Check Point also confirmed worldwide exploitation of a pre-authentication certificate flaw that reaches code execution on VPN gateways.
Public source code and an APK reproduce the cross-application FileObserver path without requesting Android permissions.
Android applications using FileObserver, demonstrated against WhatsApp media stored through Android shared storage.
Cross-application observation of private media activity, filenames and timing
The change is reachability: metadata about another application's private activity is available to ordinary permissionless code.
The attacker watches WhatsApp shared-media directories that scoped storage otherwise prevents it from listing, then receives filenames, event types and timing when WhatsApp opens, closes, moves or deletes files.
Those events are enough to infer whether private media was sent, received or deleted and to identify its filename and media type.
Check Point Security Gateway and Spark Firewall, VPN and firewall appliances deployed at enterprise and small-business network edges.
Unauthenticated code execution on a security gateway
Check Point confirmed worldwide exploitation attempts against a VPN certificate-validation flaw that permits pre-authentication gateway code execution. An attacker needs network reachability to the affected remote-access VPN negotiation service and does not need to authenticate.
The path requires network reachability to the affected remote-access VPN negotiation service but no authentication.
Check Point has published a fix, but pre-fix images remain accepted and complete revocation has not been established.
R81.10 later received a corrective Jumbo Hotfix, but affected R81 remains uncovered; therefore EOL coverage is only partial.
Apple macOS and its CoreWLAN framework on Mac computers.
CoreWLAN exposes profile properties containing BSSIDs, association times, coordinates, accuracy values and timestamps through ordinary getters and key-value coding.
Talos confirmed the path on macOS 26.3.1 and reports that Apple fixed it in macOS 27.
Foxit PDF Reader, a Windows desktop PDF viewer with a privileged updater.
The path requires victim interaction, but FoxitUpdater then accepts content without properly validating the update server certificate and consumes it in its privileged context.
Foxit identifies the affected Reader versions and a fixed release.
Microsoft SharePoint Server 2016, 2019 and Subscription Edition, on-premises collaboration servers running on Windows.
CISA marked the vulnerability as actively exploited on September 25, and Microsoft has published fixes for supported affected versions.
WordPress Core, the PHP content-management system used by self-hosted websites.
The complete chain depends on an affected theme layout and a readable local execution target such as pearcmd.php, which can turn local inclusion into an attacker-controlled PHP write.
GitLab.com and GitLab self-managed installations with incoming email enabled; GitLab is a source-code hosting and CI/CD platform.
The embedded token acts across projects as the victim account, the mail path does not verify the sender, and changing the suffix to merge-request permits a Git patch and branch name to be submitted.
The researcher demonstrated a push to main and CI execution in an IP-allowlisted private project; GitLab's documentation and interface changes did not remove the underlying authority.
Salesforce Agentforce, a cloud AI-agent platform connected to CRM records and optionally deployed into Slack workspaces.
A stored prompt submitted through Web-to-Lead can run during routine review, query other CRM tables with the employee's permissions and move values through attacker-controlled DNS without a click.
The affected Slack action could also post links as the agent without confirmation or initiator attribution; Salesforce patched the demonstrated chains.
Norwegian Cruise Line shipboard door-access controllers using NTAG212 credentials; exact controller models and firmware builds were not disclosed.
The controller treats the seven-byte UID as the sole credential, so a copied or emulated value is accepted as the original card.
CERT/CC reports failed vendor coordination and no shipped remediation.
U-Boot, an embedded bootloader used across ARM and other embedded systems.
The available record says additional validation patches followed the original fixes, but it does not establish memory corruption on current upstream U-Boot.
OpenCode, a cross-platform AI coding agent with an optional local HTTP web interface.
The browser submits cross-origin text/plain JSON to the loopback upgrade endpoint, which accepts the attacker's tarball as the package target.
The upstream advisory publishes the complete proof of concept, Datadog demonstrated it against version 1.18.21, and the merged fix limits targets to semantic versions while restoring typed JSON decoding.
DJI Neo, Flip, Air, Avata, Mavic and Mini consumer aircraft using DJI Fly and QuickTransfer.
The demonstrated command set reaches Wi-Fi and radio configuration, storage operations, resets, wipes, reboot and power-off without pairing or a trusted UUID.
It does not establish that replacing the Wi-Fi credential grants flight-control authority.
Foxit PDF Reader, a Windows desktop PDF viewer with a privileged updater.
The three paths are insecurely permissioned resources, DLL loading from a user-writable directory and a download-and-extraction substitution race.
Foxit identifies the affected updater paths and the fixed Reader release.
DJI Neo, Flip, Air, Avata, Mavic and Mini consumer aircraft using DJI Fly and QuickTransfer.
The public parser recovers the aircraft SSID, persistent PSK and trusted-client UUID from captured ATT traffic without pairing or prior trust.
We do not know which internal management or flight-control services accept those values without another authorization secret.
Rapid7 Insight Agent, an endpoint telemetry and assessment agent installed on Windows systems.
The assessment content invokes an unqualified command from the SYSTEM agent, allowing Windows path resolution to select a low-privilege user's planted executable.
Rapid7 fixed and automatically distributes the corrected content, but did not identify the earliest affected build.
PHP-FPM, the FastCGI process manager used by PHP web servers, when listening on IPv6 TCP and relying on listen.allowed_clients.
The client check compares only 12 address bytes, silently widening an exact IPv6 entry to every source sharing its first 96 bits.
The reporter demonstrated the bypass against a real php-fpm process, and PHP lists fixed releases dated September 24.
Dokku, a self-hosted Docker-based platform-as-a-service running on Linux servers.
An app-scoped user who may set Docker options can store command substitution that Bash eval expands during a build, deployment or run operation.
Dokku identifies the affected range and a fixed release.
fetchmail, a Unix mail-retrieval and forwarding client that may run interactively or as a system daemon.
The maintainer now says code execution may be possible on some builds, but reliable instruction-pointer control remains compiler-, ABI-, layout- and hardening-dependent.
Fetchmail 6.6.7 fixes the overflow and withdraws the earlier non-exploitability conclusion.
IBM PowerVM Hypervisor firmware on listed IBM Power 9, Power 10, and Power 11 servers.
IBM attributes the disclosure to an out-of-bounds read but does not identify the protocol, listening service or returned data.
IBM identifies corrected firmware branches.
Apache Doris, a distributed analytical database whose Java Frontend coordinates metadata, queries and cluster operations.
Apache establishes the Frontend execution boundary but does not publish the minimum required permission, precise URL form or fixed release.
PaperCut Hive Embedded Application for Ricoh, the cloud print-management client embedded in Ricoh multifunction printers.
The demonstrated boundary ends at JavaScript inside the embedded browser sandbox; the vendor does not identify reachable browser bridges, data or unauthorized actions.
PaperCut identifies version 2.3.0 as the corrected release.
The consequential changes were the Android cross-application side channel and confirmed exploitation of the Check Point VPN, SharePoint and WordPress execution paths.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.