Skip to content

company

ZoomEye

ZoomEye, run by Knownsec, is an internet-wide scanning search engine that indexes exposed devices and services, often used for security reconnaissance.

Known aliases

  • zoomeye.ai
  • ZoomEye international

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

CISA warns a single unauthenticated request can root MikroTik RouterOS below 7.24

CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 66%
Investor
Investor 7%

Reality

Evidence64
Adoption70
Hype gap+8
Incentives
Insufficient
Confidence62
build1 publisher

CERT-BUND's high-risk Drupal advisory puts 36 CVEs in 16 contributed modules

CERT-BUND has rated 36 CVEs in 16 contributed Drupal projects high risk, and Drupal core is not listed as affected. Each site team has to check the modules it has installed against 19 fixed releases and confirm that the code serving requests actually changed.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+8
Incentives
Insufficient
Confidence60
build1 publisher

Gunra enters through the same VPN appliances the advisory says should front RDP

Gunra affiliates get in through two FortiOS and FortiProxy authentication bypasses, CVE-2024-55591 and CVE-2025-24472, says a 10 August 2026 advisory. Its fix for exposed RDP routes remote access through that same class of appliance, so the gateway has to be secured before RDP moves behind it.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives30
Confidence50
build1 publisher

How Gunra actors got into a network through a default SSL VPN admin password

Gunra actors entered a victim's network through an SSL VPN admin account still on default credentials, according to a 10 August 2026 advisory. The path used no software flaw, so it tests credential changes, lockout and account reviews on edge devices.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
build1 publisher

Cisco email gateway flaw runs attacker SQL as root the moment it parses a message

CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence50
build1 publisher

ZoomEye counts 736,893 internet-facing Mattermost fingerprint matches

ZoomEye's fingerprint index returned 736,893 matches for Mattermost on 23 September 2026, each a service identifying itself as the self-hosted chat server. Teams that self-host to keep chat internal also own the job of checking whether their server is among them.

Publishers:dev.to

Reality

Evidence45
Adoption40
Hype gap+10
Incentives
Insufficient
Confidence45
build1 publisher

CVE-2026-76441 lets unauthenticated attackers reach restricted functions on Cisco email gateways

CERT-In rates CVE-2026-76441 critical for letting unauthenticated remote attackers into restricted functions on Cisco email gateways 15.5 and earlier. The gateway inspects mail in both directions, so the fix belongs ahead of the next scheduled window, using the release Cisco's own advisory names.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence50

Earlier coverage

  1. Chaining a 10.0 portal SSRF to a 7.8 console injection gets OS execution on SonicWall's SMA1000

    Build · September 21, 2026 · 1 publisher

  2. A crafted HTTP request runs as root on the console that pushes every Cisco firewall's policy

    Build · September 20, 2026 · 1 publisher

  3. Firewalling RouterOS SSH to a management network removes MikroTrick's precondition

    Build · September 19, 2026 · 1 publisher

  4. A ZoomEye port query returned 4,138,087 hosts on Kubernetes' conventional API port

    Build · September 20, 2026 · 1 publisher

  5. Confirmed exploitation moves the Adobe Commerce RCE to the front of CERT-In's patch queue

    Build · September 19, 2026 · 1 publisher

  6. A crafted request to one Cisco ISE API endpoint reaches root without a credential

    Build · September 19, 2026 · 2 publishers

  7. ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts

    Build · September 19, 2026 · 1 publisher

  8. ZoomEye's SonicWall SMA fingerprint returns 7 records against Shadowserver's several hundred

    Build · September 19, 2026 · 1 publisher

  9. GitLab's commits API returns arbitrary files to an unauthenticated caller at CVSS 10.0

    Build · September 19, 2026 · 1 publisher

  10. CISA gave federal SonicWall SMA 1000 operators three days to patch a pre-auth SSRF

    Build · September 19, 2026 · 1 publisher

  11. A prohibited leading character in a RouterOS username rewrites the session's policy mask

    Build · September 16, 2026 · 1 publisher

  12. Attackers are authenticating to unpatched Proxmox hosts with an arbitrary ticket value

    Build · September 18, 2026 · 1 publisher

  13. A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API

    Build · September 17, 2026 · 1 publisher

  14. An empty string in Artifactory's default join keys mints a platform admin token

    Build · September 17, 2026 · 1 publisher

  15. LiteLLM's MCP endpoint answered a failed key check with an empty auth object

    Build · September 16, 2026 · 1 publisher

  16. Sizing AA26-231A with ZoomEye returns 173 assets or 161,764, depending on the query

    Build · September 16, 2026 · 1 publisher

  17. ZoomEye counts 202,686 Modbus and S7 ports that answer whoever can route to them

    Build · September 16, 2026 · 1 publisher

  18. One slash in a Host header moves the path Starlette's middleware checks

    Build · September 16, 2026 · 1 publisher

  19. CISA warns of rising attacks on internet-exposed water sector PLCs

    Build · September 14, 2026 · 1 publisher

  20. Any Kestra API path ending in /configs skipped Basic Authentication

    Build · September 15, 2026 · 1 publisher

  21. U.S. warning on Siemens S7 PLCs: AI-written scripts, borrowed scan data, read access first

    Security · August 24, 2026 · 1 publisher

  22. AI-written snap7 scripts move the scarce resource in OT attacks from skill to exposure

    Build · August 19, 2026 · 2 publishers