[{"id":"cve-2026-16232-check-point-smartconsole-authentication--20260826-234705","ps_url":"https://packetstorm.news/files/id/229557","title":"Check Point SmartConsole Authentication Bypass / Remote Code Execution","cve":"CVE-2026-16232","ps_type":"local","platform":"","author":"sfewer-r7","pub_date":"2026-08-25","priority_score":null,"legitimacy_score":8,"exploit_quality":"functional","target_software":"Check Point SmartConsole / Security Management Server / Multi-Domain Security Management Server (CVE-2026-16232)","target_popularity":"high","network_traffic":true,"exploit_language":"ruby","notable_techniques":["auth_bypass","rce","certificate_impersonation"],"verdict":"exploit","timestamp":"2026-08-26T23:47:05Z","activity_at":"2026-08-26T23:47:05Z","activity_kind":"triaged","pipeline_candidate":true,"pipeline_candidate_reason":"","legitimacy_reason":"Authored by sfewer-r7, a known Rapid7/Metasploit researcher, with a highly specific technical description referencing the FWM/CPMI service, SIC distinguished name replay, and application certificate bind vulnerability. The mechanism described \u2014 replaying the server's own SIC DN to bypass authentication \u2014 is a precise and credible exploit primitive consistent with real Check Point architecture.","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_version":"3.1"},{"id":"cve-2026-5281-chromium-cve-2026-5281-cve-2026-11057-ex-20260826-234705","ps_url":"https://packetstorm.news/files/id/229689","title":"Chromium CVE-2026-5281 / CVE-2026-11057 Exploit Chain","cve":"CVE-2026-5281","ps_type":"remote","platform":"","author":"Jafork","pub_date":"2026-08-26","priority_score":null,"legitimacy_score":7,"exploit_quality":"partial","target_software":"Chromium (Chrome/Edge/Android WebView) \u2014 Dawn WebGPU wire server and Skia graphics, Android ARM64","target_popularity":"high","network_traffic":true,"exploit_language":"unknown","notable_techniques":["use_after_free","aslr_bypass","heap_disclosure","fake_object","rce"],"verdict":"exploit","timestamp":"2026-08-26T23:47:05Z","activity_at":"2026-08-26T23:47:05Z","activity_kind":"triaged","pipeline_candidate":true,"pipeline_candidate_reason":"Chromium is a high-popularity target deployed on billions of devices; the exploit is typed 'remote' implying network interaction; and the legitimacy score of 7 reflects a credible, technically specific chain description matching known Chromium attack surfaces.","legitimacy_reason":"The metadata describes a highly specific, technically credible exploit chain: a Dawn wire server use-after-free (CVE-2026-5281) combined with a GPU-process heap disclosure via Skia (CVE-2026-11057) for ASLR bypass, culminating in a controlled indirect branch on Android ARM64. The named subsystems (Dawn wire server, GPU process, Skia) are real Chromium components, and the responsible-disclosure framing (stopping at PC control, omitting full shellcode) is consistent with legitimate PoC publication. No file was available to verify actual implementation quality.","cvss_score":8.8,"cvss_severity":"HIGH","cvss_version":"3.1"},{"id":"cve-2026-66066-ruby-on-rails-active-storage-vips-arbitr-20260826-234705","ps_url":"https://packetstorm.news/files/id/229555","title":"Ruby on Rails Active Storage Vips Arbitrary File Read / Remote Code Execution","cve":"CVE-2026-66066","ps_type":"local","platform":"","author":"castilho","pub_date":"2026-08-25","priority_score":null,"legitimacy_score":8,"exploit_quality":"functional","target_software":"Ruby on Rails Active Storage with Vips variant processor (CVE-2026-66066)","target_popularity":"high","network_traffic":true,"exploit_language":"ruby","notable_techniques":["arbitrary_file_read","deserialization","rce","secret_key_extraction","image_format_abuse"],"verdict":"exploit","timestamp":"2026-08-26T23:47:05Z","activity_at":"2026-08-26T23:47:05Z","activity_kind":"triaged","pipeline_candidate":true,"pipeline_candidate_reason":"","legitimacy_reason":"This is a Metasploit module with a detailed, coherent multi-stage exploit chain: crafted HDF5/MATLAB v7.3 image triggers arbitrary file read via Vips processing, secret_key_base is recovered from multiple Rails secret sources, and a forged serializer-compatible payload achieves RCE \u2014 this attack pattern (file-read-to-deserialization via Rails session forgery) is well-established and the description is highly specific. CVE-2026-66066 is consistent with publication date of 2026-08-25.","cvss_score":9.5,"cvss_severity":"CRITICAL","cvss_version":"4.0"}]