0x08
MEMO #008
TARGET: Balbooa Forms 2.4.3.1
2026-08-30
CVSS 9.8 CRITICAL
While variant-hunting the pre-auth upload RCEs in Balbooa Forms, a line-by-line read of the shortcode engine and the payment tasks surfaced two separate flaws: custom-PHP eval() query injection and payment parameter tampering.
CVE-2026-67363
CVE-2026-67364
VERIFIED POC
JOOMLA
VIEW MEMO →
0x07
MEMO #007
TARGET: Apache Gravitino 0.5.0–0.7.0
2026-08-17
CVSS 9.8 CRITICAL
While hunting an incomplete-fix pattern across Apache Gravitino's catalog REST surface, an unauthenticated testConnection endpoint surfaced that hands attacker-controlled jdbc-url strings to the connection factory with zero validation.
CVE-2026-41042
DETERMINISTIC POC
JDBC DRIVER RCE
VIEW MEMO →
0x06
MEMO #006
FRAMEWORK: DropoutJeep v2.1
2026-08-15
RED TEAM SIM
DropoutJeep is a phishing-simulation and red-team platform with 80-plus utility modules spanning OSINT, pretext generation, payload crafting, C2, exfiltration, evasion, persistence, and deliverability.
80+ MODULES
RED TEAM
PHISHING SIM
VIEW MEMO →
0x05
MEMO #005
TARGET: iCagenda 4.0.8–4.0.12
2026-09-12
CVSS 7.2 HIGH
A stored XSS in iCagenda 4.0.8 through 4.0.12, found while rebuilding the extension's KEV-listed upload bug during an incident response. The event submission form stores image and file fields as raw unescaped strings.
CVE-2026-75948
COORDINATED FIX
STORED XSS
VIEW MEMO →
0x04
MEMO #004
TARGET: Grandstream GXP16xx / PBX
2026-08-15
CVSS 9.8 ROOT CHAIN
One unauthenticated request against a Grandstream desk phone is enough to locate the PBX, fingerprint its firmware, and eventually own it, root shell included. Full narrative of the unauth leak to blind SQLi to root.
ROOT CHAIN
PROVEN WEAPONIZATION
VOIP ROOT
VIEW MEMO →