Sign in

Stephen Fewer

@stephenfewer.bsky.social
342 followers 77 following 49 posts

Senior Principal Security Researcher at @rapid7.com. Specializing in software vulnerabilities and exploitation. stephenfewer.github.io

PostsRepliesMedia
Stephen Fewer @stephenfewer.bsky.social · 10/09/2026
New (draft) @metasploit-r7.bsky.social exploit module in the queue for the latest N-able N-central unauth RCE, CVE-2026-86218. Already being exploit in-the-wild, was disclosed five day ago, added to KEV two days ago. github.com/rapid7/metas...
Metasploit exploit module for N-able N-central unauthenticated RCE (CVE-2026-86218)
021
Stephen Fewer @stephenfewer.bsky.social · 08/09/2026
While researching last months N-able N-central exploit (CVE-2026-18577, on KEV), we found and reported a new authentication bypass chain (CVE-2026-86206 and CVE-2026-86207). Patched and disclosed by the vendor over the weekend, full details on the @rapid7.com blog: www.rapid7.com/blog/post/ve...
rapid7.com
Rapid7
While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central....
011
Stephen Fewer @stephenfewer.bsky.social · 07/09/2026
Just added a @metasploit-r7.bsky.social exploit for last weeks SonicWall SMA1000 0-day chain that's exploited in-the-wild (CVE-2026-83548, SMA1000-9427, CVE-2026-83549). 3 bug chain; SSRF to CouchDB read/write for low priv RCE, to root RCE via cmd injection in cmsSnmpTrap github.com/rapid7/metas...
Metasploit exploit for CVE-2026-83548 + SMA1000-9427 + CVE-2026-83549
020
Stephen Fewer @stephenfewer.bsky.social · 31/08/2026
Module supports MF and NG editions, all supported product versions 26.x, 25.x, 24.x. Bypasses vendor emergency patch v1. Emergency patch v2 successfully remediates the chain. Module has platform agnostic Java payload support (that will be in-memory on 26.x targets), and OS command based payloads.
000
Stephen Fewer @stephenfewer.bsky.social · 31/08/2026
We have published our @metasploit-r7.bsky.social exploit for the recent PaperCut MF and NG zero-day (CVE-2026-81578 + CVE-2026-82078) that is being actively exploited in-the-wild. github.com/rapid7/metas...
120
Stephen Fewer @stephenfewer.bsky.social · 07/08/2026
PoC for CVE-2026-63077 here: github.com/sfewer-r7/CV...
000
Stephen Fewer @stephenfewer.bsky.social · 07/08/2026
We have published our @rapid7.com analysis of CVE-2026-63077, an unauth RCE in JetBrains TeamCity that was disclosed last week and already added to KEV as being exploited in the wild. This one has a gnarly gadget chain and a polyglot SQL/JSP payload. Full analysis/PoC: www.rapid7.com/blog/post/ra...
101
Stephen Fewer @stephenfewer.bsky.social · 30/07/2026
we now have a (draft) @metasploit-r7.bsky.social exploit module in the queue for CVE-2026-16232, leveraging the authentication bypass for RCE against vulnerable Check Point Security Management Server appliances: github.com/rapid7/metas...
121
Stephen Fewer @stephenfewer.bsky.social · 28/07/2026
PoC for CVE-2026-16232 available here: github.com/sfewer-r7/CV...
001
Stephen Fewer @stephenfewer.bsky.social · 28/07/2026
We have published our @rapid7.com analysis of CVE-2026-16232, the auth bypass in Check Point Security Management Server that was disclosed last week as a zero-day exploited in-the-wild. Full details and PoC: www.rapid7.com/blog/post/ra...
112
Stephen Fewer @stephenfewer.bsky.social · 30/05/2026
Congrats and best of luck with the new gig 👏
010
Reposted by Stephen Fewer
CryptoCat @cryptocat.me · 22/05/2026
New episode of the @rapid7.com podcast! 👀 @stephenfewer.bsky.social joins @fulmetalpackets.bsky.social and myself to talk about the latest SD-WAN auth bypass - available now in the Metasploit framework 😎 www.youtube.com/watch?v=tg4T...
youtube.com
Hacktics and Telemetry, E6: Cisco SD-WAN Zero-Days, Mythos AI Evaluations, and Pwn2Own Drama
YouTube video by Rapid7
011
Reposted by Stephen Fewer
Rapid7 @rapid7.com · 12/03/2026
🎤👾 Introducing Hacktics and Telemetry, a bi-weekly video and audio podcast out of Rapid7 Labs, starring Rapid7's Doug McKee (fulmetalpackets) & Jonah Burgess (@cryptocat.me)! 🧵 Find episode 1's companion blog here: r-7.co/4di8tuH ▶️ Or dive right into the full vid on YouTube: r-7.co/3NiQfP2
022
Stephen Fewer @stephenfewer.bsky.social · 11/03/2026
Check out the analysis by @cryptocat.me for CVE-2026-20127 in Cisco SD WAN. That other PoC posted last week exploits a totally different bug that doesn't match the reported IOCs (some kind of file upload due to path traversal in vManage maybe). We asses with high confidence this is CVE-2026-20127 🔥
021
Stephen Fewer @stephenfewer.bsky.social · 18/02/2026
We have disclosed CVE-2026-2329, a critical unauth stack-based buffer overflow vuln affecting the Grandstream GXP1600 series of VoIP phones. Read our disclosure on the @rapid7.com blog, including technical details for unauth RCE, and accompanying @metasploit-r7.bsky.social modules: r-7.co/4tIzope
035
Stephen Fewer @stephenfewer.bsky.social · 10/02/2026
We just published our @rapid7.com analysis of CVE-2026-1731, a critical command injection affecting BeyondTrust Privileged Remote Access (PRA) & Remote Support (RS). Unauthenticated RCE, with a root cause due to Bash arithmetic evaluation. Analysis/PoC here: attackerkb.com/topics/jNMBc...
attackerkb.com
CVE-2026-1731 | AttackerKB
On February 6, 2026, BeyondTrust published an advisory for a new critical command injection vulnerability, CVE-2026-1731, affecting their products Remote Suppo…
031
Stephen Fewer @stephenfewer.bsky.social · 21/11/2025
We now have a (draft) @metasploit-r7.bsky.social exploit module for the recent Fortinet FortiWeb vulns, chaining CVE-2025-64446 (auth bypass) + CVE-2025-58034 (command injection) to achieve unauthenticated RCE with root privileges: github.com/rapid7/metas...
12110
Reposted by Stephen Fewer
Rapid7 @rapid7.com · 19/11/2025
⚠️ In Aug. 2025, Rapid7 found #TwonkyServer susceptible to multiple vulns – granting unauthenticated attackers plaintext admin credentials, full admin access to the instance & control of all stored media files. At the time of publication, these vulns have not been patched. Read on: r-7.co/4a0JiuU
r-7.co
CVE-2025-13315, CVE-2025-13316: Critical Twonky Server Authentication Bypass (NOT FIXED)
Rapid7 has identified two vulnerabilities that facilitate administrator authentication bypass in Twonky Server, a media solution.
031
Stephen Fewer @stephenfewer.bsky.social · 19/11/2025
We posted our AttackerKB @rapid7.com Analysis of the new EITW FortiWeb command injection vuln, CVE-2025-58034. The patch fixes several command injections, so we reproduced the SAML config name injection, and popped a reverse root shell 🎯 Full details here: attackerkb.com/topics/zClpI...
021
Stephen Fewer @stephenfewer.bsky.social · 14/11/2025
New @metasploit-r7.bsky.social aux module in the pull queue for the FortiWeb vuln (no CVE at this time). Based on the PoC captured and posted by Defused, it leverages an auth bypass to create a new local admin account on the target: github.com/rapid7/metas...
030
Stephen Fewer @stephenfewer.bsky.social · 11/11/2025
We just published our AttackerKB @rapid7.com analysis of CVE-2025-12480. Disclosed yesterday, but patched back in July, it's an access control bypass affecting not only Gladinet Triofox, but as we show, also Gladinet CentreStack. Full analysis & RCE details here: attackerkb.com/topics/5C4wR...
011
Stephen Fewer @stephenfewer.bsky.social · 24/10/2025
As Pwn2Own Ireland 2025 draws to a close, a huge thank you to @thezdi.bsky.social for putting on another great contest! I reflected on why @rapid7.com has taken part at #Pwn2Own over the last two years, and our successes so far in the world of competitive zero day exploit development r-7.co/4o6RM85
r-7.co
Rapid7 at Pwn2Own: Raising the Bar in Vuln Intel
As the 2025 edition of Pwn2Own Ireland draws to a close, we are taking a beat to reflect on Rapid7’s participation & achievements in the world of competitive zero day exploit development.
022
Stephen Fewer @stephenfewer.bsky.social · 06/10/2025
The auth bypass appears to be a patch bypass of an older 2018 vuln (CVE-2018-0296). The buffer overflow is in a Lua endpoint, but unsafe native code operations allow a buffer to be overflowed and memory corruption to occur.
000
Stephen Fewer @stephenfewer.bsky.social · 06/10/2025
We just posted our AttackerKB @rapid7.com Analysis for the recent Cisco 0day chain; CVE-2025-20362 and CVE-2025-20333. Full technical root cause analysis of both the auth bypass and buffer overflow are here: attackerkb.com/topics/Szq5u...
attackerkb.com
CVE-2025-20362 | AttackerKB
On September 25, 2025, Cisco published advisories for two new vulnerabilities, CVE-2025-20362, and CVE-2025-20333, which are known to be exploited in-the-wild …
111
Stephen Fewer @stephenfewer.bsky.social · 24/09/2025
and shout out to @iagox86.bsky.social who figured out the access control bypass part of this back in his 2023 analysis of the CVE-2023-0069 patch 🔥
131
Stephen Fewer @stephenfewer.bsky.social · 24/09/2025
We have published our AttackerKB @rapid7.com Analysis for the recent GoAnywhere MFT vuln, CVE-2025-10035. It's an access control bypass + unsafe deserialization + an as-yet unknown issue in how an attacker can know a specific private key! attackerkb.com/topics/LbA9A...
attackerkb.com
CVE-2025-10035 | AttackerKB
On September 18, 2025, Fortra published a security advisory for a new vulnerability affecting their managed file transfer product, GoAnywhere MFT. The new vuln…
152
Reposted by Stephen Fewer
Rapid7 @rapid7.com · 23/09/2025
⚠️ Rapid7 has identified a permission bypass vuln. in multiple versions of #OnePlus OxygenOS installed on its Android smartphones. When leveraged, any app on the device may read SMS/MMS data & metadata via the default Telephony provider. More in our blog: r-7.co/42EujlR
011
Stephen Fewer @stephenfewer.bsky.social · 25/08/2025
Come join @rapid7.com ! I’m hiring for a Senior Security Researcher to join our team. You'll get to work on n-day analysis, zero-day research, exploit development, and more - focusing on enterprise software and appliances. Fully remote in the UK, more details here: careers.rapid7.com/jobs/senior-...
careers.rapid7.com
Senior Security Researcher - United Kingdom
The Senior Security Researcher will drive vulnerability discovery and analysis within Rapid7’s Vulnerability Intelligence team. You’ll research zero-day and n-day threats, develop exploits, publish ro...
030
Stephen Fewer @stephenfewer.bsky.social · 23/07/2025
I just completed the reimplementation of the in-the-wild gadget to use the Msf::Util::DotNetDeserialization routines, so that part is much cleaner now, no more sketchy blobs of base64 😅
010
Stephen Fewer @stephenfewer.bsky.social · 23/07/2025
We now have a (draft) @metasploit-r7.bsky.social exploit module in the pull queue for the recent Microsoft SharePoint Server unauthenticated RCE zero-day (CVE-2025-53770), based on the in-the-wild exploit published a few days ago. Check it out here: github.com/rapid7/metas...
1118
Stephen Fewer @stephenfewer.bsky.social · 25/06/2025
Our @metasploit-r7.bsky.social auxiliary module for the new Brother auth bypass is available. The module will leak a serial number via HTTP/HTTPS/IPP (CVE-2024-51977), SNMP, or PJL, generate the devices default admin password (CVE-2024-51978), and then validate the creds: github.com/rapid7/metas...
051
Stephen Fewer @stephenfewer.bsky.social · 25/06/2025
Today @rapid7.com is disclosing 8 new vulnerabilities affecting 742 models across 4 vendors. After 13 months of coordinated disclosure with Brother Industries, Ltd, we're detailing all issues including a critical auth bypass. Full details here: www.rapid7.com/blog/post/mu...
rapid7.com
Rapid7
Rapid7 conducted a zero-day research project into multifunction printers (MFP) from Brother Industries, Ltd. This research resulted in the discovery of 8 new vulnerabilities.
042
Stephen Fewer @stephenfewer.bsky.social · 18/06/2025
Today @rapid7.com disclosed two vulns affecting NetScaler Console and SDX, found by Senior Security Researcher Calum Hutton! 🎉 Our blog details the authenticated arbitrary file read vuln (CVE-2025-4365), and the authenticated arbitrary file write vuln (Which the vendor has not assigned a CVE for).
032
Stephen Fewer @stephenfewer.bsky.social · 27/05/2025
A new @rapid7.com Analysis of CVE-2024-58136 was just published to AttackerKB, courtesy of Calum Hutton 🔥 Affecting the Yii framework, this analysis details the root cause of CVE-2024-58136, and how it can be leveraged for RCE via a dirty file write to a log file. attackerkb.com/topics/U2Ddo...
attackerkb.com
CVE-2024-58136 | AttackerKB
Yii framework is a component-based MVC web application framework, providing developers with the building blocks to create complex web applications including mo…
020
Stephen Fewer @stephenfewer.bsky.social · 10/04/2025
This was an interesting challenge to go from a restricted character set "0123456789." for the overflow, to arbitrary RCE. Hat tip to watchTowr for diffing out the bug last Friday. PoC available here: github.com/sfewer-r7/CV...
github.com
GitHub - sfewer-r7/CVE-2025-22457
Contribute to sfewer-r7/CVE-2025-22457 development by creating an account on GitHub.
010
Stephen Fewer @stephenfewer.bsky.social · 10/04/2025
We have just published our AttackerKB @rapid7.com Analysis of CVE-2025-22457, an unauthenticated stack based buffer overflow in Ivanti Connect Secure. Difficult to exploit due to severe character restrictions, we detail our full RCE technique here: attackerkb.com/topics/0ybGQ...
attackerkb.com
CVE-2025-22457 | AttackerKB
On April 3, 2025, Ivanti published an advisory for CVE-2025-22457, an unauthenticated remote code execution vulnerability due to a stack based buffer overflow.…
134
Stephen Fewer @stephenfewer.bsky.social · 07/03/2025
A VM escape exploit chain, exploited in the wild as 0day ...well that's not something we see very often 👀
0114
Reposted by Stephen Fewer
Metasploit @metasploit-r7.bsky.social · 05/03/2025
Root cause analysis of Sitecore XM + XP remote code execution CVE-2025-27218 via @rapid7.com's pen testing team attackerkb.com/assessments/...
attackerkb.com
machang-r7's assessment of CVE-2025-27218 | AttackerKB
On January 6, 2025, Sitecore published a security bulletin, SC2024-002-624693 , for a critical unauthenticated remote code execution (RCE) vulnerability affect…
085
Stephen Fewer @stephenfewer.bsky.social · 13/02/2025
Our @metasploit-r7.bsky.social exploit module for unauthenticated RCE against BeyondTrust Privileged Remote Access & Remote Support is now available. The exploit can either leverage CVE-2024-12356 and CVE-2025-1094 together, or solely leverage CVE-2025-1094 for RCE: github.com/rapid7/metas...
github.com
Exploit module for BeyondTrust Privileged Remote Access & Remote Support (CVE-2024-12356, CVE-2025-1094) by sfewer-r7 · Pull Request #19877 · rapid7/metasploit-framework
Overview This pull request adds an unauthenticated RCE exploit module targeting BeyondTrust Privileged Remote Access & Remote Support, leveraging CVE-2024-12356 + CVE-2025-1094. CVE-2024-12356 ...
011
Stephen Fewer @stephenfewer.bsky.social · 13/02/2025
We are also publishing our AttackerKB Rapid7 analysis for CVE-2024-12356 - Unauth RCE affecting BeyondTrust PRA & RS, which was exploited in the wild last Dec as 0day ...our analysis details leveraging the new PostgreSQL vuln CVE-2025-1094 for RCE! 👀 attackerkb.com/topics/G5s8Z...
attackerkb.com
112
Stephen Fewer @stephenfewer.bsky.social · 13/02/2025
Today Rapid7 has disclosed CVE-2025-1094, a new PostgreSQL SQLi vuln we discovered while researching CVE-2024-12356 in BeyondTrust Remote Support. Untrusted inputs that have been safely character escaped could still generate SQLi under certain conditions: www.rapid7.com/blog/post/20...
rapid7.com
CVE-2025-1094: PostgreSQL psql SQL injection (FIXED) | Rapid7 Blog
124
Reposted by Stephen Fewer
Ron Bowes @iagox86.bsky.social · 28/01/2025
Process injection shenanigans are dear to my heart - it's one of the first things I ever learned in security. Inspired by an Akamai blog last month, this blog digs into techniques to tinker with other processes on Linux, and show you how to write a little debugger in C!
labs.greynoise.io
GreyNoise Labs - How-To: Linux Process Injection
Ever wondered how to inject code into a process on Linux?
041
Reposted by Stephen Fewer
Caitlin Condon @catc0n.bsky.social · 28/01/2025
Root cause analysis of #SonicWall SSL VPN auth bypass CVE-2024-53704 available now c/o Ryan Emmons: attackerkb.com/topics/UB3P3...
attackerkb.com
CVE-2024-53704 | AttackerKB
On January 7, 2025, SonicWall announced an authentication bypass affecting SonicOS, the operating system used by many SonicWall appliances. This authentication…
064
Stephen Fewer @stephenfewer.bsky.social · 23/01/2025
100% this!! They're amazing 😃
120
Stephen Fewer @stephenfewer.bsky.social · 16/01/2025
PoC for CVE-2025-0282 targeting 22.7r2.4 can be found here: github.com/sfewer-r7/CV...
github.com
GitHub - sfewer-r7/CVE-2025-0282: PoC for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways
PoC for CVE-2025-0282: A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways - sfewer-r7/CVE-2025-0282
021
Stephen Fewer @stephenfewer.bsky.social · 16/01/2025
Without a suitable info leak you have to brute force the 32bit base address of a shared library, and with 9 bits of entropy this can take upwards of 1.5 hours, although in practice it can be much quicker. Regardless of the time it takes to succeed, exploitation is reliable.
120
Stephen Fewer @stephenfewer.bsky.social · 16/01/2025
I wrote a PoC for the recent Ivanti Connect Secure stack buffer overflow, CVE-2025-0282, based on the exploitation strategy watchTowr published, along with an assessment of exploitability given the lack of a suitable info leak to break ASLR: attackerkb.com/assessments/...
1118
Reposted by Stephen Fewer
Caitlin Condon @catc0n.bsky.social · 07/01/2025
I'm #hiring a vulnerability research manager in Dublin, IE (or Prague CZ, Belfast NI, or Reading UK) to help lead our zero-day vulnerability research and disclosure function. Love vulns, exploits, and CVD? Hit us up! careers.rapid7.com/jobs/manager...
careers.rapid7.com
Manager, Vulnerability Research - Dublin, Ireland
Job OverviewRapid7’s security sciences division is looking for an experienced vulnerability research leader to help define and execute a research strategy that helps defenders get ahead of the curve, ...
0910
Stephen Fewer @stephenfewer.bsky.social · 07/01/2025
We now have a @metasploit-r7.bsky.social RCE exploit module in the pull queue for CVE-2024-55956 - an unauthenticated file write vulnerability affecting Cleo LexiCom, VLTrader, and Harmony which was exploited in the wild last month as 0day: github.com/rapid7/metas...
021
Reposted by Stephen Fewer
Piotr Bazydło @chudypb.bsky.social · 19/12/2024
[1/n] I want to kick off my profile here a little bit, thus I'll post several fun projects that I've made last year. Let's kick off with SharePoint XXE blog, which could be abused due to URL parsing confusion between SharePoint and .NET components: www.zerodayinitiative.com/blog/2024/5/...
zerodayinitiative.com
Zero Day Initiative — CVE-2024-30043: Abusing URL Parsing Confusion to Exploit XXE on SharePoint Server and Cloud
Yes, the title is right. This blog covers an XML eXternal Entity (XXE) injection vulnerability that I found in SharePoint. The bug was recently patched by Microsoft. In general, XXE vulnerabilities ar...
042