We publish a portion of our vulnerability research with full root cause analysis, proof-of-concept code, detection signatures, and patch analysis. Our research is available on request — whether you need a deep-dive on a specific CVE affecting your environment, or a security audit of your own product. Contact business@aretiq.ai to discuss.
Research
Vulnerability research and security analysis by Aretiq AI
CVE-2026-15748
WPMU DEV Forminator Forms Select Field Injection Unrestricted File Upload
1. Overview A vulnerability exists in WPMU DEV’s Forminator Forms plugin for WordPress (600,000+ active installations) that allows …
18 Aug 2026
CVE-2026-61967
miniOrange OTP Verification Ultimate Member Password Reset Authentication Bypass
1. Overview A vulnerability exists in the miniOrange OTP Verification plugin for WordPress (versions 5.5.1 and earlier) that allows an …
15 Aug 2026
CVE-2026-54995
Microsoft Windows Reliable Multicast Transport Driver Integer Underflow
1. Overview A vulnerability exists in the Windows Reliable Multicast Transport Driver (rmcast.sys) that implements the Pragmatic General …
2 Jul 2026
CVE-2026-45502
Microsoft Exchange Server EWS InstallApp Server-Side Request Forgery
1. Overview A server-side request forgery (SSRF) vulnerability exists in Microsoft Exchange Server’s Exchange Web Services (EWS) …
22 Jun 2026
CVE-2026-45453
Microsoft SharePoint Server Workflow Pages DocURL Parameter Reflected Cross-Site Scripting
1. Overview A reflected cross-site scripting vulnerability exists in three SharePoint Server workflow management pages. The DocURL query …
16 Jun 2026
CVE-2026-45454
Microsoft SharePoint Server Upload Page Folder Path Traversal
1. Overview A path traversal vulnerability exists in the SharePoint Server file upload page (Upload.aspx). The UploadPage.CurrentFolder …
10 Jun 2026
CVE-2026-28318
SolarWinds Serv-U HTTP Deflate Uncontrolled Resource Consumption
1. Overview A vulnerability exists in SolarWinds Serv-U’s HTTP request handler that processes Content-Encoding: deflate encoded POST …
7 Jun 2026
CVE-2026-3593
ISC BIND 9 DNS-over-HTTPS HTTP/2 SETTINGS Use-After-Free
1. Overview A use-after-free vulnerability exists in ISC BIND 9’s DNS-over-HTTPS (DoH) implementation. When a DoH response has been …
5 Jun 2026
CVE-2026-8206
Themeum Kirki WordPress Plugin Password Reset Email Redirect Privilege Escalation
1. Overview A vulnerability exists in the Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress, in the …
2 Jun 2026
CVE-2026-48866
WordPress Gravity Forms Plugin File Upload Path Traversal Arbitrary File Deletion
1. Overview A path traversal vulnerability exists in the Gravity Forms WordPress plugin’s file deletion mechanism. When processing …
1 Jun 2026