The Chrome outcome remains undisclosed, while the NetScaler and Nexus paths require no credentials once their affected services are reachable.
The affected Redirect-binding path defeats the default unsigned-assertion policy.
Customer-managed NetScaler ADC and NetScaler Gateway appliances exposing SAML-authenticated Gateway or AAA virtual servers.
Unauthenticated session forgery on a SAML-configured NetScaler Gateway or AAA virtual server
This is a code-backed authentication bypass: a reachable SAML endpoint can construct a session from attacker-controlled assertion fields without a signed assertion.
The caller collects the pre-authentication redirect values, sends an attacker-built unsigned assertion to /cgi/samlauth, and receives a session after the parser clears strict signature enforcement.
Public code performs the forgery. Citrix has fixed builds, but pre-fix images remain accepted; matching probes do not yet establish successful compromise.
The fixed implementation is proprietary and no fixed-binary diff establishing broader legacy coverage was available; definite conclusions are therefore limited to the documented downgrade behavior.
The exposed Silicon One services listen on TCP/43210 and TCP/43211 in the default Layer 3 VRF.
Cisco Nexus 9000 switches containing Cisco Silicon One ASICs and running NX-OS in standalone mode.
Unauthenticated command execution as root on a network switch
The established outcome is direct root execution from routed service reachability, not merely disruption of the switch.
A peer that can route to a locally configured switch address sends crafted input to the Silicon One Hardware Abstraction Layer service, which executes it with root privileges.
Cisco has published fixes, but exact version checks require its interactive Software Checker, no public reproducer is available, and pre-fix images remain accepted.
The pre-fix-image answer is an inference from Cisco’s documented downgrade support; Cisco’s advisory does not describe an anti-rollback change.
Cisco IOS XR Software, the embedded network operating system used by Cisco carrier and service-provider routers.
Seven grouped CVEs span several defect classes, but Cisco does not map individual defects to services, starting positions, or concrete outcomes.
WHMCS, a self-hosted billing and web-hosting automation application commonly deployed on Internet-facing servers.
WHMCS says a forged payload can reach executable server-side processing without an account or user interaction and compromise the installation.
A fix has shipped, but the path has no public technical reproduction or exploit code.
MikroTik RouterOS, the operating system used by MikroTik routers and CHR virtual routers.
The public exploit uses incomplete PKCS#1 v1.5 verification to construct a valid checked prefix, but it needs the exact exponent-3 key authorized for the account.
The forgery works against RouterOS 7.23.3 and is rejected by 7.23.4.
SAUTER modulo 6 and EY-modulo 5 building-automation controllers used to operate building systems.
The race replaces an update after validation but before use.
We do not know its practical LAN or WAN exposure or the privilege of the installed code.
ASUS Control Center Enterprise, an on-premises system for centrally managing servers, PCs and workstations.
The request discloses an encryption key that composes with SSRF and embedded credentials to enable SSH on TCP/2222 and supply a root login.
The available advisory material does not identify a fixed version.
Alephium TokenBridge's hosted watcher, full-node, and guardian infrastructure connecting Alephium with Ethereum and BNB Chain.
The fallback path accepted a crafted bridge-formatted event without normal validation, producing guardian signatures that could withdraw collateral and mint unbacked wALPH.
Alephium reports that the chain was used and has published a fix.
Cudy WR3000 2.0 Wi-Fi routers and P5 5G routers running the affected OpenWrt-derived firmware.
A forged JWT reaches the plaintext MQTT broker, and the consuming command handler passes attacker input to a root shell.
We do not know whether a network-only peer can derive the required device identifier or which P5 versions are affected.
PowerJob, a Java distributed job-scheduling and computing framework whose server and worker components commonly run in containers on Linux.
The server turns a selected Spring bean method into Groovy evaluation, while the worker downloads an attacker-selected JAR and initializes its Spring context.
Public exploits demonstrate execution, and no maintainer fix is established.
GeoNetwork, a self-hosted geospatial metadata catalog commonly deployed as an agency or government geoportal, including its official Docker image.
An unprotected upload stores an attacker formatter, after which Saxon evaluates its Java extension functions without secure-processing restrictions.
A working chain and packet capture were reported, exploitation is recorded from September 3, and fixes are available.
Nango's self-hosted integration-automation runner, which executes customer integration code in Linux containers or Kubernetes pods.
The scope excludes Nango Cloud and runners isolated from untrusted peers.
Release 0.71.6 adds verification, but its authentication switch defaults to false, leaving an unchanged image deployment fail-open.
SonicWall Network Security Manager On-Prem, the Linux-based control plane used to centrally administer SonicWall security infrastructure.
Missing authorization reaches SuperAdmin, which exposes a separate operating-system command-injection path; an existing delegated account is required.
A fixed release boundary is published, but no public reproducer or exploitation evidence is established.
MikroTik RouterOS, the operating system used by MikroTik routers and CHR virtual routers.
The path depends on an authentication backend accepting the literal username, after which PTY bytes replace fields carried through a trusted file descriptor.
Public code demonstrates full-policy writes, while RouterOS 7.23.4 rejects the username before the vulnerable child starts.
The Linux kernel XFS filesystem when its experimental exchange_range feature is enabled.
The exploit requires the experimental exchange_range feature and abuses a cleared reflink flag so writes to a clone land on the privileged source file's shared blocks.
The completed chain overwrites /etc/passwd, and upstream identifies fixed stable releases.
MikroTik RouterOS, the operating system used by MikroTik routers and CHR virtual routers; exploit control was demonstrated on x86 CHR.
A test-policy account invokes /tool fetch with an overlong TFTP pathname, overwriting saved EIP and the post-return stack.
The public ROP proof demonstrates a controlled unlink call through a fixed PLT address.
TP-Link Archer AX55 v4, a consumer Wi-Fi router running embedded firmware.
The observer must capture an actual HTTP login, then uses a shared RSA private key and weakened AES session key to decrypt the reusable password.
TP-Link has published a fix, but no public exploit implementation is established.
BlueZ, the Linux Bluetooth userspace stack and system bluetoothd daemon, when LE Audio uses linked media transports.
A replaced owner can retain a disconnect watch and transport pointer after the transport is freed, causing its later disconnect callback to dereference freed memory.
We do not know whether a client can deterministically reuse the allocation and influence callback-reachable data.
TP-Link Archer AX55 v4, a consumer Wi-Fi router running embedded firmware with optional EasyMesh mode.
The demonstrated path requires LAN reachability and Mesh mode, then triggers a stack overflow that terminates the daemon.
The public material does not establish execution control, daemon privilege, or mitigation behavior.
Google Chrome, the web browser on Android and desktop operating systems.
The established path begins when Chrome loads attacker-controlled web content and reaches the V8 type confusion tracked as CVE-2026-85046.
Google has published a fix. We still do not know what the exploit gains after corruption or whether it requires a separate sandbox escape.
Three public RouterOS paths broke SSH possession, read-only policy, and native-execution assumptions under narrow prerequisites.
No new zero-click capability was confirmed; the missing August Android vulnerability table prevents a complete quiet finding.
The U-Boot USB result stops at out-of-bounds reads; no new disk-encryption, Secure Boot, TPM, or locked-device bypass was established.
The exploited Chrome V8 flaw reaches Android through the Chrome application; no separate mobile-platform primitive was confirmed.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.