PAN-OS GP Auth Bypass (CVE-2026-0257)
Point hosts at PAN-OS GlobalProtect and flag CVE-2026-0257 (auth bypass) by version, then confirm with an unauthenticated GET. Non-destructive. CISA KEV.
83 workflows built around a known CVE or exploit path — not a generic scanner. Open the graph to see how the check is wired, then point the same nodes at hosts you are authorized to test.
Point hosts at PAN-OS GlobalProtect and flag CVE-2026-0257 (auth bypass) by version, then confirm with an unauthenticated GET. Non-destructive. CISA KEV.
Point hosts at F5 BIG-IP Configuration Utility and flag CVE-2023-46748 (SQL injection) from a version compare plus time-based sleep confirm. Non-destructive.
Fingerprint Next.js hosts, safely probe two advisories, and version-classify CVE-2025-29927 plus React2Shell (CVE-2025-55182).
Flag Apache Tomcat hosts for CVE-2020-1938 by reading Apache Tomcat/x.y.z from a GET 404 probe. Floors 7.0.100 / 8.5.51 / 9.0.31. No AJP.
Flag Jenkins hosts for CVE-2017-1000353 by reading the X-Jenkins header on GET /. Floors 2.57 / LTS 2.46.2. No CLI remoting payload.
Point hosts at Metabase and flag CVE-2026-72898 (SQL injection) by version, then confirm with a sleep-only probe. Non-destructive. CISA KEV.
Flag VMware vCenter hosts for CVE-2021-21973 by reading version and build from GET /sdk. Floor is 7.0 U1c build 17327517. No SSRF.
Flag Atlassian Confluence hosts for CVE-2023-22515 by reading ajs-version-number on /login.action. Floors 8.3.3 / 8.4.3 / 8.5.2. No admin-create.
CVE-2026-8452 is a heap overflow in Citrix NetScaler ADC and Gateway. Version flag only. No confirm: a probe would crash the box or be RCE.
Point hosts at Progress LoadMaster and flag CVE-2026-8037 (command injection) from a version compare, then echo a short token on /accessv2. Non-destructive.
Point hosts at Openfire and flag CVE-2023-32315 (path traversal) by version, then confirm by opening a restricted page. Non-destructive. CISA KEV.
Point hosts at Check Point Quantum and flag CVE-2024-24919 (info disclosure) by version, then confirm with a public MyCRL GET. Non-destructive. CISA KEV.
Check a list of WordPress hosts for the wp2shell pre-auth RCE chain, CVE-2026-63030, by confirming the batch route-confusion SQLi on each one.
Flag SharePoint hosts for CVE-2019-0604 by reading MicrosoftSharePointTeamServices on GET /. Floor is 16.0.10340.12101. No XML deserialize POST.
Flag Atlassian Confluence hosts for CVE-2019-3396 by reading ajs-version-number on /login.action. Floors 6.6.12 / 6.12.3 / 6.13.3 / 6.14.2. No SSTI.
Flag Roundcube Webmail hosts for CVE-2020-12641 by reading the version from GET /CHANGELOG. Floor 1.4.4. No ImageMagick write and no RCE.
Point hosts at SAP NetWeaver and flag CVE-2017-12637 (path traversal) from a version compare, then confirm with a public static file read. Non-destructive.
Flag Roundcube Webmail hosts for CVE-2020-35730 by reading the version at GET /?_task=login. Floors 1.2.13-1.4.10. No XSS payload.
Flag Pulse Connect Secure hosts for CVE-2019-11510 by reading version from GET /dana-na/nc/nc_gina_ver.txt. Floors 8.2R12.1 / 8.3R7.1 / 9.0R3.4.
Flag VMware vCenter hosts for CVE-2021-21985 by reading version and build from GET /sdk. Fixed only at 7.0 U2b build 17958471. No vSAN RCE.
Find self-managed JFrog Artifactory below CVE-2026-82329 CNA floors. Version fingerprint, confirm path, no token mint. Cloud *.jfrog.io marked patched.
Flag ManageEngine Desktop Central for CVE-2021-44515 by reading 10.1.x builds on GET /configurations.do. Floors 10.1.2127.18 / 10.1.2137.3.
Flag Roundcube Webmail hosts for CVE-2021-44026 by reading the version on /?_task=login. Floors 1.3.17 and 1.4.12. No SQLi payload.
CVE-2026-65643 cPanel/WHM parking flaw: authenticated file write can lead to root code execution. Check cpsrvd builds without an exploit.
Flag Roundcube Webmail hosts for CVE-2017-16651 by reading the version from the default response. Floors 1.1.10-1.3.3. No login.
Flag SharePoint hosts for CVE-2023-24955 by reading MicrosoftSharePointTeamServices on /_layouts/15/start.aspx. Unauth May 2023 floors only.
Detect Grafana CVE-2021-43798 with a version check and safe public plugin-file read. The CISA KEV workflow does not read secrets or write files.
Point hosts at TeamCity and flag CVE-2024-27198 by version, then confirm with a GET of /app/rest/server through the ?jsp= bypass. No token write. CISA KEV.
Point hosts at BeyondTrust Remote Support and PRA and flag CVE-2026-1731 (OS command injection) from a version compare plus sleep-only confirm. Non-destructive.
Flag VMware vCenter hosts for CVE-2021-22005 by reading version and build from GET /sdk. 6.5 N/A; 6.7 build 18485166; 7.0.2 build 18356314.
Flag Atlassian Confluence hosts for CVE-2022-26134 by reading ajs-version-number on /login.action. Per-branch floors only. No OGNL.
Confirm CVE-2026-19490 vulnerable SAML configuration with a safe oracle, then review NetScaler title fingerprints and best-effort version rows.
Point hosts at Ivanti Connect Secure and flag CVE-2023-46805 by version, then confirm with an unauthenticated GET of system-information. CISA KEV.
Point hosts at PaperCut NG/MF and flag CVE-2026-81578 by build, then confirm with a read-only admin-page GET. No config write. CISA KEV.
Point hosts at TeamCity and flag CVE-2024-27199 (auth bypass) by version, then confirm by opening the REST path unauthenticated. Non-destructive. CISA KEV.
Flag Jenkins hosts for CVE-2015-5317 by reading the version from the default response. Floors 1.638 / 1.625.2. No Fingerprints browse.
Flag SonicWall Email Security hosts for CVE-2021-20022 by reading the version on GET /login.html. Floor band to 10.0.9.6177. No file upload.
Flag Atlassian Confluence hosts for CVE-2021-26084 by reading ajs-version-number on /login.action. Per-branch floors only. No OGNL.
Flag Microsoft Exchange hosts for CVE-2022-41082 by reading the OWA version path on GET /owa/auth/logon.aspx. Fixed only at 15.2.1118.21. No RCE.
Flag Jenkins hosts for CVE-2018-1000861 by reading the X-Jenkins header on GET /login. Floors 2.154 / LTS 2.138.4 / 2.150.1. No Stapler invoke.
Flag Apache Tomcat hosts for CVE-2017-12617 by reading Apache Tomcat/x.y.z from GET /nonexistent-4041c2b7f. Floors 7.0.82 / 8.0.47 / 8.5.23 / 9.0.1. No PUT.
Flag Microsoft OMI hosts for CVE-2021-38647 by reading ProductVersion from GET /wsman. Floor 1.6.8-1. No SOAP Identify POST and no RCE.
Point hosts at PAN-OS and flag CVE-2024-3400 by version. No confirm: the public probe creates a file on the portal. Version flag only. CISA KEV.
Point hosts at FortiOS and flag CVE-2025-68686 (info disclosure) by version, then confirm with a public /remote/fcnfg GET. Non-destructive. CISA KEV.
Point hosts at Confluence and flag CVE-2023-22518 by version, then confirm with an unauthenticated GET of /json/setup-restore.action. Non-destructive. CISA KEV.
Flag ZK Framework hosts for CVE-2022-36537 by reading the version from the default response. Floors 8.6.4.2-9.6.2. No file read.
Point hosts at Ubiquiti UniFi OS and flag CVE-2026-34909 (path traversal) from a version compare, then confirm by reading a public file. Non-destructive.
Flag Pulse Connect Secure hosts for CVE-2020-8218 by reading version from GET /dana-na/nc/nc_gina_ver.txt. FIXED floor 9.1R8 / 9.1.8. No admin code inject.
Flag Microsoft Exchange hosts for CVE-2022-41040 by reading the OWA version path on GET /owa/auth/logon.aspx. 15.0/15.1/15.2 floors. No SSRF.
Version-classify self-hosted workflow-automation hosts for CVE-2026-21858 (Ni8mare) and optionally confirm a form-endpoint canary on hosts you own.
Point hosts at Progress MOVEit Transfer and flag CVE-2023-34362 (SQL injection) from a version compare, then a sleep-only confirm. Non-destructive.
Flag Laravel apps for CVE-2021-3129 by reading laravel_version from a GET debug-surface probe. Floor 8.4.2. Needs debug markers. No file-write RCE.
Point hosts at N-central and flag CVE-2026-18577 (auth bypass) by version, then confirm on a DWR path without credentials. Non-destructive. CISA KEV.
Flag Microsoft OMI hosts for CVE-2021-38648 by reading ProductVersion from GET /wsman. Floor 1.6.8-1. No SOAP Identify POST and no PrivEsc.
Point hosts at Roundcube and flag CVE-2025-49113 by version. No confirm: the _from gadget needs a login and deserializes PHP. Version flag only. CISA KEV.
Point hosts at TeamCity and flag CVE-2023-42793 by version, then confirm with a GET of /app/rest/users/id:1/tokens/RPC2. No token write. CISA KEV.
Flag Microsoft Exchange hosts for CVE-2023-21529 by reading the OWA version path on GET /owa/auth/logon.aspx. 15.0/15.1/15.2 floors. No deser RCE.
Point hosts at Langflow and flag CVE-2026-33017 (code injection) from a version compare, then sleep on the unauthenticated build path. Non-destructive.
Point hosts at Jira Server/DC and flag CVE-2021-26086 (path traversal) by version, then confirm with a public web.xml read. Non-destructive. CISA KEV.
Point hosts at SharePoint and flag CVE-2025-53770 by version, then confirm with a ToolPane GET and a SignOut referer. No ViewState gadget. CISA KEV.
Flag Atlassian Confluence hosts for CVE-2019-3398 by reading ajs-version-number on /login.action. Floors 6.6.13 through 6.15.2. No traversal.
Flag Atlassian Confluence hosts for CVE-2021-26085 by reading ajs-version-number on /login.action. Floor is 7.12.3. No /s/ file read.
Flag Microsoft Exchange hosts for CVE-2022-41080 by reading the OWA version path on GET /owa/auth/logon.aspx. 15.0/15.1/15.2 floors. No PrivEsc.
Flag Metabase hosts for CVE-2021-41277 by reading version.tag from /api/session/properties. Only x.40.0-x.40.4. No GeoJSON fetch.
Point hosts at ConnectWise ScreenConnect and flag CVE-2024-1708 (path traversal) from a version compare, then a public-file confirm. Non-destructive.
Flag Roundcube Webmail hosts for CVE-2020-13965 by reading the version at GET /?_task=login. Floors 1.3.12 / 1.4.5. No XSS payload.
Point hosts at Confluence and flag CVE-2023-22527 by version, then confirm with a GET of /template/aui/text-inline.vm. No OGNL. CISA KEV.
Flag Atlassian Jira hosts for CVE-2019-11581 by reading version on GET /login.jsp. Floors 7.6.14 / 7.13.5 / 8.0.3 / 8.1.2 / 8.2.3. No SSTI.
Flag Apache Tomcat hosts for CVE-2016-8735 by reading Apache Tomcat/x.y.z from GET /nonexistent-404-probe. Floors 6.0.48-9.0.0. No JMX/RMI.
Detect Jenkins CVE-2024-23897 with a version check and safe /cli availability probe. The CISA KEV workflow never expands @-files.
Point hosts at SonicWall SMA 1000 and flag CVE-2026-83548 by hotfix, then confirm with a GET of /wsproxy. No destination URL.
Point hosts at Ivanti Connect Secure and flag CVE-2024-21887 by version. Confirm is the 46805 bypass GET only. No command injection. CISA KEV.
Point hosts at vCenter and flag CVE-2022-22948 (info disclosure) by version, then confirm with a public metadata GET. Non-destructive. CISA KEV.
Flag Grafana hosts for CVE-2021-39226 by reading version from GET /api/health. Floors 7.5.11 / 8.1.6. No snapshot GET, delete, or data disclosure.
Point hosts at SmarterMail and flag CVE-2026-23760 (auth bypass) by version, then confirm via the password-reset API. Non-destructive. CISA KEV.
Flag VMware vCenter hosts for CVE-2021-21972 by reading version and build from GET /sdk. Floors 6.5 U3n / 6.7 U3l / 7.0 U1c. No plugin upload.
Point hosts at Superset and flag CVE-2023-27524 by version, then confirm with a local HMAC of the issued session cookie. It never forges a cookie. CISA KEV.
Flag Citrix NetScaler SD-WAN hosts for CVE-2017-6316 by parsing /rN-N-N-N-N/ from GET /. FIXED floor 9.1.2.26.561202. No cookie cmd inject.
Flag Pulse Connect Secure for CVE-2019-11539 via GET /dana-na/nc/nc_gina_ver.txt. Floors 8.1.15.59747 / 8.2.12.64003 / 8.3.7.65025 / 9.0.3.64053. No cmd inject.
Point hosts at FortiAnalyzer and flag CVE-2026-24858 (auth bypass) by version, then confirm on a protected REST path. Non-destructive. CISA KEV.
Point hosts at PHP and flag CVE-2024-4577 by version. No confirm: a Best-Fit probe would execute PHP. Version and banner only. CISA KEV.
Point hosts at Tomcat and flag CVE-2025-24813 by version, then confirm with OPTIONS if PUT is advertised. No file write. CISA KEV.
Point hosts at LiteLLM and flag CVE-2026-42208 (SQL injection) by version, then confirm with a sleep-only probe. Non-destructive. CISA KEV.