Sign in

watchTowr Labs [Unofficial]

@labs.watchtowr.com.web.brid.gy
12 followers 0 following 23 posts

watchTowr Labs is the epicentre of offensive security expertise at watchTowr - where research, innovation, and real attacker insight power our Preemptive […] 🌉 bridged from 🌐 labs.watchtowr.com: fed.brid.gy/web/labs.watchtowr.com

PostsRepliesMedia
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 29/09/2026
labs.watchtowr.com
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)
Part 1 of this week's saga can be found here. This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution, enabling organizations to rapidly react to emerging threats: the watchTowr Platform. ### What Is A Citrix NetScaler? NetScaler, from Citrix (now under Cloud
001
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 28/09/2026
labs.watchtowr.com
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)
God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up
010
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 24/09/2026
labs.watchtowr.com
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, **and** their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 14/08/2026
labs.watchtowr.com
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded. You know the drill - it’s the typical enterprise “please don’t be
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 02/07/2026
labs.watchtowr.com
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)
We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working. Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to have confidence
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 30/06/2026
labs.watchtowr.com
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Well, well, well - once again, the cat has dragged us in and spat us out. Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?” Well, if you’re here, you likely fit
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 29/06/2026
labs.watchtowr.com
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)
Welcome back to another watchTowr Labs blog post. This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 12/06/2026
labs.watchtowr.com
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
Three posts? In three days? Are we insane? We're home alone, there's no one to stop us, and we're up past bedtime. So, we need to talk about Splunk. On June 10th, Splunk published this CVE-2026-20253 advisory: It has everything that we
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 12/06/2026
labs.watchtowr.com
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)
It is yet another day in this parallel universe of security, where the devices we bolt onto the edge of our networks to keep the bad people out are, with remarkable consistency, the exact thing that let the bad people in. While we’ve seemingly had a breather from
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 10/06/2026
labs.watchtowr.com
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520)
Today, Ivanti published an advisory. “No way?” we hear you say. "Yes way!" a random dog screams back at you, across the street. Today’s rare advisory outlines two vulnerabilities in Ivanti’s Sentry product, appealing directly to our inner desire for sophisticated server-side,
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 29/04/2026
labs.watchtowr.com
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
Hello! Yes, it's all a disaster again! Let's get this party started: 0:00 /0:12 1× No comments today, so imagine this: * We wrote something that we find very funny, * Nobody else gets it, * But everyone humors us **Just like a typical watchTowr Labs**
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 02/04/2026
labs.watchtowr.com
You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)
If you squint and look at the CISA KEV list, you might think it's made up exclusively of vulnerabilities in file transfer solutions. While this would be wrong (and you shouldn’t squint, it’s bad for your eyes), file transfer solutions do play a decent
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 29/03/2026
labs.watchtowr.com
Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)
Today, we woke up with a nagging feeling: what if Citrix had, in fact, patched multiple Memory Overread vulnerabilities as part of CVE-2026-3055? While we've been using our analysis from Part 1 (please read it first, as this post will be brief) to accurately identify exploitable Citrix NetScaler
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 28/03/2026
labs.watchtowr.com
The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)
Sequels? Pain? We're obviously talking about Citrix NetScalers, yet again. Welcome back to another watchTowr Labs blog post - pull up a chair, we always welcome new members to our group therapy sessions. If you asked a C programmer what they most dislike doing in life, their answer
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 19/03/2026
labs.watchtowr.com
A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE)
A long, long time ago, in a land free of binary exploit mitigations, when Unix still roamed the Earth, there lived a pre-authentication Telnetd vulnerability. In fact, this vulnerability was born so long ago (way back in 1994) that it may even be older than you. To put the timespan
010
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 18/03/2026
labs.watchtowr.com
The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)
SolarWinds. Ivanti. SysAid. ManageEngine. Giants of the KEV world, all of whom have ITSM side-projects. ITSMs, as a group of solutions, have played pivotal roles in numerous ransomware gang campaigns - not only do they represent code running on a system, but they hold a significant amount of sensitive information.
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 03/03/2026
labs.watchtowr.com
Sometimes, You Can Just Feel The Security In The Design (Juniper Junos Evolved CVE-2026-21902 Pre-Auth RCE)
On today’s ‘good news disguised as other things’ segment, we’re turning our gaze to CVE-2026-21902 - a recently disclosed “Incorrect Permission Assignment for Critical Resource” vulnerability affecting Juniper’s Junos OS Evolved platform. This vulnerability affects only Juniper’s PTX
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 25/02/2026
labs.watchtowr.com
Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s))
It’s been a while, but we’re back - in time for story time. Gather round, strap in, and prepare for another depressing journey of “all we wanted to do was reproduce an N-day, and here we are with 0-days”. Today, friends, we’re
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 30/01/2026
labs.watchtowr.com
Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)
<p>When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti&#x2019;s Endpoint Manager Mobile (EPMM) solution - we sighed with relief.</p><p>Clearly, the universe had decided to continue mocking Secure-By-Design signers right on schedule - every January. </p><figure class="kg-card kg-image-card"><img alt="alt" class="kg-image" height="606" src="https://labs.watchtowr.com/content/images/2026/01/image-19.png" width="1080" /></figure><p>Welcome back to</p>
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 22/01/2026
labs.watchtowr.com
Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)
Well, well, well - look what we’re back with. You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a timeline that is typically reserved for KEV hall-of-famers. The plot of that story had everything;
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 08/01/2026
labs.watchtowr.com
Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691)
Welcome to 2026! While we are all waiting for the scheduled SSLVPN ITW exploitation programming that occurs every January, we’re back from Christmas and idle hands, idle minds, yada yada. In December, we were alerted to a vulnerability in SmarterTools’ SmarterMail solution, accompanied by an advisory from
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 10/12/2025
labs.watchtowr.com
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025). Weeeeeeeee. Before then, we want to clear the decks and see how much research we can publish. This
000
watchTowr Labs [Unofficial] @labs.watchtowr.com.web.brid.gy · 25/11/2025
labs.watchtowr.com
Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)
Welcome to watchTowr vs the Internet, part 68. That feeling you’re experiencing? Dread. You should be used to it by now. As is fast becoming an unofficial and, apparently, frowned upon tradition - we identified incredible amounts of publicly exposed passwords, secrets, keys and more for very sensitive
000