Skip to content

Batch #7 - August 2026 (10 advisories · 5 critical · 5 unauth)

Choose a tag to compare

@Exploit-Garbage Exploit-Garbage released this 22 Aug 14:48
· 2 commits to main since this release

Batch #7 — August 2026

10 advisories · 10 vendors · every advisory ships a full root-cause analysis + a working, reproducible PoC.

Seventh batch — expanding coverage into enterprise integration, distributed caching, telephony, configuration management, critical-communication infrastructure, project management, document scanning, ERP, reporting, and document management. Headline: Software AG webMethods MSR default-credential RCE via XSLT Xalan Java-extension abuse. Full writeups on https://0day-rubbish.com/blog; PoC code under product/<vendor>/<version>/<type>/exploit/.

# Product Affected Version CVSS Class Advisory & PoC
1 Software AG webMethods MSR 10.x 9.8 Default-creds XSLT Xalan Java-extension RCE XSLT Xalan ext → RCE
2 NCache Enterprise 5.3.6 9.8 Unauth Assembly.LoadFrom RCE via Web Manager Assembly.LoadFrom → RCE
3 Brekeke PBX 3.19.1.8 9.8 Unauth XmlTransBean Util.exec RCE XmlTransBean → RCE
4 CFEngine Enterprise Nova Hub 3.27.1 8.8 Auth VCS Settings Cmd Injection → Root gitServer → Root RCE
5 RTS Intercom VLink Virtual Matrix 6.60 8.8 Auth OpenSSL Arg Injection → SYSTEM openssl -engine → SYSTEM RCE
6 Inflectra SpiraTeam 9.3.0.0 8.8 Auth SQLi → xp_cmdshell RCE yAxisKey SQLi → RCE
7 Scan2x ScanWebClient 2.3.3.0 9.8 Unauth File Upload → Webshell RCE FileUploadHandler → RCE
8 Microsip ASD 2026 Eval 9.8 Unauth UNC Binary-Planting RCE gbak.exe planting → RCE
9 myDBR 7.5.4 8.8 Auth File-Editor PHP Code Injection fileedit_v → RCE
10 LogicalDOC Enterprise 9.3 8.8 Auth Automation Sandbox-Bypass RCE Velocity sandbox bypass → RCE

Highlights

  • 5 critical (CVSS ≥ 9.0) · 5 unauthenticated · 5 authenticated (deep-chain)
  • Headline: Software AG webMethods MSR — factory Administrator:manage credential + XSLT Xalan Java-extension abuse → arbitrary OS command execution as sagadmin; the IS fetches the attacker's stylesheet server-side (SSRF), so no local file write is needed.
  • Other unauth entries: NCache Enterprise Web Manager Assembly.LoadFrom of an uploaded DLL; Brekeke PBX reflective Util.exec; Scan2x upload → ASPX webshell; Microsip ASD UNC binary planting as LocalSystem.
  • Authenticated deep-chain entries: CFEngine Nova Hub VCS settings injection → root; RTS Intercom VLink OpenSSL argument injection → SYSTEM; SpiraTeam SQLi → xp_cmdshell; myDBR file-editor PHP injection; LogicalDOC Automation sandbox bypass.
  • Attack classes: missing authentication, XSLT extension abuse, reflection abuse, command injection, SQL injection, unsafe deserialization/loading, unrestricted upload, binary planting, sandbox bypass.

Totals

10 advisories · 10 vendors · 5 unauthenticated · 5 authenticated (deep-chain) · 4 system-level (root/SYSTEM/LocalSystem) · all with reproducible PoC.

Cumulative across 7 batches: 68 advisories.