← All threat briefs
Threat Brief

Weekly Situation Report — 7/6/26

Key takeaways

  • A new Citrix NetScaler pre-authentication memory overread vulnerability, dubbed “CitrixBleed To Infinity And Beyond” (CVE-2026-8451), exposes affected appliances to remote attacks.
  • A security researcher has released an “exploitarium” repository containing proof-of-concept exploits for multiple unpatched vulnerabilities.
  • The SimpleHelp account creation vulnerability is now being actively exploited in the wild following its public disclosure.
  • Attackers are actively exploiting a remote code execution vulnerability in Microsoft SharePoint to compromise vulnerable servers.
  • Public proof-of-concept exploits have been released for multiple Adobe ColdFusion vulnerabilities that enable file read/write access and path traversal attacks.

1. CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)

Summary

A new memory overread vulnerability, dubbed ‘CitrixBleed To Infinity And Beyond,’ has been discovered in Citrix NetScaler devices. This marks the fifth disclosed ‘CitrixBleed’ variant with a public proof of concept (PoC).

Category: Critical Vulnerabilities

Industry: Multiple

Analyst comments

Citrix NetScaler, a widely-used application delivery controller and VPN gateway appliance, has been found to have a new memory overread vulnerability nicknamed “CitrixBleed To Infinity And Beyond” (CVE-2026-8451). This vulnerability arises from the appliance’s XML parsing logic, particularly when it is configured as a SAML IdP. Successful exploitation can cause memory overread conditions, potentially leading to information disclosure or even system crashes. Full PoC code of this vulnerability is publicly available.

This is the 6th CitrixBleed-classed vulnerability that has been disclosed since 2023. The previous five vulnerabilities in this class have been exploited in the wild by threat actors, including ransomware groups. Based on this history and the release of full PoC code, this vulnerability is likely to see exploitation in the near future. The vulnerability itself is unlikely to result in direct compromise, however it may be used as part of an attack chain targeting these devices. At least one IP has been observed in public honeypot data attempting to exploit this vulnerability in the last 30 days. This IP is listed below and is tied to other malicious activity, including exploitation of other vulnerabilities:

Network IoC
194.165.16[.]11 - AS 48721 FlyServers SA Monaco
ptr.flow-metric[.]com (resolved domain from reverse DNS)

The vulnerability targets the /saml/login endpoint when it is enabled and actively in use. A specially crafted SAML request is sent to a vulnerable server with varying memory allocation, which can leak portions of device memory. The leaked memory is contained within the NSC_TASS cookie Base64 value in the server response.

This vulnerability can also be used to trigger a DoS condition by supplying crafted SAML content targeting the samlp:AuthnRequest ID parameter.

Actionable guidance

Patches are available to remediate this issue and should be applied to prevent exploitation of this vulnerability. If compromise is suspected, teams should hunt for decoded SAML requests that contain variable bytes and a lack of tag terminator for the samlp:AuthnRequest parameter. Teams should also decode the NSS_TASS cookie and inspect the Base64 decoded value for embedded binary data. Alternatively, organizations can also opt to disable SAML authentication if not in use, which will prevent attacks.

Affected NetScaler versions if SAML Auth is enabled
NetScaler ADC and NetScaler Gateway 14.1 BEFORE 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 BEFORE 13.1-63.18
NetScaler ADC FIPS BEFORE 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP BEFORE 13.1-37.272

2. Researcher Drops 0-Day ‘Exploitarium’ Repository

Summary

A researcher dubbed “bikini” (aka Trinea) publicly released exploit code for multiple zero-day vulnerabilities affecting various software products and open-source projects, including critical flaws in libssh2 and Gitea. The releases occurred without prior vendor notification, led to immediate exploitation by attackers, and raised concerns about the role of AI in vulnerability discovery and exploitation.

Category: Emerging Threats

Industry: Technology, Multiple

Analyst comments

A researcher known as bikini (aka Trinea) has released exploit code for multiple zero-day vulnerabilities across 15 software products and open source projects, including critical vulnerabilities in libssh2 and Gitea, without prior notification to vendors. One of the vulnerabilities, CVE-2026-55200 in libssh2, allows pre-authentication remote code execution through crafted SSH packets, while another, CVE-2026-20896 in Gitea Docker deployments, enables unauthenticated users to impersonate any user and take over the server. The cache of PoC code was criticized on social media after several analyzed samples were described as low quality. Examples include vulnerabilities that are only triggerable when security controls are disabled, require non-standard configurations, affect user tooling under specific conditions, take advantage of normal operating system design, or were tested in lab environments that were overly favorable to exploitation.

Focusing on the two vulnerabilities that external analysts have called out as important, both require pre-positioning and additional requirements based on the available PoC code we were able to analyze. CVE-2026-55200 does not affect SSH servers but affects clients (i.e. users connecting to an attacker controlled server). Therefore the scenario for exploitation would be luring unsuspecting users to connect to an attacker controlled server to exploit that user. This would likely be used in conjunction with stealer malware and related behavior. This is unlikely to reflect typical user activity and will primarily affect IT staff, likely through a social engineering component. However, we assess that this is unlikely to have a major impact.

CVE-2026-20896 would still require initial write access to a victim GitHub repository and be able to write a malicious workflow to the target repository. Successful exploitation could bypass the Privileged: false flag and execute malicious Docker flags that would allow the actor to escape the container with root access on the host system. Similar attack chains have been seen in the wild during supply chain attacks, including Shai-Hulud and similar package exploitation worms. These attacks took advantage of existing workflow designs and the access conditions granted from the initial theft of the repository maintainer credentials.

No verified reports of exploitation have been observed at this time. Given the various pre-conditions required for a majority of these vulnerabilities, they are unlikely to be taken advantage of by sophisticated threat actors. Exploitation will most likely include lone wolf or lower skilled threat actors attempting to exploit these issues. Other security researchers have also analyzed the repository, and based on their findings and our initial analysis, these vulnerabilities are unlikely to be weaponized for major impact.

The Exploitarium repository was deleted and later restored during the week of June 29th. Since its restoration, the researcher has added 8 new entries affecting products that include QEMU, NextJS, GOGs, NodeBB, Pillow, ImageCMS, libarchive, Ladybird WASM, and Curl. All the PoCs contained in the repository were likely found with AI assistance. The full list of products with claimed PoCs is as follows:

7-Zip 26.01
AnyDesk for Windows 9.7.6
c-ares
curl
Docker Engine 29.6.0
FFmpeg's RASC decoder
Firefox 152.0.2
Floci 1.5.27
Flowise 3.1.2
Ghidra 12.1.2
Gitea (CVE-2026-20896)
Gogs 0.15.0+dev
ImageMagick 7.1.2-25 (Ghostscript 10.07.1)
Ladybird WebAssembly
libarchive
libssh2 (including CVE-2026-55200 PoC)
Lunar Client
MyBB 1.8.40
Next.js
nghttpx v1.69.0
Nmap
NodeBB
GNU objdump (GNU Binutils) 2.46.1
OpenVPN core 3.11.3
OpenVPN Connect for Windows 3.8.0 (4528)
PHP 8.5.7
Pillow 12.3.0
QEMU emulator version 11.0.50
RustDesk
System Informer canary (formerly Process Hacker) 4.0.26162.539
VLC 3.0.23

Actionable guidance

Many of the PoCs detailed can likely be treated as a lower patching priority due to non-standard configuration requirements or other exploitation constraints. Some product maintainers may also choose not to patch these issues due to the low likelihood of exploitation. Organizations using any of the affected products should review vendor support pages for available patches, workarounds and additional guidance specific to the impacted software. Both libssh2 and Gitea vulnerabilities have been patched in newer versions.

3. UPDATE: SimpleHelp Vulnerability Allows Creation of Accounts, Now Exploited in the Wild

Summary

A critical vulnerability (CVE-2026-48558) in SimpleHelp’s remote management software allows unauthenticated attackers to create privileged technician accounts via OIDC. The issue affects versions 5.5.15 and older, and 6.0 pre-releases. Exploitation requires specific configurations, but approximately 14,000 exposed servers may be affected.

Updated July 2nd with additional sources and threat actor exploitation details.

Category: Known Exploited Vulnerabilities

Industry: Multiple

Analyst comments

A critical vulnerability (CVE-2026-48558) in SimpleHelp versions 5.5.15 and older, as well as 6.0 pre-release versions, allows unauthenticated attackers to create privileged technician accounts through OpenID Connect (OIDC), bypassing multi-factor authentication. This flaw enables attackers to perform privileged management activities like remotely accessing managed endpoints and executing scripts. The vulnerability affects SimpleHelp servers that rely on OIDC and have specific group settings enabled, impacting approximately 1,008 servers worldwide. SimpleHelp has patched this issue in versions 5.5.16 and 6.0RC2. Organizations should update to these versions or restrict technician login sources with IP-based allowlists.

The vulnerability will likely be used to abuse legitimate sources and URLs during later stages of attack chains. Attackers may compromise SimpleHelp instances to gain access to hosted environments for reconnaissance, but the higher value is likely in using vulnerable SimpleHelp instances to execute attacks against external organizations or internal hosts. This is more likely given recent threat actor trends involving abuse of RMM software for initial access and C2 operations. In normal scenarios, a victim would likely need to download and install an RMM binary first. By compromising SimpleHelp infrastructure directly, attackers may bypass that step and increase the likelihood of successful targeting against one or more victims.

A working PoC exploit for this vulnerability is currently being sold in the wild for an estimated $2500. While researchers have reported on the alleged sale, we have not been able to verify the forum post directly. The post states “priv on target: system”, which appears to describe a Windows privilege escalation exploit. This is inconsistent with the vulnerability disclosed by researchers, which is an authorization bypass. This discrepancy, combined with the unverifiable nature of the post, increases the likelihood that the alleged exploit being sold is fake.

Updated July 2nd: This vulnerability is now being exploited in the wild by threat actors to deploy stealer malware for credential theft, including user and cloud credentials when available on the target system. Based on current information, the vulnerability is likely due to altering a JWT token during OIDC authentication. For example, setting the role from user to admin, or crafting a JWT entirely, could grant administrator privileges to the user authenticating if the OIDC integration does not fully verify the JWT signature.

According to researchers, the threat actors are deploying Djinn Stealer and Taskweaver (loader) using temporary tunnel domains such as trycloudflare[.]com and dev-tunnels[.]com. Both pieces of malware are written in JavaScript and affect multiple platforms. The SimpleHelp vulnerability is used for persistence and to spread the malware for maximum impact amongst users, likely primarily targeting enterprise users over individuals. After SimpleHelp is compromised, the threat actor deploys the Node.js runtime via PowerShell using the -enc flag to hide the command contents. The actor then executes the Node binary to trigger TaskWeaver, which loads Djinn stealer onto the victim system to conduct credential theft. The malware likely executes its activities in userland without elevating privileges, opting to access user stored information.

IOCs

Sha256 hashes of samples
00cc86d1144020c24c8fbb3a8dc6b908926497ebd23be3bf854360f93d1c8f4c - TaskWeaver
f4a72600a3735c2a4d843875ea61bbb6f935a1af51a81f2fbc992ce11ba94afc - Djinn Stealer

Network indicators
trycloudflare[.]com - Official service domain primarily used for developer testing
a.dev-tunnel[.]com - Official service domain primarily used for developer testing
96[.]126[.]130[.]126:58942 - Djinn stealer exfiltration IP (Still Online)
ASN 14940 - Evoxt Sdn. Bhd. US

User agent
telemetry-client/1.0

Dropped files used for Reconnaissance
processList.txt
linux-process-env.json
env.json
telemetry.json
user-dirs.txt

Actionable guidance

Applying the patch or upgrading to the most recent version of the software is recommended to reduce the risk of compromise. Indicators of potential abuse may include unfamiliar OIDC authentication activity in SimpleHelp logs or unknown technician accounts identified during an audit of currently logged in users.

Update July 2nd: Block 96[.]126[.]130[.]126 (Djinn stealer exfiltration endpoint) as it remains online as of July 2nd and is currently being used by known threat actors exploiting this issue. Organizations should also restrict PowerShell usage and apply least privilege controls to SimpleHelp deployments to help reduce risk of further compromise. Excessive calls to trycloudflare[.]com or dev-tunnels[.]com, combined with other identified artifacts involved with this intrusion, should be treated as a strong indicator of compromise.

Fixed versions
5.5.16
6.0RC2

4. Microsoft SharePoint RCE Flaw Now Actively Exploited

Summary

CISA has warned of a critical SharePoint vulnerability (CVE-2026-45659) allowing low-privilege attackers to execute code remotely. Microsoft has released updates to address the flaw, and CISA has directed federal agencies to apply patches, highlighting the significant cybersecurity risk posed by this vulnerability.

Category: Known Exploited Vulnerabilities

Industry: Technology, Public Sector and Government Administration, Multiple

Analyst comments

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of a high-severity Microsoft SharePoint vulnerability (CVE-2026-45659), which allows low-privilege authenticated attackers to execute arbitrary code remotely on unpatched SharePoint servers without user interaction. This flaw stems from deserialization of untrusted data and is remotely exploitable with low attack complexity. Most deserialization risks for SharePoint are likely due to the use of .NET BinaryFormatter or other legacy endpoints such as /_vti-bin.

To our knowledge, no public version of the exploit or PoC code exists. However, we have seen signals that the exploit for this vulnerability is being sold through several GitHub repositories that link to the purchase sites. At least one of the repositories makes mention of the underground crime forum exploit[.]in, indicating that the exploit code is also being advertised on those forums. We are not currently aware of any attribution to specific groups exploiting this vulnerability. Based on public honeypot data from the last seven days, we have observed several IPs that are likely scanning for SharePoint instances:

Scanning hosts looking for SharePoint and other products likely for targeting over the last 7 days:
185.177.72.24 FR AS211590 Bucklog SARL
185.177.72.54 FR AS211590 Bucklog SARL
185.177.72.38 FR AS211590 Bucklog SARL
185.177.72.11 FR AS211590 Bucklog SARL

Actionable guidance

Microsoft released updates on May 21 for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition to address this vulnerability. These should be applied to remediate this issue. No data is currently available for the exact endpoints being targeted. Threat hunting should focus on excessive or unusual traffic patterns, as well as unknown source hosts accessing SharePoint specific endpoints such as /layouts/, /_api, or /vti_bin/.

5. Multiple Adobe ColdFusion PoCs Disclosed Resulting in File Read/Write and Path Traversal

Summary

Multiple vulnerabilities have been disclosed in Adobe ColdFusion, with particular focus on path traversal issues in the RDS and CKEditor file manager components. These vulnerabilities can lead to arbitrary file read and write operations.

Category: Critical Vulnerabilities

Industry: Technology, Multiple

Analyst comments

Adobe ColdFusion, a web application development platform, released a security advisory addressing multiple critical vulnerabilities, including several that allow for arbitrary code execution and privilege escalation. The affected versions include ColdFusion 2025 (Update 9 and below) and ColdFusion 2023 (Update 20 and below). The vulnerabilities arise from issues in the RDS (Remote Development Services) feature and the CKEditor file manager, which were exploited through path traversal and file upload mechanisms.

The researchers disclosed details on three vulnerabilities:

CVE-2026-48313 - Arbitrary File Read
CVE-2026-48282 - Arbitrary File Write
CVE-2026-48276 - File Upload Path Traversal

CVE-2026-48313 and CVE-2026-48282 require certain preconditions for full exploitation. RDS must be enabled, with RDS authentication disabled, as noted by the researchers. The vulnerabilities then abuse the /CFIDE/main/ide.cfm?ACTION=FILEIO endpoint to arbitrarily read and write files to disk.

A path traversal issue exists within the file upload component of Adobe ColdFusion, specifically the CKEditor file manager plugin. The vulnerability takes advantage of the path parameter in the upload content when making POST requests to /cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/upload.cfm.

This is now known to be exploited in the wild. Honeypots recorded in regions near India were exploited within hours of the PoC’s disclosure.

Attacker IP
103.207.14[.]220 - AS 134862 (Ultimate Internet Services Private Limited) from India

Actionable guidance

Patches have been issued that address these vulnerabilities. Monitoring should be enabled for exposed Adobe ColdFusion instances, with alerts generated for requests to affected endpoints that include RDS read and write calls or path traversal sequences, such as ../../../. The endpoints and Adobe ColdFusion versions include the following:

Endpoints affected
POST /CFIDE/main/ide.cfm?ACTION=FILEIO
POST /cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/upload.cfm

Vulnerable Adobe ColdFusion versions
ColdFusion 2025 (Update 9 and below)
ColdFusion 2023 (Update 20 and below)

Get the Complete Report

The full Intelligence Desk brief includes exhaustive IOC lists, YARA detection rules, detailed remediation playbooks, and OSec’s original threat research. Delivered weekly to partners and clients. REQUEST ACCESS

More briefs
Weekly Situation Report — 8/17/26Aug 20, 2026Weekly Situation Report — 8/10/26Aug 13, 2026Weekly Situation Report — 8/3/26Aug 6, 2026