往事不回首,安全不停步。AiRedTeam 的安全随笔,记录那些与代码和漏洞博弈的深夜。代码为剑,漏洞为砺,守一方数字净土。以此笔墨,化作守望万物的白泽。

漏洞分析

CVE-2018-25332 (CVSS 9.8) - GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability

🔥 热门漏洞情报 · NVD-Latest · 2026-05-17 CVE-2018-25332 (CVSS 9.8) - GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability Critical · CVSS 9.8 不安全的反序列化与弱密钥组合漏洞 CVE-2018-25332 📋 漏洞概述 GitBucket 4.23.1 因弱密钥生成和文件上传缺陷,导致未认证远程代码执行漏洞。 📋 基础信息 受影响版本GitBucket <= 4.23.1 漏洞类型不安全的反序列化与弱密钥组合漏洞 CVSS9.8 · Critical CVECVE-2018-25332 🔬 漏洞根因 GitBucket 使用 Blowfish 加密算法保护会话和插件签名,但其密钥生成依赖于 Java
阅读时间 2 分钟
漏洞分析

CVE-2018-25320 (CVSS 9.8) - ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code executi

🔥 热门漏洞情报 · NVD-Latest · 2026-05-17 CVE-2018-25320 (CVSS 9.8) - ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code executi Critical · CVSS 9.8 命令注入 CVE-2018-25320 📋 漏洞概述 ACL Analytics 11.x至13.0.0.579版本EXECUTE函数存在命令注入漏洞,攻击者可远程执行任意命令获取系统控制权。 📋 基础信息 受影响版本ACL Analytics 11.x, 12.x, 13.0.0.579及之前版本 漏洞类型命令注入
阅读时间 3 分钟
安全情报

How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework

📡 GitHub Security Lab · 0 How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework CVE-2026-25757CVE-2026-25758CVE-2025-64487CVE-2026-28514 For the last few months, we’ve been using the GitHub Security Lab Taskflow Agent along with a new set of auditing taskflows that specialize in finding web security vulnerabilities. They
阅读时间 20 分钟
安全情报

When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446)

📡 watchTowr Labs · 0 When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446) CVE-2025-64446 When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446) The Internet is ablaze, and once again we all have a front-row seat - a bad person, if
阅读时间 6 分钟
安全情报

Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)

📡 watchTowr Labs · 0 Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691) CVE-2025-52691 Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691) Welcome to 2026! While we are all waiting for the scheduled SSLVPN ITW exploitation programming that occurs every January, we’
阅读时间 9 分钟
安全情报

Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)

📡 watchTowr Labs · 0 Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass) CVE-2025-52691 Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass) Well, well, well - look what we’re back with. You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability
阅读时间 7 分钟
安全情报

📊 2026-05-18 漏洞情报日报 · 200 条 · 高危 98

每日漏洞情报汇总 · 2026-05-18 📊 2026-05-18 漏洞情报日报 📋 共 200 条 🔥 高危/严重 98 条 💣 Exploit-DB-RSS 3 条 🐙 GitHub-Advisory 25 条 🔥16 🛡️ NVD-Latest 82 条 🔥82 ⚔️ Sploitus 90 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-8398 (CVSS 9.8) - DAEMON Tools Lite 供应链攻击:官方安装包被植入恶意代码,影响Windows版本12.5.0.2421至12.5.0.2434。攻击者通过合法分发渠道投放后门,用户安装即被控,利用条件极低,危害范围广。 * CVE-2018-25332 (CVSS
阅读时间 22 分钟
APT情报

cPanel & WHM认证绕过零日漏洞(CVE-2026-41940):互联网管理面板的“多米诺骨牌”倒塌

🔓 Critical 漏洞利用 安全研究人员发现cPanel & WHM所有受支持版本中存在一个严重的认证绕过漏洞(CVE-2026-41940),该漏洞源于会话加载与保存过程中的输入验证不完善,允许攻击者通过精心构造的会话数据绕过认证,获得服务器root级管理权限。已知Host已确认该漏洞在野外被积极利用,作为零日漏洞攻击互联网上大量共享托管基础设施。 来源:watchTowr Labs | 0 | 原文链接 🔍 关键发现 * 漏洞影响cPanel & WHM所有受支持版本(110.0.x至136.0.x),覆盖超过7000万个域名。 * 漏洞根源是saveSession函数中filter_sessiondata调用时机不当,导致CRLF注入和目录遍历等攻击向量可被利用。 * 补丁将filter_sessiondata调用移至saveSession内部,并引入了新的十六进制回传编码逻辑,以防御会话数据篡改。 * 会话文件结构分析显示,攻击者可通过伪造pass字段中的换行符注入恶意会话属性,从而提升权限或绕过认证。 ⚔️ 攻击链分析 1. 攻击者向cPane
阅读时间 2 分钟
APT情报

Progress ShareFile存储控制器曝高危漏洞链:未授权RCE风险

🔓 Critical 漏洞利用 研究者发现Progress ShareFile Storage Zone Controller 5.x版本中存在认证绕过(CVE-2026-2699)与远程代码执行(CVE-2026-2701)漏洞组合,攻击者可利用/ConfigService/Admin.aspx等端点绕过访问限制,进而执行任意代码。该漏洞链影响约3万个自托管实例,威胁文件传输安全。 来源:watchTowr Labs | 0 | 原文链接 🔍 关键发现 * CVE-2026-2699:/ConfigService/Admin.aspx端点存在认证绕过,可被远程利用获取管理访问权限 * CVE-2026-2701:结合认证绕过后,可在未授权状态下实现远程代码执行 * 漏洞影响ShareFile Storage Zone Controller 5.12.3及更早版本,5.12.4已修复 ⚔️ 攻击链分析 1. 攻击者远程访问/ConfigService/Admin.aspx端点,
阅读时间 1 分钟
漏洞分析

Exploit for CVE-2026-4882 exploit

🔥 热门漏洞情报 · Sploitus · 2026-05-16 Exploit for CVE-2026-4882 exploit Critical · CVSS 9.8 输入验证不当(推测) CVE-2026-4882 📋 漏洞概述 CVE-2026-4882被利用,该漏洞影响某未具体指明产品,可导致远程代码执行或数据泄露,危害严重。 📋 基础信息 受影响版本未公开具体产品与版本(根据漏洞编号推测为某企业级应用或中间件) 漏洞类型输入验证不当(推测) CVSS9.8 · Critical CVECVE-2026-4882 🔬 漏洞根因 根据现有公开信息有限,推测漏洞源于对用户输入的边界检查不严,导致攻击者能够传递恶意构造的数据包触发缓冲区溢出或逻辑错误。代码层可能未对参数长度、类型进行充分验证,使得攻击者可绕过预期控制流。在反序列化或解析特定协议字段时,未正确处理异常输入,从而引发内存破坏或执行任意代码。 🎯 攻击场景 1. 攻击者首先通过网络扫描定位正常运行中、且存在CVE-2026-4882漏洞的目标服务端
阅读时间 3 分钟
漏洞分析

Exploit for CVE-2026-6433 exploit

🔥 热门漏洞情报 · Sploitus · 2026-05-16 Exploit for CVE-2026-6433 exploit Critical · CVSS 9.8 输入验证不当(命令注入) CVE-2026-6433 📋 漏洞概述 CVE-2026-6433为Ollama中的高危远程代码执行漏洞,攻击者可利用特制请求在服务端执行任意命令。 📋 基础信息 受影响版本Ollama < 0.17.1 漏洞类型输入验证不当(命令注入) CVSS9.8 · Critical CVECVE-2026-6433 🔬 漏洞根因 漏洞源于Ollama在处理用户提供的模型名称或路径时,未充分过滤或转义特殊字符(如管道符、分号)。攻击者可通过构造包含shell元字符的字符串,导致底层API在拼接系统命令时(例如调用`ollama pull`或模型加载流程)发生命令注入。推测该缺陷位于模型启停或下载处理的参数解析逻辑中,由于直接拼接用户输入到system()或exec()调用而产生。 🎯 攻击场景 1. 信息收集: 攻击者发现目
阅读时间 3 分钟
漏洞分析

Exploit for CVE-2026-42897 exploit

🔥 热门漏洞情报 · Sploitus · 2026-05-15 Exploit for CVE-2026-42897 exploit Critical · CVSS 9.8 远程代码执行(RCE) CVE-2026-42897 📋 漏洞概述 CVE-2026-42897 为 Ollama 远程代码执行漏洞,攻击者可利用特制请求实现未授权 RCE。 📋 基础信息 受影响版本Ollama < 0.17.1 漏洞类型远程代码执行(RCE) CVSS9.8 · Critical CVECVE-2026-42897 🔬 漏洞根因 漏洞源于 Ollama API 对用户输入的模型名称或路径参数未进行充分验证与过滤。攻击者可以通过构造包含路径穿越或系统命令注入的恶意载荷,触发服务端执行非预期的系统调用。推测根本缺陷在于 API 处理 `create` 或 `pull` 接口时,将用户可控字符串直接拼接到命令行或文件操作中,导致命令注入或任意文件写入。 🎯 攻击场景
阅读时间 2 分钟
安全情报

Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)

📡 watchTowr Labs · 0 Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) CVE-2026-1340CVE-2026-1281 Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited
阅读时间 8 分钟
安全情报

The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)

📡 watchTowr Labs · 0 The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains) CVE-2025-24813CVE-2025-71260CVE-2025-71257CVE-2025-71258 The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains) SolarWinds. Ivanti. SysAid. ManageEngine. Giants of the KEV world, all of whom have ITSM side-projects. ITSMs,
阅读时间 19 分钟
安全情报

A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)

📡 watchTowr Labs · 0 A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE) CVE-2005-0469CVE-2026-32746CVE-2026-24061 A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE) A long, long time ago, in a land free of binary exploit mitigations, when Unix still roamed the
阅读时间 18 分钟
安全情报

You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)

📡 watchTowr Labs · 0 You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) CVE-2026-2701CVE-2026-2699 You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) If you squint and look at the CISA KEV list, you might think it&
阅读时间 18 分钟
安全情报

📊 2026-05-17 漏洞情报日报 · 200 条 · 高危 81

每日漏洞情报汇总 · 2026-05-17 📊 2026-05-17 漏洞情报日报 📋 共 200 条 🔥 高危/严重 81 条 🚨 CISA-KEV 1 条 💣 Exploit-DB-RSS 3 条 🐙 GitHub-Advisory 55 条 🔥30 🛡️ NVD-Latest 51 条 🔥51 ⚔️ Sploitus 90 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-8398 (CVSS 9.8) — DAEMON Tools Lite 供应链攻击:攻击者通过篡改官方安装包(版本12.5.0.2421~12.5.0.2434)植入恶意代码,影响大量Windows用户。无交互即可远程执行,
阅读时间 18 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)