Tag: Poc

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root
News

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

A recently revealed serious security vulnerability affecting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME) has been exploited by threat actors. The vulnerability, known as CVE-2026-20230 (CVSS score: 8.6), is a case of incorrect input validation for particular HTTP requests that may enable server-side request forgery (SSRF) attacks through an impacted device by an unauthenticated, remote attacker. According to a Cisco advisory issued earlier this month, "an attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device." If the exploit is successful, the attacker may be able to write files to the underlying operating system that they can then use to elevate to root. ...
Zoho ManageEngine PoC Exploit to be Released Soon – Patch Before It’s Too Late!
Risk, Security

Zoho ManageEngine PoC Exploit to be Released Soon – Patch Before It’s Too Late!

Before a proof-of-concept (PoC) exploit code is released, Zoho ManageEngine users are recommended to patch their instances against a critical security vulnerability. The problem is CVE-2022-47966, a remote code execution vulnerability that affects a number of products because it is caused by the use of an obsolete third-party dependency called Apache Santuario. In a late-year alert, Zoho stated that the vulnerability "allows an unauthenticated adversary to execute arbitrary code," noting that it impacts all ManageEngine configurations that have the SAML single sign-on (SSO) capability enabled or have previously had it enabled read the complete article Zoho ManageEngine PoC Exploit to be Released Soon. For recent and trending cybersecurity news follow ReconBee.com.