important2 findings, 15 signals5 min read

RouterOS accepted forged TLS certificates, while Artifactory’s blank default join key let anonymous callers mint administrator tokens.

The RouterOS route requires traffic redirection and a public trusted-root certificate; the Artifactory route requires only network reachability to an instance retaining the shipped blank key.

Priority findings2
01
High
Edge — RouterOS
Confirmed
CVE-2026-67278

An on-path attacker can forge certificates that RouterOS accepts for any TLS server.

The attack needs control or redirection of a RouterOS-initiated TLS connection and the public certificate of a trusted RSA root using exponent 3.

Affects

MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.

What it enables

Impersonation of arbitrary TLS servers to RouterOS without a trusted CA private key

Obtain an on-path or traffic-redirection position for a RouterOS-initiated TLS connectionUse the public certificate of an e=3 root already present in the RouterOS trust storeForge a certificate chain exploiting incomplete PKCS#1 v1.5 signature validationPresent a certificate for an attacker-chosen server nameRouterOS accepts the attacker as the intended TLS server
Why this matters

This removes trusted-authority authentication from every outbound TLS service that relies on the affected RouterOS certificate check.

Detail and 3 sources
Required access

Control or redirection of an outbound TLS connection initiated by an affected RouterOS device

Affected versions

6.0.0 before 6.49.21, 7.0.0 before 7.23.4, 7.24 before 7.24.2

Proof of concept

Demonstrated by the researcher

CERT Polska validated the certificate-forgery behavior on real RouterOS systems.

Incomplete PKCS#1 v1.5 validation lets the attacker forge a chain under the trusted root, name an arbitrary server, and have RouterOS accept it as the intended peer.

Fixed release ranges are public and complete revocation on updated supported systems; pre-fix images still accept the forged chains, and the fixes do not reach end-of-life hardware.

Evidence
CERT Polska identifies the trusted e=3 root, incomplete RSA/PKCS#1 v1.5 validation, and arbitrary-name certificate consequenceCERT Polska reports validation of the findings on real RouterOS systemsFixed RouterOS release ranges are publicly available
Share this finding
02
High
RCE — Artifactory
Confirmed
CVE-2026-82329

Artifactory’s blank default join key lets an anonymous network caller mint a platform-administrator token.

The Access service accepts attacker-authored HS256 join claims and returns a non-expiring administrator token.

Affects

JFrog Artifactory, a self-hosted artifact repository and CI/CD package control plane.

What it enables

Unauthenticated platform-administrator takeover

Reach the self-hosted Artifactory Access API without credentials.Sign chosen join claims with the known default additional join-key value.Submit the forged JWT to /access/api/v1/registry/join.Receive a non-expiring service token carrying administrator scope.Use the token to enumerate users, reset the built-in administrator password, mint further tokens, or modify repositories and artifacts.
Why this matters

We move this above the higher-ranked HPE scope expansion because a shipped default turns anonymous network reachability into administrator access, with runnable code confirming the complete path.

Detail and 2 sources
Required access

Unauthenticated network reachability to a self-hosted Artifactory instance

Affected versions

7.111.4–7.111.20, 7.117.0–7.117.27, 7.125.0–7.125.19, 7.133.0–7.133.28, 7.146.0–7.146.36, 7.161.0–7.161.19

Proof of concept

Public exploit code

An attacker signs chosen join claims with the public blank key, submits them to the registry join endpoint, and receives administrator scope without authenticating.

That token can reset the built-in administrator password, mint more tokens, and modify repositories or artifacts.

The request sequence has been reproduced, and JFrog has published a fixed-version matrix.

Evidence
Pruva verified reproduction with runnable request sequenceJFrog vendor advisory and fixed-version matrix
Share this finding
Signals15
important · Boot chain

HPE mapped TPM attestation-forgery and RSA secret-recovery flaws into its server line.

Affects

HPE Alletra, Apollo, Edgeline, MicroServer, ProLiant Gen10, Gen10 Plus and Gen11, and Synergy systems using affected Intel CSME or SPS firmware.

The paths require privileged local access to the TPM command interface: object-slot reuse can expose key-certification credentials, while RSA-OAEP timing leaks information about managed ciphertexts.

Detail and 5 sources
important · Mobile — MediaTek

A local caller can reach a heap overwrite in MediaTek’s video decoder.

Affects

MediaTek chipset video-decoder firmware and drivers used across Android mobile devices and other embedded products.

The vendor establishes a local out-of-bounds write but does not identify the calling API or precisely describe the caller’s starting privilege.

Detail and 4 sources

We do not know whether browser, messenger, or media-framework input can reach the decoder without an existing local foothold.

Chain to watch
Deliver malformed media through a browser, messenger, or Android media frameworkReach the affected MediaTek vdec pathTrigger the heap overwrite from a remote delivery pathRemote media reachability without prior local execution is not established.
Unverified chainTest malformed samples through major Android media routes on representative affected chipsets.
important · RCE — Nacos

Nacos 3.x exposes administrator-equivalent account creation and configuration control on its server port.

Affects

Nacos 3.x, a service-discovery and configuration-management control plane used by distributed applications.

Misclassified management controllers inherit open-API handling and a separately disabled-by-default authentication switch.

Detail and 4 sources
important · Edge — RouterOS

Unauthenticated WebFig callers can read root-owned RouterOS files and recover configuration credentials.

Affects

MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.

The stale authorization pointer and encrypted-URI traversal were already tracked; today’s change establishes their reach into root-owned, credential-bearing configuration files.

Detail and 3 sources

WebFig must be reachable, with WAN exposure determined by firewall configuration; pre-fix images remain accepted, and fixes do not reach end-of-life hardware.

important · Mobile — MediaTek

A rogue cellular base station can crash affected MediaTek modems without user interaction.

Affects

Phones and other connected devices using the affected MediaTek modem chipsets and firmware

The target must connect to the attacker-controlled base station, after which malformed modem input reaches one of two missing bounds checks and a system crash.

Detail and 3 sources
important · Edge — OpenStack

Authenticated Glance users can turn image imports into full-read requests against metadata and internal services.

Affects

OpenStack Glance, the image-management service used by private and public OpenStack clouds.

Weak destination filtering, DNS-rebinding gaps, and an unfiltered HTTP image store let an authorized importer select an internal resource.

Detail and 2 sources
important · Edge — Langflow

Attackers are using Langflow’s public validator to execute as root and probe cloud and API secrets.

Affects

Langflow, a self-hosted Python platform for building and deploying AI agents and workflows, commonly run in Linux containers.

An Internet-reachable validate endpoint executes unauthenticated Python supplied through its code parameter.

Detail and 6 sources
important · Physical — Windows

A signed PassMark driver lets a standard Windows user read physical memory and chain hardware primitives to SYSTEM.

Affects

PassMark PerformanceTest, BurnInTest and OSForensics, Windows benchmarking, stress-testing and forensic utilities that install a signed kernel helper driver.

The vulnerable driver must be loaded and its device obtainable, but its permissive ACL then exposes physical-memory, MSR, PCI, I/O-port, and privileged-file operations.

Detail and 10 sources
important · Zero-click

A crafted HEIF auxiliary-image graph can crash libheif during decoding.

Affects

libheif, the cross-platform HEIF and AVIF decoding library used by image applications and server-side processors.

An unsupported auxiliary item receives a null context that verify_decodable dereferences when a consumer traverses or decodes it.

Detail and 4 sources

Upstream published a complete regression-file generator, but released-version scope and receipt-only reachability remain unverified.

Chain to watch
Deliver a crafted HEIF file to a default consumerCause automatic auxiliary-image traversalTerminate the receiving or indexing processReceipt-only behavior in mail clients, thumbnailers, chat clients, indexers, and upload processors is not established.
Unverified chainRun the regression-file generator through default desktop thumbnailers and common inline-attachment paths.
important · Edge — SAML

A self-signed SAML response can impersonate any identity accepted by MojoX::Authentication.

Affects

MojoX::Authentication, a Perl authentication library used by Mojolicious applications for local and SAML2 login.

The parser lacked a configured trust anchor, so an attacker could sign an assertion naming the target account and have it checked against the certificate embedded in that response.

Detail and 2 sources
important · Firmware — D-Link

Internet exploitation attempts now target an unpatched command-injection path on end-of-life D-Link DIR-882 routers.

Affects

D-Link DIR-882 wireless routers running end-of-life embedded firmware.

An anonymous request stores shell syntax in an NVRAM field that the router later concatenates into a twsystem command.

Detail and 3 sources

The evidence is ten honeypot connections recorded as attempts; it does not establish successful compromise or execution as root.

The product is end of life and will receive no fix.

Chain to watch
Reach an Internet-exposed DIR-882 management serviceStore shell syntax through SetSysLogSettingsObserve whether the later command executes successfully and as which userSuccessful compromise and root execution are not established by the available telemetry.
Unverified chainObtain a successful capture or reproduce a benign identity command on stock hardware.
important · RCE — JimuReport

JimuReport 2.5.1’s no-login export path turns a forged fixed-key signature into server-side command execution.

Affects

JimuReport, a Java/Spring Boot web-based reporting and dashboard server.

A caller needs a valid report identifier but no account, then uses the hard-coded signing secret to reach Aviator evaluation and escape its sandbox.

Detail and 2 sources
important · Firmware — Tenda

A public request demonstrates unauthenticated command injection on the current Tenda HG10 firmware.

Affects

Tenda HG10 GPON optical-network terminals and routers running embedded firmware.

From the LAN, an anonymous caller can place shell syntax in fmgpon_loid; the published benign payload powers off the appliance.

Detail and 2 sources

We do not know whether the route is WAN-reachable or which operating-system identity executes the command.

Chain to watch
Reach the HG10 Boa serviceSubmit shell syntax through fmgpon_loidDetermine the executing identity and whether remote management exposes the routeWAN exposure and the command’s operating-system identity remain unknown.
Unverified chainTest stock firmware with default and remote-management configurations using a benign identity command.
important · Firmware — FreeIPMI

A malicious BMC can overwrite a FreeIPMI management client’s stack during a routine FRU read.

Affects

FreeIPMI management clients on Linux and Unix hosts used to query server baseboard-management controllers.

A compromised BMC returns more FRU bytes than requested, and the client copies them beyond a fixed-size stack buffer when an administrator reads inventory.

Detail and 3 sources

Controlled execution remains unproved; FreeIPMI 1.6.19’s announcement says it fixes stack overflows caused by nonconforming BMC responses.

Chain to watch
Compromise a BMC queried by an affected clientReturn an oversized FRU responseConvert the stack overwrite into controlled instruction flowArbitrary code execution and the affected client process identity remain unverified.
Unverified chainReproduce a benign control-flow proof against a pre-1.6.19 client and record its hardening and process identity.
important · Boot chain

Three additional HPE server generations may expose data retained after UEFI execution.

Affects

HPE Alletra, Apollo, Edgeline, ProLiant, and Synergy servers; HPE's September revision added Gen11, Gen10 Plus, and Gen10 systems to the previously listed Gen12 scope.

HPE added Gen10, Gen10 Plus, and Gen11 systems to the affected scope, but access already requires privileged local system software and additional conditions.

Detail and 2 sources

The public material does not identify the retained buffer, the exposed data, or the operation used to retrieve it.

Chain to watch
Obtain privileged local access on an affected HPE serverReach the incomplete UEFI cleanup pathIdentify what retained data crosses into the subsequent contextThe stale region, exposed data, and retrieval operation are unspecified.
Unverified chainObtain technical root-cause material or reproduce the issue on a listed model and inspect the retained region.
Also noted0

No additional findings today.

What was checked · 4 quiet
BluetoothQuiet

No cheaper access path, demonstrated consequence, wider affected scope, fix bypass, or exploitation emerged from the Bluetooth work.

Wi-FiQuiet

No new Wi-Fi access path, consequence, affected scope, fix bypass, or exploitation was established.

Physical accessQuiet

PassMark’s signed driver exposed physical-memory and kernel-control operations to a standard Windows user when the device is available.

ResearchQuiet

RouterOS certificate forgery and root-file disclosure were demonstrated, and Langflow exploitation moved into observed secret probing.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026