Rapid responses

runZero’s Rapid Response program provides immediate detection and notification of emerging threats. Older entries are migrated to standalone queries or templates.

10
Rapid Responses
6
software
3
assets
1
services
10 of 10 rapid responses
BMC Vulnerabilities - runZero Research
Type:assetsPublished:Aug 4, 2026

runZero has identified multiple vulnerabilities in a large subset of major baseboard management controllers (BMCs) that can lead to device compromise or segmentation breakdowns. Details of individual vulnerabilities will be published as the disclosure process completes.

BMCs are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer’s ground-breaking research in 2013. Since Farmer’s original research into Cipher Zero authentication bypass and RAKP password hash disclosure, dozens of new vulnerabilities have been identified in these devices, but none of this research revisits the IPMI protocol itself.

High level details of our findings will be presented at Black Hat 2026 & DEF CON 34.

(protocol:ipmi OR type:=BMC) AND ( hw:=OpenBMC OR  hw:="Super Micro IPMI" OR  hw:="HP% iLO%" OR  hw:="Dell iDRAC%" OR  hw:="AMI MegaRAC" OR  (hw:="Raritan%" AND type:="Power Device") OR  hw:="H3C HDM" OR  hw:="Fujitsu%")
N-Able N-Central Multiple Vulnerabilities (2026-08)
Type:softwarePublished:Aug 3, 2026

N-able N-central is an enterprise remote monitoring and management (RMM) software platform used by managed service providers (MSPs) and internal IT teams to discover, automate, patch, and secure network infrastructure and endpoints across Windows, macOS, Linux, and cloud environments.

Certain versions of N-Central are affected by multiple authentication bypass vulnerabilities:

  • CVE-2026-18556: Initial authentication bypass via an alternate path or channel.
  • CVE-2026-18577: Secondary authentication bypass resulting from an incomplete patch for CVE-2026-18556.

Successful exploitation allows a remote, unauthenticated attacker to bypass authentication and obtain administrative account access on the server. Administrative access may allow attackers to execute unauthorized commands or establish persistence across managed downstream endpoints.

There is evidence that CVE-2026-18577 is being actively exploited in the wild, prompting its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.

Update (August 4, 2026): There is evidence that CVE-2026-18556 is being actively exploited in the wild, prompting its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on August 4, 2026.

The following versions are affected:

  • N-Central: Versions prior to 2026.3.1 Hotfix 1 (Build 2026.3.1.7)
vendor:="N-able" AND product:="N-central"
Gitea RCE (CVE-2026-60004)
Type:softwarePublished:Jul 30, 2026

Gitea is an open-source, self-hosted Git service written in Go that provides web-based repository hosting, issue tracking, and code review capabilities using minimal system resources.

Certain versions of Gitea are affected by a remote code execution (RCE) vulnerability within the diffpatch feature. By exploiting this through malicious repository content, an attacker can write custom Git hooks into the underlying repository directory. When these hook scripts are subsequently triggered during Git operations, they execute arbitrary shell commands with the privileges of the Gitea process user.

On default installations where open self-registration is enabled, successful exploitation allows a remote, unauthenticated attacker, or any user with repository write access, to execute arbitrary commands with the privileges of the Gitea process. Depending on the service account’s permission level, successful compromise enables an attacker to extract sensitive credentials and configurations, and may allow for altering build outputs, potentially threatening the integrity of downstream artifacts.

The following versions are affected:

  • Gitea: Versions 1.17 through 1.27.0 (inclusive)
vendor:=Gitea AND product:=Gitea
JetBrains TeamCity RCE (CVE-2026-63077)
Type:softwarePublished:Jul 30, 2026

JetBrains TeamCity is a continuous integration and continuous delivery (CI/CD) server that automates the building, testing, and deployment of software applications across distributed build environments.

Certain versions of TeamCity On-Premises are affected by a remote code execution (RCE) vulnerability exploitable via the server’s agent polling protocol. Successful exploitation allows a remote, unauthenticated attacker with HTTP(S) access to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. Depending on the service account’s permission level, successful compromise enables the attacker to steal sensitive credentials and configurations or alter build outputs, threatening the integrity of build artifacts and downstream CI/CD workflows.

The following versions are affected:

  • TeamCity: All On-Premises versions prior to 2026.1.3 and 2025.11.7.
vendor:=JetBrains AND product:=TeamCity
Cisco Secure Firewall Management Center Static Credential Vulnerability (CVE-2026-20316)
Type:softwarePublished:Jul 29, 2026

Cisco Secure Firewall Management Center (FMC) is a centralized administrative platform used to configure security policies, manage firmware updates, and aggregate threat telemetry across physical and virtual Cisco security appliances from a single interface.

Certain versions of Cisco FMC are affected by a static credential vulnerability in the web interface. The flaw stems from hardcoded credentials for a low-privileged user account. Successful exploitation allows a remote, unauthenticated attacker with access to the management interface to authenticate with these low-privileged credentials and access sensitive data within the system.

Cisco assigned a high Security Impact Rating (SIR) to the vulnerability, noting that it could be chained with other FMC flaws to elevate privileges. A Rapid Response was issued in March 2026 for CVE-2026-20079, and Cisco appears to have updated its advisory for that CVE alongside this one. However, the exact relationship between the two issues remains unclear, given that CVE-2026-20079 is an authentication bypass vulnerability requiring no privileges.

There is evidence that CVE-2026-20316 is being actively exploited in the wild, prompting its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on July 29, 2026.

The following versions are affected:

  • FMC 10.0: Versions prior to hotfix Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar
  • FMC 7.7: Versions prior to hotfix Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar
  • FMC 7.6: Versions prior to hotfix Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar
  • FMC 7.4: Versions prior to hotfix Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar
  • FMC 7.2: Versions prior to hotfix Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar
  • FMC 7.0: Versions prior to hotfix Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar
vendor:=Cisco AND product:=FMC
Broadcom VMware vCenter Multiple Vulnerabilities (2026-07)
Type:softwarePublished:Jul 29, 2026

Broadcom VMware vCenter is a centralized management software platform that allows IT administrators to control, monitor, and automate virtualized server infrastructure across multiple ESXi hypervisors from a single interface.

Certain versions of VMware vCenter are affected by multiple vulnerabilities:

  • CVE-2026-59309: An authentication bypass vulnerability in the VMware Directory Service. Successful exploitation allows a remote, unauthenticated attacker with network access to vCenter to gain unauthorized access to the system.

  • CVE-2026-59310: A directory traversal vulnerability in the syslog server. Successful exploitation allows a remote, unauthenticated attacker with network access to vCenter to execute arbitrary code.

The following versions are affected:

  • VMware Cloud Foundation & VMware vSphere Foundation 9.1.x.x: Versions prior to 9.1.0.0300
  • VMware Cloud Foundation & VMware vSphere Foundation 9.0.x.x: Versions prior to 9.0.2.0100
  • VMware vCenter 8.0: Versions prior to 8.0 Update 3k (U3k)
  • VMware Cloud Foundation 5.x: Versions prior to 8.0 Update 3k (U3k)
  • VMware Telco Cloud Platform (TCP): Versions 3.0, 4.x, 5.0.x, and 5.1.x
  • VMware Telco Cloud Infrastructure (TCI): Version 3.0
(vendor:=VMware OR vendor:=Broadcom) AND (product:="vCenter Server" OR product:="vCenter" OR product:="VMware Cloud Foundation")
Check Point Multiple Vulnerabilities (2026-07)
Type:assetsPublished:Jul 23, 2026

Check Point Security Gateways act as physical or virtual enforcement points that inspect network traffic and execute access rules in real time. The Security Management Server serves as the centralized database and control plane that stores configuration settings, processes logs, and compiles security policies to deploy to those gateways. SmartConsole is the graphical interface, available as a Windows client or web application, that administrators use to configure policies, manage network objects, and monitor system health. Multi-Domain Security Management (MDS) extends this architecture by hosting multiple, isolated virtual management servers on a single platform to serve complex multi-tenant or enterprise environments.

Certain versions of Check Point products are affected by multiple vulnerabilities:

  • CVE-2026-16232: An authentication bypass vulnerability in the SmartConsole login process that allows a remote, unauthenticated attacker to obtain an application login token and authenticate with full administrative privileges. To exploit this, the attacker must have network access to the management interface, and the system must lack Trusted Clients (GUI clients) restrictions. Successful exploitation permits full modification of security policies and configurations.

  • CVE-2026-62144: An authentication bypass vulnerability in the Security Management and Multi-Domain Security Management servers that allows a remote, unauthenticated attacker to execute administrative commands on the server, including run-script and exec-command on managed Security Gateways. The attacker must have access to the management interface, and the system must lack firewall protections or Trusted Clients restrictions.

  • CVE-2026-62145: A local privilege escalation vulnerability in the Gaia Portal that allows an authenticated, low-privileged (read-only) attacker to execute arbitrary commands with root privileges.

There is evidence that CVE-2026-16232 is being actively exploited in the wild, prompting its addition to the CISA KEV catalog on July 22, 2026.

The following versions are affected:

  • Security Management Server, Multi-Domain Security Management Server (MDS), Security Gateways: R81.20, R82, R82.10, and End-of-Support (EOS) versions R77.30 through R81.10.

Note: Spark Gateways are not affected.

os:="Check Point Gaia"
WordPress Multiple Vulnerabilities (2026-07)
Type:servicesPublished:Jul 18, 2026

WordPress is a content management system that is designed for blog publishing and management of web content. It is widely deployed with a large set of plugins and is used for a wide variety of applications.

Certain versions of WordPress are affected by two vulnerabilities, dubbed wp2shell. Successful exploitation of these issues may allow an unauthenticated remote attacker to conduct an SQL injection and gain remote administrative access and remote code execution on the vulnerable WordPress instances.

  • CVE-2026-60137: A SQL injection vulnerability in a WordPress query.
  • CVE-2026-63030: A REST API batch endpoint confusion issue.

The following versions are affected:

  • 6.9.0 through 6.9.4
  • 7.0.0 through 7.0.1
  • 7.1 beta
product:"wordpress" AND _service.product:wordpress
SonicWall SMA1000 Appliances Multiple Vulnerabilities (2026-07)
Type:assetsPublished:Jul 14, 2026

SonicWall Secure Mobile Access (SMA) 1000 series appliances are hardware security devices that provide zero-trust and secure access gateway support for businesses.

Certain versions of the SonicWall SMA1000 appliances are affected by multiple vulnerabilities:

  • CVE-2026-15409: An Server-Side Request Forgery (SSRF) vulnerability allows a remote unauthenticated attacker to access internal server resources and unintended locations.

  • CVE-2026-15410: An authenticated remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console (AMC) could allow an attacker with administrator permissions to execute OS commands.

There is evidence that these vulnerabilities are being actively exploited in the wild and the vulnerability has been added to the CISA KEV list July 14th, 2026.

The following versions are affected

  • SMA1000 Models - 6210, 7210, 8200v
    • 12.4.3-03245
    • 12.4.3-03387
    • 12.4.3-03434
    • 12.5.0-02283
    • 12.5.0-02624
    • 12.5.0-02800
hw:="SonicWall SMA1000" AND os_version:>0 AND (os_version:=12.4.3 OR os_version:=12.5.0)
Microsoft SharePoint Multiple Vulnerabilities (2026-07)
Type:softwarePublished:Jul 14, 2026

Microsoft SharePoint is a web-based collaboration and document management platform, available both within Microsoft 365 and as on-premises software, that serves as a secure, centralized hub for storing, organizing, and sharing information across devices.

Certain versions of SharePoint Server are affected by multiple vulnerabilities:

  • CVE-2026-55040: An authentication bypass vulnerability stemming from weaknesses in how it validates JSON Web Tokens (JWTs). A remote, unauthenticated attacker who knows or enumerates a target user’s Active Directory Security ID (SID) or User Principal Name (UPN) can leverage this flaw to bypass authentication checks. Successful exploitation grants the attacker unauthorized access, allowing them to perform actions, disclose files, and modify data under the identity of the impersonated user, including administrators.

  • CVE-2026-56164: A privilege escalation vulnerability stemming from missing authentication for a critical function. Successful exploitation allows a remote, unauthenticated attacker to elevate privileges.

Vulnerability researchers disclosed that CVE-2026-55040 is the first link in a high-impact, two-vulnerability exploit chain originally developed for the Pwn2Own Berlin hacking competition. The second vulnerability, yet to be publicly disclosed, is a remote code execution (RCE) flaw. Microsoft plans to patch the RCE vulnerability during its August 2026 security update cycle. Applying the July 2026 patch for CVE-2026-55040 is critical, as it successfully disrupts this exploit chain and prevents unauthenticated RCE.

There is evidence that CVE-2026-56164 is being actively exploited in the wild, prompting its addition to the CISA KEV catalog on July 14, 2026.

The following versions are affected:

  • SharePoint Enterprise Server 2016: Versions prior to 16.0.5561.1001
  • SharePoint Server 2019: Versions prior to 16.0.10417.20175
  • SharePoint Server Subscription Edition: Versions prior to 16.0.19725.20434

Severity & Risk Assessment

  • Severity: Critical – Successful exploitation allows an attacker to bypass authentication, disclose files, modify data, and elevate privileges. Furthermore, CVE-2026-55040 can be seamlessly chained with an upcoming unauthenticated RCE flaw.
  • Risk: High – These vulnerabilities can be exploited by an unprivileged remote attacker. The active in-the-wild exploitation of CVE-2026-56164, combined with the low barrier to entry for acquiring target identifiers required for CVE-2026-55040, significantly increases the likelihood of widespread exploitation.
vendor:=Microsoft AND version:>0 AND ( (product:="SharePoint Server 2016" AND (version:>=16.0.4107.1002 AND version:<16.0.5561.1001)) OR (product:="SharePoint Server 2019" AND (version:>=16.0.10337.12109 AND version:<16.0.10417.20175)) OR (product:="SharePoint Server Subscription Edition" AND (version:>=16.0.0.1 AND version:<16.0.19725.20434)) )

Each Rapid Response includes a query to find matching assets, a trigger to analyze all inventories for exposure, and a corresponding blog post with the details of the issue. This program focuses on helping customers mitigate exposures before compromise.

Vulnerabilities covered by the Rapid Response program are replaced by more specific coverage as mitigations become available.
Updated