Skip to content

Batch #1 - July 2026 (12 advisories · 9 critical · 8 unauth)

Choose a tag to compare

@Exploit-Garbage Exploit-Garbage released this 05 Aug 14:29
· 9 commits to main since this release

Batch #1 — July 2026

12 advisories · 9 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.

First disclosure batch of the AI-driven 0-day series. Full writeups and exploit scripts are published on https://0day-rubbish.com/blog; reproducible PoC code lives in this repo under product/<vendor>/<version>/<type>/exploit/.

# Product Affected Version CVSS Class Advisory & PoC
1 InterSystems IRIS 2026.1.0.234.1 9.8 Unauth RCE FolderManager Property Injection → RCE
2 AdRem NetCrunch 16.0.0.8397 RC 9.8 Unauth RCE (SYSTEM) Cross-Session Hijack → RCE
3 Altus BluePlant 9.1.40 9.8 Unauth RCE Hardcoded Credentials → RCE
4 Brekeke SIP Server v3.19.1.8p1 9.8 Unauth RCE Nashorn JS Engine → RCE
5 Brekeke SIP Server v3.19.1.8p1 9.8 Unauth RCE (Zip Slip) Zip Slip Webshell → RCE
6 DataSunrise Suite 11.2.17.12820 9.8 Unauth RCE Email Verification Brute Force → RCE
7 Cisco CUCM 14.0 9.8 RCE Chain Multi-stage RCE Chain
8 SonicWall SMA 1000 12.4.2 9.8 Pre-Auth RCE Struts 1 Property Injection → Deserialization RCE
9 Brekeke SIP Server v3.19.1.8p1 9.1 Auth Bypass Auth Fail-Open → 23 Unauth Beans
10 Acumatica ERP 2026 R1 8.8 Auth RCE Customization Publish Webshell → RCE
11 AdRem NetCrunch 16.0.0.8397 RC 8.8 Auth RCE (SYSTEM) Startup Script → RCE
12 Altus iX Developer 2.53.65422 7.3 Local/UI RCE XAML Deserialization → RCE

Highlights

  • 9 critical (CVSS ≥ 9.0) · 8 unauthenticated
  • Attack classes: unauth RCE chains, session hijack, hardcoded credentials, deserialization, Zip Slip webshell, auth fail-open
  • Vendors span enterprise IT (Cisco, InterSystems, SonicWall), telecom (Brekeke), ERP (Acumatica), and ICS (Altus)

To all vendors: we hope you complete fixes before these are weaponized.

Star to bookmark · 👁 Watch (custom → Releases + Discussions) for the next drop · 🌐 https://0day-rubbish.com/blog