CVE-2026-61511 - Draft or Todo
Unprivileged user to root via CUPS logic flaw — macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.
A poc for a vulnerability in ZTE File Manager (zte.com.cn.filer) which allows to read arbitrary files from other apps as the privileges of this file manager
CVE-2026-43499: Linux kernel futex PI use-after-free research package
Threat Intelligence Investigation
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.
A POC for the recently discovered Qualys bug on COW with XFS
authz research - CVE-2026-3306 fix coverage
CVE-2026-63030 + CVE-2026-60137+poc
CVE-2026-4861 - Draft or Todo
Slidev presentation for Certighost (CVE-2026-54121), with Mermaid diagrams and exported assets.
Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)
Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)
Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)
Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)
Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)
Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)
Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.