Batch #5 - August 2026 (8 advisories · 6 critical · 5 unauth)
·
4 commits
to main
since this release
Batch #5 — August 2026
8 advisories · 8 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.
Fifth batch — expanding coverage into IoT/MQTT, in-memory data grids, mail servers, hosting control panels, load balancing, physical communication infrastructure, contact centers, and low-code BPM. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.
| # | Product | Affected Version | CVSS | Class | Advisory & PoC |
|---|---|---|---|---|---|
| 1 | HiveMQ Platform | 4.54.0 | 9.8 | Default creds + Zip-Slip (Root) | Data Hub Zip-Slip → Root RCE |
| 2 | GigaSpaces XAP | 16.1.1 | 9.8 | Unauth Path Traversal → Webshell (Root) | Unauth Path Traversal → Root RCE |
| 3 | IceWarp Server | 14.3.0 | 9.0 | Auth Config + Unauth Trigger → UNC DLL (SYSTEM) | Static Route UNC DLL → SYSTEM RCE |
| 4 | KeyHelp | 26.0 | 7.2 | Auth Apache Directive Pipe (Root) | Custom Directive ErrorLog Pipe → Root RCE |
| 5 | Loadbalancer.org ADC | 8.13.8 | 8.8 | Auth Cmd Injection → sudo (Root) | Deployment Template Cmd Injection → Root RCE |
| 6 | Biamp Vocia MS-1 | 1.2.27 | 9.8 | Hardcoded Creds + Supervisor Exec (Root) | FTPS Hardcoded Creds → Root RCE |
| 7 | Voicent Call Center | 10.10.1 | 9.8 | Unauth Auth Bypass + Webshell (Root) | SaveFileServlet Unauth → Root RCE |
| 8 | Joget Workflow Enterprise | 9.1.0.1 | 9.8 | Unauth jrxml Expression Injection (Root) | JasperReports Expression Injection → Root RCE |
Highlights
- 6 critical (CVSS ≥ 9.0) · 5 unauthenticated
- Notable: HiveMQ Platform default-credential Zip-Slip to root RCE (IoT/MQTT infrastructure), Biamp Vocia MS-1 hardcoded FTPS credentials to root RCE (public-address/intercom infrastructure), and GigaSpaces XAP unauth path traversal to root RCE (in-memory data grid)
- Attack classes: zip-slip, path traversal, UNC DLL loading, command injection, expression injection, hardcoded credentials, authentication bypass, arbitrary file write