Batch #2 - August 2026 (15 advisories · 12 critical · 12 unauth)
·
9 commits
to main
since this release
Batch #2 — August 2026
15 advisories · 10 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.
Second batch — expanding coverage into ICS/SCADA, backup, source-control management, and media systems. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.
| # | Product | Affected Version | CVSS | Class | Advisory & PoC |
|---|---|---|---|---|---|
| 13 | Apache Struts 2 | 6.11.0 | 9.8 | Unauth RCE (Root) | RestfulActionMapper OGNL Injection → RCE |
| 14 | AOMEI Cyber Backup | 2.3.0 | 9.8 | Unauth RCE (Root) | Thrift NAS Mount Injection → RCE |
| 15 | Xeams | 10.3 (build 6449) | 9.8 | Unauth RCE (Root) | SMTP X-SM_SAVE_BODY File Write → RCE |
| 16 | Xeams | 10.3 (build 6449) | 9.8 | Unauth RCE (Root) | SQLRunner Derby Hardcoded Creds → JSP Webshell |
| 17 | atvise SCADA | 3.13.0 | 9.8 | Unauth RCE (Root) | OPC UA Auth Bypass + V8 Injection → RCE |
| 18 | CIRCUTOR PowerStudio | 24.11.6.0 | 9.8 | Unauth RCE (SYSTEM) | JWT alg=none + shellExecute → RCE |
| 19 | CatDV Server | 10.7.8 | 9.8 | Unauth RCE (Root) | RMI ClientID Minting → aaftoolPath RCE |
| 20 | CatDV Server | 10.7.8 | 9.8 | Default Credentials | Factory-Default Empty Admin Password |
| 21 | Vicon Valerus | 25.200.46.0 | 9.8 | Unauth RCE (SYSTEM) | OWIN Web API Command Injection → RCE |
| 22 | Stimulsoft Server | 2026.3.1 | 9.8 | Unauth RCE (SYSTEM) | Signup + Report-Script Compilation → RCE |
| 23 | Plastic SCM (Unity) | 11.0.16.10303 | 9.8 | Unauth RCE | Name-Only ACL 8087 Trigger → RCE |
| 24 | vMix | 29.0.0.48 | 9.8 | Unauth RCE (Admin) | VBScript Blocklist Bypass → RCE |
| 25 | atvise SCADA | 3.13.0 | 8.8 | Default-Cred RCE (Root) | WebMI Default Credential + V8 Injection → RCE |
| 26 | CIRCUTOR PowerStudio | 24.11.6.0 | 8.6 | Auth Bypass | JWT alg=none Identity Forgery |
| 27 | CatDV Server | 10.7.8 | 7.6 | Auth RCE (Root) | aaftoolPath Property Injection → RCE |
Highlights
- 12 critical (CVSS ≥ 9.0) · 12 unauthenticated (incl. default-credential)
- Notable: Apache Struts 2 (9.8, OGNL), two ICS/SCADA RCEs (atvise, CIRCUTOR), and a Unity Plastic SCM unauth RCE
- Attack classes: OGNL injection, Thrift injection, JWT alg=none forgery, V8 injection, VBScript blocklist bypass
Running total
27 advisories · 18 vendors · 21 critical · 20 unauthenticated · all with reproducible PoC.
Next drop: late August 2026 → expanding into ICS / SCADA, energy, and aerospace.
⭐ Star to bookmark · 👁 Watch for the next batch · 🌐 https://0day-rubbish.com/blog