Full Width [alt+shift+f] Shortcuts [alt+shift+k]
Sign Up [alt+shift+s] Log In [alt+shift+l]

watchTowr Labs

Sort By

Recent [alt+2]
Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're...
a week ago
1
a week ago
Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce...
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your...
14th Aug 2026
1

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))

from watchTowr Labs [alt+shift+b] in technology

14th Aug 2026
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded. You know the drill - it’s the typical enterprise “please don’t be
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68... We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is...
2nd Jul 2026
1
2nd Jul 2026
We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working. Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to have confidence
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command... Today, Ivanti published an advisory. “No way?” we hear you say. "Yes way!" a random dog screams back...
10th Jun 2026
1
10th Jun 2026
Today, Ivanti published an advisory. “No way?” we hear you say. "Yes way!" a random dog screams back at you, across the street. Today’s rare advisory outlines two vulnerabilities in Ivanti’s Sentry product, appealing directly to our inner desire for sophisticated server-side,
You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699... If you squint and look at the CISA KEV list, you might think it's made up exclusively of...
2nd Apr 2026
1
2nd Apr 2026
If you squint and look at the CISA KEV list, you might think it's made up exclusively of vulnerabilities in file transfer solutions. While this would be wrong (and you shouldn’t squint, it’s bad for your eyes), file transfer solutions do play a decent
Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE) On today’s ‘good news disguised as other things’ segment, we’re turning our gaze to CVE-2026-21902 -...
3rd Mar 2026
1
3rd Mar 2026
On today’s ‘good news disguised as other things’ segment, we’re turning our gaze to CVE-2026-21902 - a recently disclosed “Incorrect Permission Assignment for Critical Resource” vulnerability affecting Juniper’s Junos OS Evolved platform. This vulnerability affects only Juniper’s...
Buy A Help Desk, Bundle A Remote Access Solution? (SolarWinds Web Help Desk Pre-Auth RCE Chain(s)) It’s been a while, but we’re back - in time for story time. Gather round, strap in, and prepare for...
25th Feb 2026
1
25th Feb 2026
It’s been a while, but we’re back - in time for story time. Gather round, strap in, and prepare for another depressing journey of “all we wanted to do was reproduce an N-day, and here we are with 0-days”. Today, friends, we’re
Do Smart People Ever Say They’re Smart? (SmarterTools SmarterMail Pre-Auth RCE CVE-2025-52691) Welcome to 2026! While we are all waiting for the scheduled SSLVPN ITW exploitation programming that...
8th Jan 2026
4
8th Jan 2026
Welcome to 2026! While we are all waiting for the scheduled SSLVPN ITW exploitation programming that occurs every January, we’re back from Christmas and idle hands, idle minds, yada yada. In December, we were alerted to a vulnerability in SmarterTools’ SmarterMail solution,...
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN...
10th Dec 2025
1
10th Dec 2025
Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025). Weeeeeeeee. Before then, we want to clear the decks and see how much research we can publish. This
What’s That Coming Over The Hill? (Monsta FTP Remote Code Execution CVE-2025-34299) Happy Friday, friends and.. others. We’re glad/sorry to hear that your week has been good/bad, and...
7th Nov 2025
1
7th Nov 2025
Happy Friday, friends and.. others. We’re glad/sorry to hear that your week has been good/bad, and it’s the weekend/but at least it’s almost the weekend! What’re We Doing Today, Mr Fox? Today, in a tale that seems all too
📚 BoredReading

You seem to be enjoying this.

Join free to unlock everything.

Create free account

Already have an account? Sign in