Posts of last 24 hours
A vulnerability classified as critical was found in droundy arrayref 0.3.10. The impacted element is an unknown function. Such manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-77651. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/394017
A vulnerability classified as critical has been found in droundy append-only-vec 0.1.9. The affected element is an unknown function. This manipulation causes inclusion of functionality from untrusted control sphere.
This vulnerability is registered as CVE-2026-77650. Remote exploitation of the attack is possible. No exploit is available.
https://vuldb.com/vuln/394016
整理 Fastjson1 全版本利用要点——反序列化流程、版本/依赖/期望类探测、WAF 绕过,以及 1.2.47 / 68 / 80 / 83 关键绕过与各利用链;并附配套工具,方便复习与落地。
https://xz.aliyun.com/news/92638
A vulnerability described as critical has been identified in droundy Internment 0.8.7. Impacted is an unknown function. The manipulation results in code injection.
This vulnerability is cataloged as CVE-2026-77649. The attack may be launched remotely. There is no exploit available.
https://vuldb.com/vuln/394015
A vulnerability marked as problematic has been reported in Apple watchOS up to 26.3. This issue affects some unknown processing. The manipulation leads to permission issues.
This vulnerability is listed as CVE-2026-43679. The attack must be carried out locally. There is no available exploit.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/394014
一个公开的 Form 端点,5 步走完整条攻击链:任意文件读取 → 读 encryptionKey → 伪造 JWT 接管 admin → 表达式注入沙箱逃逸 → RCE。从发第一个 POST 到拿到 root,不到 3 秒。本文基于 n8n 1.65.0 真实复现,附完整攻击脚本与检测工具,所有 PoC 已开源。
https://xz.aliyun.com/news/92554
本文详细复现了 Fastjson 1.2.66 ~ 1.2.83 版本中的远程代码执行(RCE)漏洞(CVSS 9.8),涵盖 JDK 8、17、21、25 全版本。
https://xz.aliyun.com/news/92583
本文深入探讨了Pwn的底层机制,详细梳理了x86/x64寄存器、汇编堆栈帧(push、pop、leave、ret)的执行流变化。在此基础上,系统剖析了ROP(返回导向编程)的核心原理与实战变种(如ret2libc、ret2syscall、栈迁移、32位传参特性),并完整总结了GOT表劫持的技术思想与攻击触发流程。
https://xz.aliyun.com/news/92681
某批发商的订购系统,一个未授权的接口直接返回了阿里云 OSS 的 AK/SK 明文。
拿到密钥后不是终点,怎么把"能连上"证明成"批量个人信息泄露(高危)",才是这篇文章要讲的。
https://xz.aliyun.com/news/92683
本文以 DIR-605L 路由器为例,详细记录了 CNVD-2026-28535 命令注入漏洞的挖掘与复现过程。重点分享了如何通过分析 apmib.so、编写 C 代码劫持 apmib_init 等配置函数并配合 LD_PRELOAD,解决 MIPS 架构下 QEMU 模拟固件时的环境报错问题,最终成功完成漏洞的动态调试与利用验证。
https://xz.aliyun.com/news/92573