art-1346
crit Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & CVE-2023-46133) art-1349
med Limitations of a single AI model art-1402
med Implementing TLS in Kubernetes art-1409