Separately, September’s emergency NetScaler fixes did not eliminate a repeatable SAML outage path that Citrix says is under targeted attack.
The method needs possession of the watch, disassembly and a connection to its USB test pads.
Samsung Galaxy Watch FE and Watch 4, 5, and 6 families running Wear OS, using Exynos W920 or W930 SoCs.
Passcode recovery and decrypted application-data extraction
A stolen locked watch can no longer be assumed to keep its application data confidential once an equipped examiner reaches the board.
Passware’s commercial tool exploits an undisclosed vulnerability in the Exynos W920 and W930 system-on-chips to acquire protected material.
It then performs GPU-accelerated passcode recovery and uses the recovered passcode to decrypt application data.
The reviewed announcement and device catalog do not identify a remediation for affected watches.
Citrix reports targeted attacks, and CISA has added the flaw to its exploited-vulnerability catalog.
Customer-managed NetScaler ADC and NetScaler Gateway appliances providing application delivery, AAA and remote-access VPN services.
Unauthenticated persistent denial of service against SAML authentication gateways
An unauthenticated client can still repeatedly crash SAML-enabled NetScaler gateways after the emergency fixes, and Citrix reports attacks against unmitigated deployments.
An unauthenticated client can reach the memory-overflow path on a Gateway or AAA virtual server where NetScaler acts as a SAML service provider or identity provider, then repeat the trigger to keep the service unavailable.
Citrix has not identified an integrity impact, and reports calling the flaw remote code execution remain unconfirmed.
The EOL finding concerns patch availability; public vendor material does not confirm whether CVE-2026-88779 affects the EOL branches.
Fortinet FortiMail, a physical, virtual and cloud-deployed secure email gateway.
A crafted HTTP or HTTPS request combines path traversal with NULL-byte handling to write or replace files outside the intended path.
Observed compromises included attacker-added binaries, ld.so.preload modification and root cron activity.
A patch was announced, but current release availability could not be resolved from the retrieved vendor material.
Today’s change is the confirmed scope: the arbitrary-file-write primitive is now connected to persistence and command execution using root-level mechanisms.
OP-TEE Core, a trusted execution environment commonly used on Arm-based embedded and Linux systems.
The path requires local userspace access to the OP-TEE device interface and a build with CFG_ATTESTATION_PTA enabled.
A verifier can accept the valid device signature as a false claim about OP-TEE or a trusted application.
OP-TEE has published a patch for the shared-buffer race.
Armatura One, a Windows-hosted platform managing doors, elevators, visitors, parking, video, and other building-security functions.
A crafted OpenWire command causes attacker-selected object-graph deserialization before authentication, executing code with the service’s highest operating-system privilege.
Fixed versions and public attack code are available.
Dogtag PKI enterprise certificate-authority services on Linux, including affected Red Hat Certificate System and RHEL deployments.
The path applies to an EST fullcmc endpoint using HTTP Basic authentication and requires only valid EST user credentials.
Without an end-user TLS certificate, a stale subsystem-agent certificate causes downstream authorization to treat the request as agent-privileged.
Deployments that enforce mutual TLS are not susceptible to this path.
Dahua IPC and SD-series embedded network and PTZ cameras.
The demonstration establishes execution control beyond the original advisory’s emphasis on disruption and exploit-protection assumptions.
Firmware updates are published for affected Dahua families.
Apache HTTP Server 2.4 installations using mod_ssl and permitting lower-privileged users or hosting tenants to author .htaccess files.
A tenant who can write .htaccess rules in an eligible mod_ssl directory can still invoke file functions with the httpd process’s filesystem authority.
Apache identifies 2.4.69 as the release that adds the omitted restriction.
AhsayCBS, a self-hosted enterprise backup-management and replication server for Windows and Unix-like systems.
A network client can submit a crafted random parameter to UpdateReceivers.do over the Replication Receiver HTTP or HTTPS service, commonly on port 80 or 443.
We could not verify the cited exploit or determine the resulting process identity on Windows and Linux from a primary publication.
Rejetto HFS, a self-hosted HTTP file server for Windows, Linux, macOS, FreeBSD and Android.
The attacker needs a network-reachable HFS 3.x server and a login-enabled username available through the documented enumeration oracle.
Consecutive Math.random outputs reveal recoverable xorshift128+ state, which yields the startup signing key used to forge an administrator session.
HFS 3.2.1 is published as the fixed release.
Today’s change is the complete root cause and execution chain, accompanied by observed exploitation.
Digi Accelerated Linux, the embedded operating system used by Digi cellular routers, console servers, USB-over-IP devices and IoT gateways.
The administration service is LAN-only by default but can become WAN-reachable when reconfigured.
A crafted unauthenticated HTTP POST injects a command that runs with root privileges.
Today’s change is the recovery gap: affected devices still accept pre-fix images, preserving a route back to vulnerable code after an update.
Moxa MGate 3000 and 5000 Series industrial protocol gateways connecting serial and industrial protocols to Ethernet networks.
The path requires high-privilege credentials and access to the gateway’s firmware-update interface.
Improper signature verification permits installation of a crafted image, and its unauthorized changes can persist across subsequent firmware updates.
Maestro, a cross-platform desktop application for controlling AI coding agents and terminals.
Live Mode binds an HTTP and WebSocket control server to 0.0.0.0, embeds bearer tokens in URLs and exposes a terminal-capable API.
A fixed version is published, but the fix itself was not inspected for this brief.
Teledyne FLIR Aware2 software used by PackBot and FirstLook unmanned ground robots.
A remote client can read arbitrary files through the Aware2 web service, including stored credentials and operational configuration.
Mandiant claims complete compromise and remote code execution, but the public material does not disclose the transition from file reading to execution.
Updated software is published, but the fix itself was not inspected for this brief.
InternLM MindSearch, a Python-based AI search-agent application commonly exposed through a web service.
ExecutionAction.run strips optional Markdown fencing and passes its command argument directly to Python exec with server globals and locals.
The CNA record says a remote planner request reaches that sink, but the end-to-end dataflow from a stock unauthenticated request was not reproduced.
MediaTek cellular modems used across phones, tablets, automotive systems and other embedded devices built on the listed chipsets.
Crafted cellular input reaches one of two parsing paths with a missing bounds check, producing an out-of-bounds write in privileged modem firmware.
MediaTek has announced a fix, but we could not retrieve the bulletin body, so the complete chipset matrix and device-level delivery status remain unresolved.
No additional findings today.
Current BlueZ items remain crash-only in experimental or paired/local workflows, while kernel activity propagates older fixes.
Recent ASUS, Buffalo and Wireshark items repeat known capabilities; inaccessible hostap diffs leave two peer-triggered questions unresolved.
Two MediaTek modem write primitives are reachable after attachment to a rogue cellular base station; Android bulletin coverage remains incomplete.
The MediaTek modem findings are the sole new mobile capability delta; full platform-bulletin coverage remains unavailable.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.