RECONINTEL
◄ BACK
// INTELLIGENCE FEED

RECON BLOG

June 3, 2026 · 5 minCVSS 9.8

CVE-2026-44825: Apache Solr Hardcoded Credentials — Detect Exposed Instances

Apache Solr's auth setup tool silently installs four accounts with passwords identical to their usernames. CVSS 9.8 Critical, no patch released yet. Affects 12,000+ organizations.

READ ADVISORY →
May 30, 2026 · 5 minCVSS 9.1

CVE-2026-0257: Palo Alto PAN-OS GlobalProtect Authentication Bypass — Find Exposed Firewalls

An actively exploited authentication bypass in PAN-OS GlobalProtect lets unauthenticated attackers establish VPN connections. CISA KEV listed with a 3-day remediation deadline.

READ ADVISORY →
May 29, 2026 · 5 minCRITICAL

CVE-2026-9874: Critical Chrome Dawn WebGPU Use-After-Free — How to Detect Vulnerable Browsers

A critical use-after-free in Chrome's Dawn WebGPU implementation could allow remote code execution. Part of a 151-vulnerability Chrome 148 update with 22 critical flaws across Dawn, WebGL, and ANGLE.

READ ANALYSIS →
May 29, 2026 · 5 minANALYSIS

Six Windows Zero-Days, Two Platform Bans: A Defender Triage Guide

A researcher dropped six Windows zero-days since early April and got banned from GitHub and GitLab. Three exploits remain unpatched. A practical triage checklist for defenders.

READ ANALYSIS →
May 27, 2026 · 6 minCVSS 6.5

CVE-2026-48710: Finding Vulnerable Starlette and FastAPI Services on Your Network

A Host header injection in Starlette bypasses path-based auth middleware. Affects FastAPI, vLLM, LiteLLM, MCP servers, and thousands of AI infrastructure services.

READ ADVISORY →
May 27, 2026 · 5 minCVSS 10.0

CVE-2026-20223: Finding Cisco Secure Workload (Tetration) on Your Network

A maximum-severity authentication bypass in Cisco Secure Workload (CVSS 10.0) lets unauthenticated attackers gain Site Admin access via an internal REST API. Identify instances on your network using RECON.

READ ADVISORY →
May 26, 2026 · 4 minCVSS 9.1

CVE-2026-35616: How to Find FortiClient EMS Instances on Your Network

A critical zero-day in Fortinet's endpoint management server has been actively exploited since late March. Walk through identifying FortiClient EMS instances using RECON.

READ ADVISORY →