The Magento and RouterOS paths are tied to observed attacks; Coder customers still have cached artifacts and incomplete credential revocation to address, while N-central Hotfix 3 is no longer sufficient.
Public GraphQL input reaches PHP execution through failed-payment reminder rendering.
Magento Open Source and Adobe Commerce, internet-facing e-commerce applications normally hosted on Linux servers.
Unauthenticated server-side code execution and persistent backdoor installation
This leads because the path is unpatched, already present in observed compromises and reproduced on clean 2.4.7 through 2.4.9 installations.
An anonymous caller sends attacker-controlled styles through GraphQL, causes Magento to write poisoned PHP into a failure-report or template input, and triggers the ordinary failed-payment reminder path to execute it.
Observed attacks installed a background implant and cron persistence. No vendor patch was available in the reviewed material, so unexplained failed-payment rendering and the documented persistence locations warrant incident review.
The path is reachable by an unauthenticated network caller on an affected self-hosted server.
N-able N-central, a remote monitoring and management server used by MSPs and IT teams to administer fleets of endpoints.
Unauthenticated remote code execution on an N-central management server
A second pre-authentication execution path after the prior emergency hotfix makes Hotfix 4 an immediate corrective action rather than routine patch maintenance.
Attacker-controlled input reaches statically saved code without proper directive neutralization, producing server-side execution before authentication.
Hotfix 4, not Hotfix 3, is the fixed release identified by the vendor. The available material does not establish whether servers reject older installable images.
Fetching a module during the exposure window was enough to run attacker code in the provisioner context.
Coder, self-hosted cloud-development-environment infrastructure whose Terraform modules execute in workspace provisioners
Execution of attacker-supplied Terraform modules in trusted Coder provisioning workflows and theft of provisioner, cloud, CI, SSH, OIDC and database credentials
This was an actual replacement of trusted provisioning artifacts, and correcting the registry origin did not remove cached modules or complete credential revocation.
The compromised key added attacker-controlled origin IPs to registry.coder.com. When Cloudflare routed a module request there, Terraform invoked an external-data script that searched the provisioner environment and configuration for cloud, CI, SSH, OIDC and database credentials.
Previously fetched modules can remain in caches, and credential revocation was incomplete at publication. Coder supplied malicious hashes, an invocation marker and detection queries for finding affected artifacts.
The purge-window lower bound is 25 minutes later than the incident start published in the advisory.
An exposed SSH listener is the only required access condition.
MikroTik RouterOS, the operating system used by MikroTik routers and network appliances
Unauthenticated full administrative control of internet-exposed RouterOS devices
CERT Polska confirmed takeovers of publicly reachable devices, turning two authentication defects into an observed credentialless administrator path.
Incomplete RSA-key comparison opens a session without the authorized private key; crafted username handling then changes the RouterOS policy mask to full administrator privileges. Observed operators created a privileged ops account and could add scripts, proxies and tunnels.
MikroTik fixed every maintained release channel and added boot-time compromise flagging. Pre-fix images remain accepted, so the fix does not prevent a device from returning to a vulnerable build.
Firefox for Android, Mozilla's mobile browser on Android devices
The official record requires network delivery and user interaction but no prior privilege, and assigns total confidentiality, integrity and availability impact.
Mozilla has not disclosed the trigger or resulting privilege, so we cannot distinguish a sandbox escape from a process- or Android-level escalation.
Firefox 155 contains the fix.
AMD XC7A200T Artix-7 FPGAs, with AMD assessing the same exposure in principle for other 7-Series and Zynq-7000 devices that decrypt bitstreams in programmable logic and reconfigure through ICAP
The demonstrated technique requires possession, unrestricted backside die access and failure-analysis-class optical equipment.
During partial reconfiguration, contactless probing observes plaintext crossing ICAP after the programmable logic decrypts it. AMD provides no software remedy.
QEMU virtual machines using the host-backed uefi-vars service with compatible OVMF firmware for Secure Boot
Access to the virtual firmware console is enough: OVMF permits CustomMode without the expected physical-presence check, then allows unrestricted Secure Boot-variable updates.
That permits removal or replacement of the VM's existing boot trust without QEMU-host access.
An upstream patch changes the default, but QEMU 11.1.1 predates it and a fixed release was not established.
A late-2022 i.MX 8M Plus hardware revision of the Lowrance HDS Live marine multifunction display running Navico NOS
With physical access, an attacker supplies a crafted microSD update. The signed outer updater selects an inner script without verifying its generated GPG signature.
The researcher used that gap to replace the root filesystem and execute code before most of the operating system starts. No vendor remediation was found.
MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.
A caller needs only network access to /jsproxy. A stale principal pointer supplies file authority, while encrypted parent-directory components escape WebFig's intended namespace.
The resulting read reaches root-owned configuration stores containing credentials.
MikroTik published a fix, but pre-fix RouterOS images remain accepted.
JupyterLab maintainer-tools, reusable GitHub Actions workflows used by software repositories to update pull-request snapshots.
After a maintainer approves a snapshot update, a contributor can push a malicious revision within the same one-second timestamp interval. The action treats it as unchanged and checks it out as the approved revision.
The checked-out code inherits the consuming job's secrets and authority. GitHub Security Lab tested the sequence against jupyter/notebook.
A patched action release exists, but consuming workflows can continue referencing the vulnerable release.
Lowrance and Simrad marine multifunction displays running Navico NOS; demonstrated on Lowrance HDS Live
Brief access to a powered display's SD slot begins a chain through a file-manager symlink escape, writable dynamic QML, file-scheme XMLHttpRequest and a privileged language-pack traversal.
The demonstrated result is arbitrary root write and lasting root code execution. No vendor acknowledgment or patch was found.
WWBN AVideo, a self-hosted web platform for publishing and streaming video.
The CNA says an anonymous caller can supply the hash parameter to videoViewsInfo and receive user records containing password hashes, recovery tokens and live session identifiers.
Replaying an administrator's live identifier reportedly inherits the administrator session, but no public reproduction or upstream fix was located.
TP-Link Archer AX55 V4, a consumer Wi-Fi router running embedded firmware.
After capturing an administrator's HTTP login on the LAN, the observer can use a device-wide RSA-1024 private key and weakened AES session key to decrypt and reuse the password.
Firmware 1.2.1 Build 20260527 fixes the login flaw.
TP-Link Archer AX55 V4, a consumer Wi-Fi router running embedded firmware.
With Mesh mode enabled, crafted LAN input reaches a stack overflow and crashes the easymesh daemon.
The vendor describes code execution as possible, but the held evidence does not establish controlled execution.
Firmware 1.2.1 Build 20260527 fixes the overflow.
OPC UA Local Discovery Server, discovery infrastructure installed as Windows services on industrial and engineering systems.
The path exists only while an administrator runs a vulnerable installer elevated and someone has physical access to its keyboard and display.
The pre-1.04.420 installer exposes an interactive elevated console that accepts the person's commands.
OPC UA LDS 1.04.420 addresses the issue.
Tenda CP3, an embedded Wi-Fi security camera running Tenda firmware.
The record names CAutoAddWifi::ThreadProc in the Kylin component as the command-injection sink.
It does not identify the protocol, endpoint, attacker-controlled field, process privilege, or whether the path is LAN-only, cloud-relayed or internet-exposed.
No newly demonstrated Bluetooth capability survived; the recent BlueZ and Unitree items changed documentation or remediation evidence only.
No new receipt-only execution chain was established; the missing August Android vulnerability tables still prevent a complete component-level accounting.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.