important3 findings, 14 signals, 2 noted6 min read

Malformed key attributes can now carry a normal-world caller into OP-TEE kernel memory, while attackers are using an encoded-URI bypass to enter Cisco SD-WAN Manager as administrators.

Public exploit code also completes the Next.js ImageResponse path from attacker-controlled rendering input to native server execution.

Priority findings3
01
High
Boot chain
Confirmed

Malformed cryptographic attributes can corrupt OP-TEE secure-world kernel memory.

The PKCS#11 TA makes the driver path reachable from a normal-world client.

Affects

OP-TEE Core, the secure-world operating system used by embedded and mobile platforms, particularly builds using NXP CAAM; SE050 and Versal were listed as possibly affected, and follow-up review identified a HiSilicon HPRE path.

What it enables

Normal-world-triggered corruption of TEE-kernel stack or heap metadata

Attacker-controlled normal-world code opens a reachable Trusted Application such as the OP-TEE PKCS#11 TA→↓The client submits oversized cryptographic key attributes through the TEE Core API→↓Core validation permits inconsistent attribute sizes to reach a capacity-sensitive crypto backend→↓NXP CAAM right-aligns an oversized ECC value before its allocated buffer, or another backend copies oversized values into fixed-size storage→↓TEE-kernel stack or heap metadata is corrupted→↓Secure-world memory corruption is established, but repeatable control of OP-TEE kernel execution has not been demonstrated publicly.
Research leadExercise malformed key attributes through the PKCS#11 TA on CAAM and HiSilicon HPRE builds under secure-world instrumentation to determine whether overwritten metadata permits program-counter control.
Why this matters

Input accepted from a normal-world client crosses into secure-world kernel memory, and follow-up review found that the first repair did not cover another backend path.

Detail, proof-of-concept code and 2 sources
Required access

Normal-world client access to a Trusted Application accepting attacker-supplied cryptographic attributes; the PKCS#11 TA exposes the relevant Core APIs on affected configurations

Affected versions

>= 3.13.0

An attacker-controlled normal-world client can submit oversized RSA, DSA, DH, or ECC attributes through a reachable Trusted Application such as the PKCS#11 TA.

On NXP CAAM, an oversized ECC value is right-aligned before its allocated buffer after inconsistent sizing passes Core validation.

A September 28 follow-up identified analogous fixed-slot writes in HiSilicon HPRE, but that proposed repair closed on October 2 without merging.

Stack or heap corruption is established; repeatable control of secure-world kernel execution is not.

Evidence
The upstream advisory confirms that malformed attributes reach crypto drivers and corrupt stack or heap metadata from normal world through the PKCS#11 TA.TEE-kernel code execution was publicly demonstrated.The September 28 follow-up identified HiSilicon HPRE fixed-slot writes, but review exposed backend-specific representation problems and the PR was closed on October 2 without merging.
Share this finding
02
High
Zero-click / edge
Confirmed
CVE-2026-76504

Attackers are using a URI-encoding bypass to enter Cisco Catalyst SD-WAN Manager as administrators.

Encoding one character prevents the API authentication rule from matching the endpoint path.

Affects

Cisco Catalyst SD-WAN Manager, the management and orchestration component for Cisco SD-WAN deployments.

What it enables

Unauthenticated API access with administrator privileges

An unauthenticated attacker reaches the Manager API.→↓The attacker sends a crafted HTTP request with an encoded character in the authentication endpoint path.→↓The authentication rule fails to match the encoded URI.→↓The API grants access with administrator privileges.
Why this matters

This is an actively exploited failure of the administrative boundary around an enterprise SD-WAN control plane.

Detail and 2 sources
Required access

Network reachability to the Cisco Catalyst SD-WAN Manager API; internet-exposed on-premises managers are directly reachable

Affected versions

Earlier than 20.9, 20.9 before 20.9.10.1, 20.12 before 20.12.8.2, 20.15 before 20.15.6.1, 20.18 before 20.18.4.1, 26.1 before 26.1.2.1, 26.2 before 26.2.1, Cisco SD-WAN Cloud before 20.15.605

Any unauthenticated caller who can reach the Manager API can attempt the bypass.

The crafted URI misses the authentication rule and receives administrator-level API access.

Cisco confirms active exploitation and has published fixed releases.

Evidence
Cisco PSIRT advisory confirms the authentication bypass, administrator access, affected releases, fixes, and active exploitation
Share this finding
03
High
Research / RCE
Confirmed
CVE-2026-94545

Public exploit code turns a Next.js image-rendering injection into native server execution.

The demonstrated stack reaches execve through sharp and the official non-PIE Node.js Linux build.

Affects

Next.js applications using Node.js ImageResponse from next/og to generate server-side images.

What it enables

Unauthenticated code execution in the Next.js server context

Reach an affected public Open Graph or image-generation route.→↓Place attacker-controlled text in content, attributes, or styles consumed by ImageResponse.→↓Cause Satori to emit the value unescaped into SVG supplied to the native rasterizer.→↓Trigger native-parser memory corruption in the demonstrated sharp rendering stack.→↓Use the public non-PIE Node.js ROP chain to invoke execve in the server process.
Why this matters

Public exploit material closes the execution chain on a specified stack instead of leaving the consequence at native-parser corruption; only routes that feed attacker-controlled values to ImageResponse are exposed.

Detail, proof-of-concept code and 2 sources
Required access

Internet access to an affected application route that renders attacker-influenced values with next/og ImageResponse

Affected versions

Next.js 16.2.0 through 16.3.5 when using the affected Node.js ImageResponse path

Proof of concept

Public exploit code →

An attacker first needs a public route that renders attacker-influenced content, attributes, or styles through next/og ImageResponse.

Satori emits the value unescaped into SVG, sharp's native renderer is corrupted, and the published ROP chain invokes execve in the server process.

The vendor advisory identifies a fixed Next.js version for the affected ImageResponse path.

Evidence
The vendor advisory establishes the vulnerable ImageResponse path and fixed version.Public exploit material demonstrates command execution against Next.js 16.3.5, sharp 0.35.4, and the official non-PIE Node.js 24.20.0 Linux build.
Share this finding
Signals14
important · Research / RCE

RouterOS has a claimed pre-authentication WebFig-to-root path.

Affects

MikroTik RouterOS, the operating system used by MikroTik routers and network appliances.

The CNA material describes one unauthenticated HTTP request body triggering an integer underflow and root code execution on a reachable WebFig service.

Detail and 2 sources

MikroTik's public changelog did not list the reported 7.24 release when checked, so we cannot establish that the announced fix is shipping from that vendor material.

important · Edge / privilege

A portal-only WatchGuard SAML identity can enter the SSL VPN.

Affects

WatchGuard Fireware OS on Firebox network-security appliances providing Access Portal and Mobile VPN with SSL services.

The caller still needs valid SAML credentials, but those credentials may be assigned only to the Access Portal.

Detail and 3 sources
important · Firmware / Wi-Fi

A main-network peer can take over Xiaomi AX3000T administration; factory-state mesh setup adds a root path.

Affects

Xiaomi Router AX3000T, a consumer Wi-Fi 6 mesh router running MiWiFi/XiaoQiang firmware.

The firmware-global mesh key authenticates an arbitrary peer to cab_meshd, which discloses enough material to derive a valid administrator login response.

Detail and 3 sources
important · Mobile / research

One Wikipedia Android deep link can disclose the victim's Wikimedia session after a tap.

Affects

Wikipedia for Android, the Wikimedia Foundation's encyclopedia application on Android devices.

The app accepts an attacker hostname ending in wikipedia.org and repeats the suffix mistake when deciding where to send CentralAuth cookies.

Detail and 1 source

Those cookies permit authenticated Wikimedia API access as the victim.

The maintainer tested a correction, but the advisory does not identify a fixed application version.

important · Firmware

A mismatched DNS answer can make Zephyr copy a name beyond sockaddr storage.

Affects

Zephyr RTOS devices built with the native DNS resolver and affected networking code.

A PTR record returned for an A or AAAA query is accepted as NET_AF_LOCAL, and its name length becomes the address-copy length.

Detail and 2 sources

The result is an out-of-bounds copy, but we do not know whether it permits controlled corruption or execution on a shipping device.

The upstream change blocks the type mismatch, but affected and fixed release boundaries remain unestablished in the public record.

important · RCE / zero-click

Any web page can make a vulnerable SConnect installation load an unsigned DLL.

Affects

Thales SConnect, browser-to-native middleware used by electronic-identity, signing and financial-authentication products on Windows workstations.

A failed RSA operation leaves attacker-influenced data in an uninitialized verification buffer, bypassing the origin token and both package-signature layers.

Detail and 3 sources
important · Privilege — Windows

A local Windows user can make WatchGuard's endpoint driver disclose arbitrary kernel and process memory.

Affects

WatchGuard Endpoint Security protection software and its PSKMAD kernel driver on Windows workstations and servers.

Missing authentication in PSKMAD.sys lets a non-administrator bypass the driver's handshake and issue privileged memory-read commands.

Detail and 3 sources
important · Privilege

Two Divi Membership request paths let an unauthenticated visitor become or impersonate a WordPress administrator.

Affects

Divi Membership by Divi Engine, a membership and registration plugin for WordPress websites.

One registration handler trusts serialized form metadata that selects the Administrator role.

Detail and 5 sources
important · Edge / firmware

An adjacent unauthenticated caller can execute root commands across affected Digi DAL OS appliances.

Affects

Digi Accelerated Linux, the embedded operating system used across Digi cellular routers, gateways, console servers, USB device servers and industrial connectivity products.

A crafted POST reaches an operating-system command sink through the DAL OS web-administration interface; packet delivery on the adjacent network is required.

Detail and 3 sources
important · Firmware / Wi-Fi

One unauthenticated LAN request executes commands as root on a Netcore NAP930.

Affects

Netcore NAP930, a Wi-Fi 6 business access point running OpenWrt-derived embedded firmware.

The network_tools CGI evaluates the sid value before checking the session, so closing its quoted value appends a root shell command.

Detail and 2 sources
important · Zero-click

A WhatsApp sender can make a default OpenWA gateway issue blind requests to internal services.

Affects

OpenWA, a self-hosted WhatsApp API gateway that links WhatsApp sessions to server-side automation and integrations.

Sending media to the linked WhatsApp number is enough to reach the default-enabled fetch path.

Detail and 2 sources

Sender-controlled media metadata selects the destination, including internal and link-local addresses, although the response body remains blind.

OpenWA 0.24.0 restricts these media fetches to WhatsApp hosts.

important · Edge / RCE

Vibe-Trading's default API composes with its shell tools into unauthenticated root execution inside the container.

Affects

Vibe-Trading, a self-hosted LLM trading agent and FastAPI service commonly deployed in a Linux container.

Leaving API_AUTH_KEY unset disables authentication on the documented port 8899 deployment.

Detail and 3 sources
important · Edge / RCE

A normal ConvertX account can execute code by uploading a Calibre recipe.

Affects

ConvertX, a self-hosted online file-conversion service normally deployed as a Linux container.

ConvertX passed uploaded recipe files to ebook-convert, which treats them as executable Python.

Detail and 4 sources

Authentication is required by default, while ALLOW_UNAUTHENTICATED deployments expose a cheaper route.

The upstream fix rejects both executable recipe extensions before invoking ebook-convert.

important · Wi-Fi / edge

Two authenticated ASUS router-management paths permit operating-system command execution.

Affects

ASUS consumer routers running the vendor's embedded router firmware.

One path consumes uploaded management data as a format string; the other reaches active debug code that enables root Telnet access.

Detail and 5 sources
Also noted2
Privilege
An ordinary Active Directory user can recover BoKS-generated service-account passwords offline.
every source is a publisher ruled unable to originate; not published as a finding
ResearchCVE-2026-79901 - Vulnerability Details - OpenCVE
Privilege
Delegated BoKS CRL management can execute shell commands as root on the Master.
every source is a publisher ruled unable to originate; not published as a finding
ResearchCVE-2026-79898 - Vulnerability Details - OpenCVE
What was checked · 4 quiet
Boot chain & TPMQuiet

OP-TEE's normal-world-to-secure-world corruption family widened to another backend; no new universal Secure Boot bypass or signed-component revocation was established.

BluetoothQuiet

The recent RFCOMM change repairs a lock-order regression requiring a concurrent local connect and authentication; no new radio-only capability was established.

Physical accessQuiet

No recent event established a new physical-access capability or completed the open LUKS memory-acquisition chain.

ResearchQuiet

Public exploit code completed the Next.js renderer-to-execution chain; RouterOS root execution remains provisional, and the Wikipedia Android session-theft path was demonstrated.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, October 4, 2026