// INTELLIGENCE REPORTS

Security Research

Deep-dive technical analysis, CVE breakdowns, threat actor profiles, and mobile security research. Written by practitioners, for practitioners.

339 articles published
29 pages
Updated every 6 hours
CVE Analysis 7 min read

CVE-2026-4798: Avada Builder Unauthenticated Time-Based SQLi via product_order

Avada Builder ≤3.15.1 passes the `product_order` parameter directly into a WooCommerce fallback query path without escaping or preparation, enabling unauthenticated time-based blind SQL injection.

#sql-injection#wordpress-plugin#unauthenticated-attack
2026-05-13
CVE Analysis 7 min read

CVE-2026-5441: OOB Read in Orthanc PSMCT_RLE1 Decoder Leaks Heap

The DecodePsmctRle1 function in Orthanc's DicomImageDecoder.cpp fails to validate escape markers near end-of-buffer, leaking heap contents into rendered DICOM image output.

#dicom-decoder#out-of-bounds-read#heap-leak
2026-04-09
CVE Analysis 8 min read

CVE-2026-0029: pKVM __pkvm_init_vm Logic Error Enables Local EoP

A logic error in __pkvm_init_vm of pkvm.c allows memory corruption in Android's protected KVM hypervisor layer, enabling local privilege escalation with no additional permissions required.

#memory-corruption#logic-error#privilege-escalation
2026-03-02
CVE Analysis 8 min read

CVE-2026-5760: SGLang Rerank Endpoint RCE via Unsandboxed Jinja2

SGLang's /v1/rerank endpoint renders Jinja2 chat templates without sandboxing, allowing RCE via malicious tokenizer.chat_template in a loaded model file. CVSS 9.8.

#remote-code-execution#jinja2-injection#unsandboxed-template
2026-04-20
CVE Analysis 9 min read

CVE-2025-48574: Android DisplayPolicy Missing Permission Check Enables Drag-and-Drop Hijack

A missing permission check in validateAddingWindowLw of DisplayPolicy.java allows unprivileged apps to intercept drag-and-drop events, enabling local privilege escalation without user interaction.

#privilege-escalation#permission-bypass#input-interception
2026-03-02
CVE Analysis 9 min read

CVE-2025-48645: DeviceAdminInfo.loadDescription Persistent Package Privilege Escalation

Improper input validation in DeviceAdminInfo.loadDescription() allows a malicious package to persist with elevated privileges. No additional execution privileges or user interaction required.

#device-admin#privilege-escalation#input-validation
2026-03-02
CVE Analysis 9 min read

CVE-2026-34645: Adobe Commerce Incorrect Authorization Leads to Unauthenticated Write

Adobe Commerce's REST API authorization middleware fails to validate role scope on nested resource writes, allowing unauthenticated attackers to gain arbitrary write access without user interaction.

#authorization-bypass#privilege-escalation#remote-exploitation
2026-05-12
CVE Analysis 9 min read

CVE-2026-23827: Heap Overflow in AOS Network Management Service Enables Unauthenticated RCE

A heap-based buffer overflow in AOS-8/AOS-10's network management service allows unauthenticated remote attackers to corrupt heap metadata and achieve privileged RCE. No authentication required.

#heap-buffer-overflow#remote-code-execution#network-service
2026-05-12
CVE Analysis 8 min read

CVE-2026-23826: AOS-8 Network Management Service Remote DoS via Malformed Packets

An unauthenticated attacker can crash the AOS-8 network management service by sending crafted packets that trigger an unhandled length/state condition, terminating the process.

#denial-of-service#network-management#remote-unauthenticated
2026-05-12
CVE Analysis 8 min read

CVE-2026-23825: AOS-8/10 Protocol Handler DoS via Malformed Network Messages

Insufficient input validation in AOS-8 and AOS-10 protocol-handling components allows unauthenticated remote attackers to terminate critical system processes via crafted network messages.

#protocol-handling#input-validation#denial-of-service
2026-05-12
CVE Analysis 8 min read

CVE-2026-23824: AOS-8/10 Protocol Handler DoS via Malformed Network Messages

Insufficient input validation in AOS-8/AOS-10's protocol-handling subsystem allows unauthenticated attackers to terminate a critical process via crafted network messages, causing a denial-of-service condition.

#protocol-handling#input-validation#denial-of-service
2026-05-12
CVE Analysis 8 min read

CVE-2026-39432: Timetics Plugin Broken Access Control via Unauthenticated REST Endpoints

Timetics ≤1.0.53 exposes AJAX/REST handlers without capability checks, allowing unauthenticated actors to manipulate booking data and staff assignments. CVSS 8.2 HIGH.

#missing-authorization#access-control-bypass#cross-platform
2026-05-12
Showing 1–12 of 339 articles
// NEVER MISS AN INTEL REPORT

Get new research delivered weekly. Join security professionals getting the CypherByte digest.

Subscribe Free →