Skip to content

Batch #2 - August 2026 (15 advisories · 12 critical · 12 unauth)

Choose a tag to compare

@Exploit-Garbage Exploit-Garbage released this 05 Aug 14:29
· 9 commits to main since this release

Batch #2 — August 2026

15 advisories · 10 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.

Second batch — expanding coverage into ICS/SCADA, backup, source-control management, and media systems. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.

# Product Affected Version CVSS Class Advisory & PoC
13 Apache Struts 2 6.11.0 9.8 Unauth RCE (Root) RestfulActionMapper OGNL Injection → RCE
14 AOMEI Cyber Backup 2.3.0 9.8 Unauth RCE (Root) Thrift NAS Mount Injection → RCE
15 Xeams 10.3 (build 6449) 9.8 Unauth RCE (Root) SMTP X-SM_SAVE_BODY File Write → RCE
16 Xeams 10.3 (build 6449) 9.8 Unauth RCE (Root) SQLRunner Derby Hardcoded Creds → JSP Webshell
17 atvise SCADA 3.13.0 9.8 Unauth RCE (Root) OPC UA Auth Bypass + V8 Injection → RCE
18 CIRCUTOR PowerStudio 24.11.6.0 9.8 Unauth RCE (SYSTEM) JWT alg=none + shellExecute → RCE
19 CatDV Server 10.7.8 9.8 Unauth RCE (Root) RMI ClientID Minting → aaftoolPath RCE
20 CatDV Server 10.7.8 9.8 Default Credentials Factory-Default Empty Admin Password
21 Vicon Valerus 25.200.46.0 9.8 Unauth RCE (SYSTEM) OWIN Web API Command Injection → RCE
22 Stimulsoft Server 2026.3.1 9.8 Unauth RCE (SYSTEM) Signup + Report-Script Compilation → RCE
23 Plastic SCM (Unity) 11.0.16.10303 9.8 Unauth RCE Name-Only ACL 8087 Trigger → RCE
24 vMix 29.0.0.48 9.8 Unauth RCE (Admin) VBScript Blocklist Bypass → RCE
25 atvise SCADA 3.13.0 8.8 Default-Cred RCE (Root) WebMI Default Credential + V8 Injection → RCE
26 CIRCUTOR PowerStudio 24.11.6.0 8.6 Auth Bypass JWT alg=none Identity Forgery
27 CatDV Server 10.7.8 7.6 Auth RCE (Root) aaftoolPath Property Injection → RCE

Highlights

  • 12 critical (CVSS ≥ 9.0) · 12 unauthenticated (incl. default-credential)
  • Notable: Apache Struts 2 (9.8, OGNL), two ICS/SCADA RCEs (atvise, CIRCUTOR), and a Unity Plastic SCM unauth RCE
  • Attack classes: OGNL injection, Thrift injection, JWT alg=none forgery, V8 injection, VBScript blocklist bypass

Running total

27 advisories · 18 vendors · 21 critical · 20 unauthenticated · all with reproducible PoC.

Next drop: late August 2026 → expanding into ICS / SCADA, energy, and aerospace.

Star to bookmark · 👁 Watch for the next batch · 🌐 https://0day-rubbish.com/blog