[{"id":"cve-2026-18963-keycloak-26-7-1-reset-credentials-authen-20260902-185418","ps_url":"https://packetstorm.news/files/id/230204","title":"Keycloak 26.7.1 Reset Credentials Authentication Bypass","cve":"CVE-2026-18963","ps_type":"remote","platform":"","author":"EQSTLab","pub_date":"2026-09-01","priority_score":null,"legitimacy_score":6,"exploit_quality":"functional","target_software":"Keycloak prior to 26.7.2 (reset credentials flow)","target_popularity":"high","network_traffic":true,"ai_generated":false,"ai_signals":null,"exploit_language":"unknown","notable_techniques":["auth_bypass","account_takeover"],"verdict":"exploit","timestamp":"2026-09-02T18:54:18Z","activity_at":"2026-09-02T19:02:27Z","activity_kind":"re-triaged","legitimacy_reason":"No exploit source is available to inspect, but the described flow (bypassing the reset-action-token check to reach the password update form) is a plausible, specific auth-logic flaw consistent with prior real Keycloak CVEs in this exact subsystem, and the description reads as a concrete technical account rather than vague marketing.","target_popularity_reason":"Keycloak is a widely deployed open-source identity and access management platform used by many enterprises and embedded in numerous products.","triage_url":"https://ips-pktstrm-pocs.pages.dev/#/report/cve-2026-18963-keycloak-26-7-1-reset-credentials-authen-20260902-185418","cvss_score":9.1,"cvss_severity":"CRITICAL","cvss_version":"3.1"},{"id":"cve-2026-27475-spip-4-4-8-insecure-deserialization-20260902-185418","ps_url":"https://packetstorm.news/files/id/230243","title":"SPIP 4.4.8 Insecure Deserialization","cve":"CVE-2026-27475","ps_type":"remote","platform":"","author":"Dorian Piette","pub_date":"2026-09-01","priority_score":null,"legitimacy_score":7,"exploit_quality":"partial","target_software":"SPIP 4.4.0 through 4.4.8","target_popularity":"medium","network_traffic":true,"ai_generated":false,"ai_signals":null,"exploit_language":"php","notable_techniques":["deserialization","auth_bypass","rce"],"verdict":"exploit","timestamp":"2026-09-02T18:54:18Z","activity_at":"2026-09-02T19:02:27Z","activity_kind":"re-triaged","legitimacy_reason":"Provides a concrete, working exploit primitive \u2014 a real serialized PHP payload (O:13:\"ExploitGadget\") triggered via a genuine SPIP admin URL parameter, with a precise __destruct gadget that writes a webshell to IMG/rce.php, though it relies on a self-crafted \"vulnerable plugin\" gadget class rather than a class already present in stock SPIP.","target_popularity_reason":"SPIP is a widely used CMS in French-speaking government/media sites but has far smaller global market share than WordPress or Drupal.","triage_url":"https://ips-pktstrm-pocs.pages.dev/#/report/cve-2026-27475-spip-4-4-8-insecure-deserialization-20260902-185418","cvss_score":8.1,"cvss_severity":"HIGH","cvss_version":"3.1"},{"id":"cve-2026-39987-marimo-0-22-x-remote-code-execution-20260902-185418","ps_url":"https://packetstorm.news/files/id/230351","title":"Marimo 0.22.x Remote Code Execution","cve":"CVE-2026-39987","ps_type":"remote","platform":"","author":"Ghxstsec","pub_date":"2026-09-02","priority_score":null,"legitimacy_score":5,"exploit_quality":"functional","target_software":"Marimo notebook server versions prior to 0.23.0 (0.22.x)","target_popularity":"medium","network_traffic":true,"ai_generated":false,"ai_signals":null,"exploit_language":"unknown","notable_techniques":["auth_bypass","rce"],"verdict":"skip_suspect","timestamp":"2026-09-02T18:54:18Z","activity_at":"2026-09-02T19:02:27Z","activity_kind":"re-triaged","legitimacy_reason":"No exploit source was available to inspect; scoring is based solely on the metadata, which describes a plausible and specific vulnerability class (unauthenticated WebSocket PTY access) but cannot be verified for actual working exploit code.","target_popularity_reason":"Marimo is a growing reactive Python notebook tool popular in the data science community but with a much smaller install base than Jupyter or mainstream enterprise software.","triage_url":"https://ips-pktstrm-pocs.pages.dev/#/report/cve-2026-39987-marimo-0-22-x-remote-code-execution-20260902-185418","cvss_score":9.8,"cvss_severity":"CRITICAL","cvss_version":"3.1"},{"id":"cve-2026-40179-prometheus-3-5-1-cross-site-scripting-20260902-185418","ps_url":"https://packetstorm.news/files/id/230232","title":"Prometheus 3.5.1 Cross Site Scripting","cve":"CVE-2026-40179","ps_type":"exploit","platform":"","author":"bsdrip","pub_date":"2026-09-01","priority_score":null,"legitimacy_score":6,"exploit_quality":"partial","target_software":"Prometheus 3.0.0 through 3.5.1","target_popularity":"high","network_traffic":true,"ai_generated":false,"ai_signals":null,"exploit_language":"javascript","notable_techniques":["stored_xss","injection"],"verdict":"exploit","timestamp":"2026-09-02T18:54:18Z","activity_at":"2026-09-02T19:02:27Z","activity_kind":"re-triaged","legitimacy_reason":"No local exploit file was available to inspect, but the description is technically specific (metric name/label escaping flaw exploitable via remote_write) which is plausible given Prometheus's known history of web UI XSS issues, so the score is based on metadata credibility alone.","target_popularity_reason":"Prometheus is a widely deployed monitoring/metrics system used extensively across cloud-native and enterprise infrastructure.","triage_url":"https://ips-pktstrm-pocs.pages.dev/#/report/cve-2026-40179-prometheus-3-5-1-cross-site-scripting-20260902-185418","cvss_score":6.1,"cvss_severity":"MEDIUM","cvss_version":"3.1"},{"id":"cve-2026-48558-simplehelp-oidc-authentication-bypass-re-20260902-185418","ps_url":"https://packetstorm.news/files/id/230355","title":"SimpleHelp OIDC Authentication Bypass / Remote Code Execution","cve":"CVE-2026-48558","ps_type":"remote","platform":"","author":"Zach Hanley","pub_date":"2026-09-02","priority_score":null,"legitimacy_score":9,"exploit_quality":"functional","target_software":"SimpleHelp 5.5.0 through 5.5.15 (and some SimpleHelp 6.0 prerelease builds before 6.0 RC2)","target_popularity":"medium","network_traffic":true,"ai_generated":false,"ai_signals":null,"exploit_language":"ruby","notable_techniques":["auth_bypass","jwt_forgery","rce","websocket_protocol_abuse"],"verdict":"exploit","timestamp":"2026-09-02T18:54:18Z","activity_at":"2026-09-02T19:02:27Z","activity_kind":"re-triaged","legitimacy_reason":"Fully realized Metasploit module with a real check() method that fingerprints SimpleHelp version via /allversions, forges an OIDC 'alg: none' id_token to create a technician session, then implements the full SimpleHelp WebSocket protocol (plane codes, transaction wrappers, terminal handshake) to open a remote terminal and execute the payload.","target_popularity_reason":"SimpleHelp is a widely used remote support/RMM tool among MSPs (and was previously abused in real ransomware intrusion chains), but it has a far smaller install base than mainstream platforms like Apache, Windows, or Exchange.","triage_url":"https://ips-pktstrm-pocs.pages.dev/#/report/cve-2026-48558-simplehelp-oidc-authentication-bypass-re-20260902-185418","cvss_score":10.0,"cvss_severity":"CRITICAL","cvss_version":"3.1"},{"id":"cve-2026-5027-langflow-1-8-4-remote-code-execution-20260902-185418","ps_url":"https://packetstorm.news/files/id/230320","title":"Langflow 1.8.4 Remote Code Execution","cve":"CVE-2026-5027","ps_type":"remote","platform":"","author":"Richard Howe","pub_date":"2026-09-02","priority_score":null,"legitimacy_score":6,"exploit_quality":"functional","target_software":"Langflow 1.8.4","target_popularity":"medium","network_traffic":true,"ai_generated":false,"ai_signals":null,"exploit_language":"unknown","notable_techniques":["path_traversal","arbitrary_file_upload","rce","auth_bypass"],"verdict":"exploit","timestamp":"2026-09-02T18:54:18Z","activity_at":"2026-09-02T19:02:27Z","activity_kind":"re-triaged","legitimacy_reason":"No source file was available to inspect, but the metadata describes a specific, technically coherent chain (authenticated path traversal in file upload leading to a malicious MCP server config write and RCE) consistent with prior real Langflow file-upload/path-traversal advisories, so it is scored from description credibility alone.","target_popularity_reason":"Langflow is a fast-growing open-source visual LLM/agent workflow builder with a sizable developer user base, though it is less widely deployed than major enterprise infrastructure software.","triage_url":"https://ips-pktstrm-pocs.pages.dev/#/report/cve-2026-5027-langflow-1-8-4-remote-code-execution-20260902-185418","cvss_score":8.8,"cvss_severity":"HIGH","cvss_version":"3.1"},{"id":"cve-2026-75855-arcadedb-26-8-0-path-traversal-20260902-185418","ps_url":"https://packetstorm.news/files/id/230201","title":"ArcadeDB 26.8.0 Path Traversal","cve":"CVE-2026-75855","ps_type":"exploit","platform":"","author":"Pervin Zahidli","pub_date":"2026-09-01","priority_score":null,"legitimacy_score":8,"exploit_quality":"functional","target_software":"ArcadeDB 26.8.0 (ArcadeData/arcadedb @ commit 545e703)","target_popularity":"medium","network_traffic":true,"ai_generated":false,"ai_signals":null,"exploit_language":"bash","notable_techniques":["path_traversal","arbitrary_file_write","arbitrary_file_delete","denial_of_service","auth_required"],"verdict":"exploit","timestamp":"2026-09-02T18:54:18Z","activity_at":"2026-09-02T19:02:27Z","activity_kind":"re-triaged","legitimacy_reason":"The advisory cites exact vulnerable source lines (PostServerCommandHandler.java, ArcadeDBServer.java:572), explains the raw string concatenation with no normalization/containment check, and provides working curl PoC commands with concrete verified output (file listings, list databases response) for both create and drop database traversal.","target_popularity_reason":"ArcadeDB is a multi-model database with a real but comparatively small user base next to mainstream databases like MySQL or Postgres, so deployment breadth is moderate.","triage_url":"https://ips-pktstrm-pocs.pages.dev/#/report/cve-2026-75855-arcadedb-26-8-0-path-traversal-20260902-185418","cvss_score":8.7,"cvss_severity":"HIGH","cvss_version":"3.1"},{"id":"cve-2026-82592-d-link-dir-825m-1-1-8-formdiskformat-buf-20260902-185418","ps_url":"https://packetstorm.news/files/id/230254","title":"D-Link DIR-825M 1.1.8 formDiskFormat Buffer Overflow","cve":"CVE-2026-82592","ps_type":"remote","platform":"","author":"HackSpeak","pub_date":"2026-09-01","priority_score":null,"legitimacy_score":5,"exploit_quality":"partial","target_software":"D-Link DIR-825M firmware 1.1.8","target_popularity":"medium","network_traffic":true,"ai_generated":false,"ai_signals":null,"exploit_language":"unknown","notable_techniques":["buffer_overflow","auth_bypass"],"verdict":"skip_suspect","timestamp":"2026-09-02T18:54:18Z","activity_at":"2026-09-02T19:02:27Z","activity_kind":"re-triaged","legitimacy_reason":"No exploit source is available to verify; the metadata describes a specific, plausible endpoint (/boafrm/formDiskFormat) and parameter (partition) consistent with the well-documented pattern of stack overflows in D-Link boafrm CGI handlers, but there is no way to confirm an actual working PoC exists.","target_popularity_reason":"D-Link DIR-825M is a consumer home router; D-Link as a vendor has broad install base but this specific older/regional model has a narrower deployment footprint than flagship enterprise or widely-deployed consumer products.","triage_url":"https://ips-pktstrm-pocs.pages.dev/#/report/cve-2026-82592-d-link-dir-825m-1-1-8-formdiskformat-buf-20260902-185418","cvss_score":9.9,"cvss_severity":"CRITICAL","cvss_version":"3.1"}]