<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Command-Injection on CuraSec</title><link>https://curasec.metacog.co.kr/tags/command-injection/</link><description>Recent content in Command-Injection on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 10 Aug 2026 11:57:16 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/command-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>Progress LoadMaster command injection flaw actively exploited (CISA KEV)</title><link>https://curasec.metacog.co.kr/insights/2026-08-10-critical-progress-loadmaster-flaw-now-actively-exploited-in/</link><pubDate>Mon, 10 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-10-critical-progress-loadmaster-flaw-now-actively-exploited-in/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA has flagged active exploitation of this critical command injection flaw in Progress Kemp LoadMaster; patch to the latest fixed version immediately and audit LoadMaster logs for signs of prior compromise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Edge device under active exploitation warrants an assume-breach posture — sweep LoadMaster access logs for anomalous commands or unexpected outbound connections since the vulnerability was disclosed, and tune detections on traffic originating from load balancer management interfaces.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm whether LoadMaster is deployed anywhere in the environment and verify your engineering team has prioritized patching; this is not yet a board-level systemic event but CISA active-exploitation designation means it should be on the remediation radar this week.&lt;/li>
&lt;/ul></description></item><item><title>Arista patches VeloCloud Orchestrator zero-day exploited in attacks</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-arista-patches-velocloud-orchestrator-zero-day-exploited-in/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-arista-patches-velocloud-orchestrator-zero-day-exploited-in/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Maximum-severity command injection in VeloCloud Orchestrator is actively exploited — if you run on-premises VeloCloud Orchestrator, patch immediately and audit for signs of compromise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of a max-severity edge orchestrator means assume-breach posture for any environment running on-prem VeloCloud Orchestrator — hunt for anomalous command execution or lateral movement from those hosts since before the patch date.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A maximum-severity zero-day actively exploited in SD-WAN infrastructure warrants immediate confirmation of whether VeloCloud Orchestrator is in use on-premises, and if so, direct the team to patch and assess exposure before this surfaces as a board-level incident.&lt;/li>
&lt;/ul></description></item><item><title>Zimbra Patches Critical SNMP Command Injection and Four XSS Flaws</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-zimbra-patches-critical-snmp-command-injection-and-four-xss/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-zimbra-patches-critical-snmp-command-injection-and-four-xss/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Upgrade Zimbra to 10.1.20 to remediate the SNMP command injection (triggered when SNMP notifications are enabled) and four XSS issues; no KEV listing or public PoC raises urgency to Act, but the critical rating warrants scheduling patching this sprint.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>CVE-2026-25089: FortiSandbox unauthenticated RCE added to CISA KEV</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-cve-2026-25089-fortisandbox-unauthenticated-command-injectio/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-cve-2026-25089-fortisandbox-unauthenticated-command-injectio/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> FortiSandbox is actively exploited per CISA KEV listing with a public PoC on GitHub; patch to the fixed version immediately and check for signs of compromise on any internet-facing FortiSandbox appliances.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> KEV listing plus public PoC means exploitation is likely underway; hunt for anomalous outbound connections or new processes spawned from FortiSandbox hosts since the PoC publication date, and check edge appliance logs for unauthenticated command-injection attempts.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> KEV-listed Fortinet RCE warrants confirming whether FortiSandbox is in the environment and requesting patch status from the infrastructure team; brief on remediation timeline if deployed, given the active exploitation signal.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-25089 — CISA KEV: listed, EPSS 0.36, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>