Skip to content

company

VulnCheck

Vulnerability intelligence company that tracks exploited CVEs, scanning activity, and initial-access threats, and acts as a CVE Numbering Authority.

Known aliases

  • VulnCheck CNA
  • vulncheck.com
  • VulnCheck Inc.
  • VulnCheck Initial Access Intelligence
  • VulnCheck Target Intelligence
  • VulnCheck zero-day research team

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

HFS leaks the Math.random() state that signs its admin cookies

Rejetto HFS 3.0.0 through 3.2.0 signs session cookies with a Math.random() key, and five leaked PRNG outputs let an attacker forge an admin session. Exploitation began on October 1, and version 3.2.1 restores secure key generation.

Publishers:dev.to

Reality

Evidence70
Adoption72
Hype gap0
Incentives50
Confidence65
build1 publisher

vm2's prefix allowlist let one approved module load its unapproved siblings

vm2's maintainer patched a CVSS 9.5 flaw in 3.12.2 where the module allowlist matched an approved path as a bare prefix and cleared a neighboring package. With NodeVM's default host context, the unapproved sibling ran with full Node authority.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives
Insufficient
Confidence58
security5 publishers

Exploited within hours: MLflow SSRF and FUXA auth bypass join the emergency patch list

watchTowr says attackers are already pulling cloud credentials through MLflow's Tracking Server, and VulnCheck logged scanning against a FUXA path traversal a day later.

Perspective Coverage

5 publishers
Builder
Builder 29%
Operator
Operator 63%
Investor
Investor 8%

Reality

Evidence72
Adoption55
Hype gap+20
Incentives35
Confidence70
security4 publishers

NASA's AIT-GUI Ground Console Shipped Without Auth: CVSS 9.4, Fixed in 2.5.2

A flaw in NASA's open-source AIT-GUI lets unauthenticated requests reach spacecraft command routes, and Cycode says a malicious web page can deliver them through an operator's browser.

Perspective Coverage

4 publishers
Builder
Builder 43%
Operator
Operator 50%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+30
Incentives45
Confidence65
security4 publishers

Detections on VulnCheck's canaries climb from 50 to 360 amid Langflow, Rails exploitation

The probes read Langflow's secret key file and grep the process environment for OpenAI and AWS credentials, which puts an AI orchestration tool on the same scanning clock as the Rails file-read bug of the same week.

Perspective Coverage

4 publishers
Builder
Builder 30%
Operator
Operator 60%
Investor
Investor 10%

Reality

Evidence62
Adoption40
Hype gap+15
Incentives65
Confidence60
security2 publishers

FBI disrupts the Nanjing contractor that sold QScan and QTRouter to Chinese espionage operators

QTYF built and ran the scanning and routing frameworks other Chinese teams pointed at U.S. critical infrastructure. That means the proxy addresses and scan fingerprints in your logs point to the supplier; the intruder behind them stays unnamed.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 58%
Investor
Investor 19%

Reality

Evidence55
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence60
security3 publishers

CISA reframes the CVE program around data quality as 2026 heads for 96,000 records

Disclosure volume is climbing faster than the process around it. CISA's answer is a framework that describes what a good CVE record is and how the program should be judged on producing one.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+30
Incentives55
Confidence66
security16 publishers

Cisco patches an ISE authentication bypass attackers used before the fix existed

CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.

Perspective Coverage

16 publishers
Builder
Builder 18%
Operator
Operator 64%
Investor
Investor 18%

Reality

Evidence82
Adoption58
Hype gap−8
Incentives62
Confidence80

Earlier coverage

  1. A spoofed Host header let DeepSeek Harness agents switch off their own sandbox

    Product · September 9, 2026 · 1 publisher

  2. One shell command let a DeepSeek Harness agent switch off its own file sandbox

    Security · September 9, 2026 · 1 publisher

  3. Two agent sandboxes ship an unauthenticated shell endpoint on every interface

    Build · September 6, 2026 · 1 publisher

  4. Counting from the vendor advisory stretches the exploitation window to 116 days

    Build · September 5, 2026 · 1 publisher

  5. Langflow's exploited-in-the-wild count climbed from one bug to twelve in six months

    Product · September 2, 2026 · 1 publisher

  6. A root implant in ZBT router firmware takes orders from whoever holds the C2 position

    Build · September 2, 2026 · 1 publisher

  7. Active Storage routed stranger-supplied uploads into libvips MATLAB and NIfTI loaders

    Security · August 31, 2026 · 1 publisher

  8. Answering one hardcoded address gives you root on 20+ Zbtlink router models

    Build · August 31, 2026 · 1 publisher

  9. Two Nim implants shipped inside a US-branded router VulnCheck bought on Amazon

    Product · August 29, 2026 · 1 publisher

  10. An all-zero MAC address bypasses the root command check in ZBT-derived white-label routers

    Build · August 28, 2026 · 2 publishers

  11. ZBT router firmware ships two factory implants that beacon out on UDP/10000

    Security · August 28, 2026 · 1 publisher

  12. Most of 19 audited MCP servers keep their context-injection surfaces out of the docs

    Product · August 28, 2026 · 1 publisher

  13. Honeypots logged a SharePoint JWT bypass hunting for a Business Data Catalog sink

    Build · August 27, 2026 · 1 publisher