The Linux route still lacks a public reproduction, while the appliance chains already end in reverse-shell or root control.
Network reachability to the CAPWAP control service on UDP/5246 is the prerequisite.
FortiOS firewall appliances and FortiSwitchManager network-management appliances.
Unauthenticated code execution and interactive appliance control
This leads ahead of the higher-ranked Bluetooth disclosure because operators have already converted the FortiGate flaw into reverse-shell control, while the Bluetooth paths have no public reproduction.
A crafted Image Data message turns the cw_acd heap overflow into an arbitrary eight-byte write, which the observed exploit converts into an execvp pivot and Node.js reverse shell.
The installed PivotC2 implant supports shell access, tunneling, scanning, and configuration theft.
HTTP reachability to the management interface is enough to reach the vulnerable path.
Cisco Secure Firewall Management Center, the on-premises management appliance for Cisco firewalls, and the affected Cisco Security Cloud Control firewall-management service.
Unauthenticated command execution as root on firewall-management infrastructure
Although ranked below the Bluetooth disclosure, it leads because exploitation is active, reaches root on the firewall-management plane, and has already produced several post-compromise toolsets; the Bluetooth elevation paths remain unreproduced.
A boot-created system process exposes an alternate route from crafted unauthenticated web requests to root-capable script execution.
Cisco observed web shells, Cyclops Blink, credential harvesting, tunnels, and ransomware staging across three intrusion clusters.
Cisco has published fixes, and CISA added the flaw to its exploited-vulnerability catalog on September 9.
The public materials do not expose the hotfix diff or package contents, so the image-acceptance and revocation questions could not be resolved beyond unknown.
Microsoft Windows 10, Windows 11, and Windows Server systems containing the built-in Bluetooth service or port driver.
Microsoft identified three use-after-free conditions and two race or double-free conditions in the Bluetooth Service and Port Driver.
The paths start from low-privileged local code and do not have an identified radio-proximity or interaction requirement.
Microsoft published affected and fixed builds, but no public proof of concept or independent reproduction was found.
ChatGPT, OpenAI’s hosted conversational agent and connected-app platform.
A shared Artifactory property channel carried a hidden task into the victim's account and returned results after one ordinary message caused ChatGPT to invoke the victim's connected tools.
The demonstrated task retrieved data from the victim's connected Gmail account.
OpenAI decommissioned the implicated internal Artifactory instance.
Palo Alto Networks GlobalProtect, the enterprise VPN and endpoint-access client for Windows, macOS, and Linux.
A non-administrative user influences a search path consumed by a privileged component, which resolves attacker-controlled content as SYSTEM on Windows or root on macOS and Linux.
Only the 6.2 Windows and macOS fixes were already available on September 10; several other platform or release fixes still had future dates.
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, PHP e-commerce storefronts commonly hosted on Linux servers.
An anonymous /graphql request injects styles data that poisons template output, and a failed-payment email path executes the injected PHP.
Sansec reproduced the complete chain on clean Magento Open Source 2.4.7, 2.4.8, and 2.4.9 installations.
Adobe shipped a hotfix.
Check Point Quantum Security Gateway, Quantum Security Management Server, and Spark Firewall network-security appliances.
The primitives are a certificate trust-validation failure and a heap overflow in VPN-certificate ASN.1 decoding.
Affected VPN or certificate-processing services are sufficient access, including negotiation exposed on UDP/500 or UDP/4500.
Check Point reports internal discovery and no active exploitation.
N-able N-central, remote monitoring and management servers used by MSPs to administer customer endpoints.
Network reachability to an affected on-premises N-central server is the only established prerequisite.
Compromise lands beside N-central's script, deployment, and remote-session functions, but public evidence does not show whether attackers used them against managed endpoints.
Microsoft Windows 10, Windows 11, and Windows Server systems whose NTFS driver processes attacker-supplied storage
Physical attachment through an accepted storage interface can reach three NTFS heap overflows without credentials or user interaction.
We do not know the malformed structures or final instruction-control mechanics.
SAP NetWeaver Kernel infrastructure underlying ABAP-based SAP systems, including S/4HANA and ABAP Platform deployments.
A crafted packet to public port 36NN asserts trusted-node status, propagates that decision to application servers, and enables RFC-callable external programs to run as the SAP operating-system account.
SAP published remediated patch levels in Security Note 3759472.
libheif, the HEIF/AVIF library used by Linux desktop image loaders and server-side image-processing pipelines.
About 45,000 distinct dimg references evade the cycle and finished-item checks until the pre-decode recursive walk exhausts the process stack.
Libheif 1.23.4 replaces the recursive walk with an explicit heap worklist.
Skullcandy Dime 3, consumer true-wireless earbuds running embedded Airoha Bluetooth firmware.
Within Bluetooth Classic range, an attacker can create a stored NoInputNoOutput bond while the earbuds are not in pairing mode, then reconnect for audio takeover and microphone access.
A fixed build exists, but no owner-accessible upgrade path for deployed units was established.
The Linux kernel IPv6 multicast-routing subsystem on Linux hosts.
An unresolved multicast packet can retain a route destination beyond RCU protection; after the route is deleted, a wrong-parent resolution makes ip6mr_cache_report clone the freed destination.
The upstream fix addresses that sequence, but we do not have a public exploit, a reliability demonstration, or a complete affected stable-version matrix.
HP-specific InsydeH2O code exposed a privileged-local-to-SMM path; the broader OpenSSL mapping still lacks preboot reachability.
FortiGate exploitation and persistent Skullcandy Dime 3 microphone access supplied the material firmware changes.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.