Batch #7 - August 2026 (10 advisories · 5 critical · 5 unauth)
·
2 commits
to main
since this release
Batch #7 — August 2026
10 advisories · 10 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.
Seventh batch — expanding coverage into enterprise integration, distributed caching, telephony, configuration management, critical-communication infrastructure, project management, document scanning, ERP, reporting, and document management. Headline: Software AG webMethods MSR default-credential RCE via XSLT Xalan Java-extension abuse. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.
| # | Product | Affected Version | CVSS | Class | Advisory & PoC |
|---|---|---|---|---|---|
| 1 | Software AG webMethods MSR | 10.x | 9.8 | Default-creds XSLT Xalan Java-extension RCE | XSLT Xalan ext → RCE |
| 2 | NCache Enterprise | 5.3.6 | 9.8 | Unauth Assembly.LoadFrom RCE via Web Manager | Assembly.LoadFrom → RCE |
| 3 | Brekeke PBX | 3.19.1.8 | 9.8 | Unauth XmlTransBean Util.exec RCE | XmlTransBean → RCE |
| 4 | CFEngine Enterprise Nova Hub | 3.27.1 | 8.8 | Auth VCS Settings Cmd Injection → Root | gitServer → Root RCE |
| 5 | RTS Intercom VLink Virtual Matrix | 6.60 | 8.8 | Auth OpenSSL Arg Injection → SYSTEM | openssl -engine → SYSTEM RCE |
| 6 | Inflectra SpiraTeam | 9.3.0.0 | 8.8 | Auth SQLi → xp_cmdshell RCE | yAxisKey SQLi → RCE |
| 7 | Scan2x ScanWebClient | 2.3.3.0 | 9.8 | Unauth File Upload → Webshell RCE | FileUploadHandler → RCE |
| 8 | Microsip ASD | 2026 Eval | 9.8 | Unauth UNC Binary-Planting RCE | gbak.exe planting → RCE |
| 9 | myDBR | 7.5.4 | 8.8 | Auth File-Editor PHP Code Injection | fileedit_v → RCE |
| 10 | LogicalDOC Enterprise | 9.3 | 8.8 | Auth Automation Sandbox-Bypass RCE | Velocity sandbox bypass → RCE |
Highlights
- 5 critical (CVSS ≥ 9.0) · 5 unauthenticated · 5 authenticated (deep-chain)
- Headline: Software AG webMethods MSR — factory
Administrator:managecredential + XSLT Xalan Java-extension abuse → arbitrary OS command execution assagadmin; the IS fetches the attacker's stylesheet server-side (SSRF), so no local file write is needed. - Other unauth entries: NCache Enterprise Web Manager
Assembly.LoadFromof an uploaded DLL; Brekeke PBX reflectiveUtil.exec; Scan2x upload → ASPX webshell; Microsip ASD UNC binary planting as LocalSystem. - Authenticated deep-chain entries: CFEngine Nova Hub VCS settings injection → root; RTS Intercom VLink OpenSSL argument injection → SYSTEM; SpiraTeam SQLi → xp_cmdshell; myDBR file-editor PHP injection; LogicalDOC Automation sandbox bypass.
- Attack classes: missing authentication, XSLT extension abuse, reflection abuse, command injection, SQL injection, unsafe deserialization/loading, unrestricted upload, binary planting, sandbox bypass.
Totals
10 advisories · 10 vendors · 5 unauthenticated · 5 authenticated (deep-chain) · 4 system-level (root/SYSTEM/LocalSystem) · all with reproducible PoC.
Cumulative across 7 batches: 68 advisories.