// the notebook
Research
CVE teardowns, root-cause notes and threat-intel writeups. We publish when the disclosure timeline allows it — no fixed cadence, no filler. Newest first.
-
CVE-2026-22769: hardcoded Tomcat credentials in Dell RecoverPoint
A username/password pair baked into the Tomcat Manager config of Dell RecoverPoint for VMs gave UNC6201 unauthenticated root on backup appliances — and a pivot into the VMware estate behind them. Exploited quietly since mid-2024.
Read the teardown → -
CVE-2026-21509: Microsoft Office OLE security-feature bypass
A CWE-807 bypass that makes an OLE mitigation decision on an attacker-controlled value inside a crafted RTF, loading restricted COM components such as Shell.Explorer.1. Full root cause, the APT28 attack chain documented by CERT-UA, detection guidance, IoCs and mitigation.
Read the teardown → -
CVE-2025-32975: Quest KACE SMA SSO authentication bypass
An SSO flaw in Quest KACE Systems Management Appliance that lets an unauthenticated attacker impersonate any user — admins included — and take over a platform that can push code to every managed endpoint.
Read the teardown → -
CVE-2025-24990: untrusted pointer dereference in Windows
A privileged Windows component dereferences a pointer from an untrusted context without validating it, giving a low-priv attacker arbitrary memory access and a reliable path to SYSTEM. Exploited in the wild in 2025.
Read the teardown → -
CVE-2025-20352: SNMP stack overflow in Cisco IOS / IOS XE
A stack-based buffer overflow in the SNMP subsystem of Cisco IOS / IOS XE: a crafted packet to UDP/161 overwrites the stack and hands an unauthenticated attacker code execution at the core of the network.
Read the teardown → -
CVE-2025-10035: GoAnywhere MFT License Servlet deserialization RCE
A perfect-10 deserialization chain in Fortra GoAnywhere MFT: a forged license response signature lets an unauthenticated attacker deserialize an arbitrary object and reach command execution. Root cause, attack chain, detection and mitigation.
Read the teardown → -
CVE-2025-5777 (CitrixBleed 2): NetScaler pre-auth memory disclosure
An out-of-bounds read on NetScaler ADC/Gateway auth endpoints that leaks ~127 bytes of uninitialized stack memory per request — including NSC_AAAC session tokens — to unauthenticated attackers, enabling session hijack and MFA bypass.
Read the teardown → -
CVE-2025-33073: Windows SMB Client reflection to SYSTEM
An improper access control flaw in mrxsmb.sys that revives NTLM reflection: coerce a host to authenticate to a malicious SMB server and the auth context reflects back as a local SYSTEM token. Why SMB signing is the control that matters.
Read the teardown →
More notes go out on the low-volume list. We don't do a newsletter cadence; you'll hear from us when there's something worth reading.