Rapid responses
runZero’s Rapid Response program provides immediate detection and notification of emerging threats. Older entries are migrated to standalone queries or templates.
Apple macOS Screen Sharing is a built-in utility that allows users to remotely view and control another Mac over a local network or the Internet using the VNC protocol.
Certain versions of macOS Screen Sharing are affected by an authentication bypass vulnerability, due to underlying state management issues. Successful exploitation allows a remote, unauthenticated attacker to bypass credential checks and gain unauthorized access to the system.
There is evidence that CVE-2026-65400 is being actively exploited in the wild, prompting its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026.
The following versions are affected:
- macOS Tahoe 26.x: Versions prior to 26.6.1
- macOS Sequoia 15.x: Versions prior to 15.7.9
- macOS Sonoma 14.x: Versions prior to 14.8.9
os:="Apple macOS%" AND port:5900 AND protocol:vnc
Metabase is an open-source business intelligence tool used by organizations to visualize data and share insights through interactive dashboards. It is typically deployed in corporate environments to provide a graphical interface for querying databases such as PostgreSQL or MySQL.
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the /reset_password database
endpoint and gain administrator access to the connected Metabase instance.
There is evidence that these vulnerabilities are being actively exploited in the wild and the vulnerability has been added to the CISA KEV list August 11th, 2026.
The following versions are affected:
- Metabase: Versions x.63.0 through x.63.4
- Metabase: Versions x.62.0 through x.62.8
- Metabase: Versions x.61.0 through x.61.10
- Metabase: Versions x.60.0 through x.60.16
- Metabase: Versions x.59.0 through x.59.20
- Metabase: Versions x.58.0 through x.58.23
vendor:=Metabase AND product:=Metabase
runZero has identified multiple vulnerabilities in a large subset of major baseboard management controllers (BMCs) that can lead to device compromise or segmentation breakdowns. Details of individual vulnerabilities will be published as the disclosure process completes.
BMCs are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer’s ground-breaking research in 2013. Since Farmer’s original research into Cipher Zero authentication bypass and RAKP password hash disclosure, dozens of new vulnerabilities have been identified in these devices, but none of this research revisits the IPMI protocol itself.
High level details of our findings will be presented at Black Hat 2026 & DEF CON 34.
(protocol:ipmi OR type:=BMC) AND ( hw:=OpenBMC OR hw:="Super Micro IPMI" OR hw:="HP% iLO%" OR hw:="Dell iDRAC%" OR hw:="AMI MegaRAC" OR (hw:="Raritan%" AND type:="Power Device") OR hw:="H3C HDM" OR hw:="Fujitsu%")
N-able N-central is an enterprise remote monitoring and management (RMM) software platform used by managed service providers (MSPs) and internal IT teams to discover, automate, patch, and secure network infrastructure and endpoints across Windows, macOS, Linux, and cloud environments.
Certain versions of N-Central are affected by multiple authentication bypass vulnerabilities:
- CVE-2026-18556: Initial authentication bypass via an alternate path or channel.
- CVE-2026-18577: Secondary authentication bypass resulting from an incomplete patch for CVE-2026-18556.
Successful exploitation allows a remote, unauthenticated attacker to bypass authentication and obtain administrative account access on the server. Administrative access may allow attackers to execute unauthorized commands or establish persistence across managed downstream endpoints.
There is evidence that CVE-2026-18577 is being actively exploited in the wild, prompting its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.
Update (August 4, 2026): There is evidence that CVE-2026-18556 is being actively exploited in the wild, prompting its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on August 4, 2026.
The following versions are affected:
- N-Central: Versions prior to 2026.3.1 Hotfix 1 (Build 2026.3.1.7)
vendor:="N-able" AND product:="N-central"
Gitea is an open-source, self-hosted Git service written in Go that provides web-based repository hosting, issue tracking, and code review capabilities using minimal system resources.
Certain versions of Gitea are affected by a remote code execution (RCE) vulnerability within the diffpatch feature.
By exploiting this through malicious repository content, an attacker can write custom Git hooks into the underlying
repository directory. When these hook scripts are subsequently triggered during Git operations, they execute arbitrary
shell commands with the privileges of the Gitea process user.
On default installations where open self-registration is enabled, successful exploitation allows a remote, unauthenticated attacker, or any user with repository write access, to execute arbitrary commands with the privileges of the Gitea process. Depending on the service account’s permission level, successful compromise enables an attacker to extract sensitive credentials and configurations, and may allow for altering build outputs, potentially threatening the integrity of downstream artifacts.
The following versions are affected:
- Gitea: Versions 1.17 through 1.27.0 (inclusive)
vendor:=Gitea AND product:=Gitea
JetBrains TeamCity is a continuous integration and continuous delivery (CI/CD) server that automates the building, testing, and deployment of software applications across distributed build environments.
Certain versions of TeamCity On-Premises are affected by a remote code execution (RCE) vulnerability exploitable via the server’s agent polling protocol. Successful exploitation allows a remote, unauthenticated attacker with HTTP(S) access to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. Depending on the service account’s permission level, successful compromise enables the attacker to steal sensitive credentials and configurations or alter build outputs, threatening the integrity of build artifacts and downstream CI/CD workflows.
The following versions are affected:
- TeamCity: All On-Premises versions prior to 2026.1.3 and 2025.11.7.
vendor:=JetBrains AND product:=TeamCity
Cisco Secure Firewall Management Center (FMC) is a centralized administrative platform used to configure security policies, manage firmware updates, and aggregate threat telemetry across physical and virtual Cisco security appliances from a single interface.
Certain versions of Cisco FMC are affected by a static credential vulnerability in the web interface. The flaw stems from hardcoded credentials for a low-privileged user account. Successful exploitation allows a remote, unauthenticated attacker with access to the management interface to authenticate with these low-privileged credentials and access sensitive data within the system.
Cisco assigned a high Security Impact Rating (SIR) to the vulnerability, noting that it could be chained with other FMC flaws to elevate privileges. A Rapid Response was issued in March 2026 for CVE-2026-20079, and Cisco appears to have updated its advisory for that CVE alongside this one. However, the exact relationship between the two issues remains unclear, given that CVE-2026-20079 is an authentication bypass vulnerability requiring no privileges.
There is evidence that CVE-2026-20316 is being actively exploited in the wild, prompting its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on July 29, 2026.
The following versions are affected:
- FMC 10.0: Versions prior to hotfix
Cisco_Secure_FW_Mgmt_Center_Hotfix_P-10.0.1.1-2.sh.REL.tar - FMC 7.7: Versions prior to hotfix
Cisco_Secure_FW_Mgmt_Center_Hotfix_AM-7.7.12.1-2.sh.REL.tar - FMC 7.6: Versions prior to hotfix
Cisco_Secure_FW_Mgmt_Center_Hotfix_CY-7.6.5.1-2.sh.REL.tar - FMC 7.4: Versions prior to hotfix
Cisco_Secure_FW_Mgmt_Center_Hotfix_HG-7.4.7.1-3.sh.REL.tar - FMC 7.2: Versions prior to hotfix
Cisco_Secure_FW_Mgmt_Center_Hotfix_HL-7.2.11.1-4.sh.REL.tar - FMC 7.0: Versions prior to hotfix
Cisco_Firepower_Mgmt_Center_Hotfix_GB-7.0.9.1-3.sh.REL.tar
vendor:=Cisco AND product:=FMC
Broadcom VMware vCenter is a centralized management software platform that allows IT administrators to control, monitor, and automate virtualized server infrastructure across multiple ESXi hypervisors from a single interface.
Certain versions of VMware vCenter are affected by multiple vulnerabilities:
-
CVE-2026-59309: An authentication bypass vulnerability in the VMware Directory Service. Successful exploitation allows a remote, unauthenticated attacker with network access to vCenter to gain unauthorized access to the system.
-
CVE-2026-59310: A directory traversal vulnerability in the syslog server. Successful exploitation allows a remote, unauthenticated attacker with network access to vCenter to execute arbitrary code.
The following versions are affected:
- VMware Cloud Foundation & VMware vSphere Foundation 9.1.x.x: Versions prior to 9.1.0.0300
- VMware Cloud Foundation & VMware vSphere Foundation 9.0.x.x: Versions prior to 9.0.2.0100
- VMware vCenter 8.0: Versions prior to 8.0 Update 3k (U3k)
- VMware Cloud Foundation 5.x: Versions prior to 8.0 Update 3k (U3k)
- VMware Telco Cloud Platform (TCP): Versions 3.0, 4.x, 5.0.x, and 5.1.x
- VMware Telco Cloud Infrastructure (TCI): Version 3.0
(vendor:=VMware OR vendor:=Broadcom) AND (product:="vCenter Server" OR product:="vCenter" OR product:="VMware Cloud Foundation")
Each Rapid Response includes a query to find matching assets, a trigger to analyze all inventories for exposure, and a corresponding blog post with the details of the issue. This program focuses on helping customers mitigate exposures before compromise.