We publish a portion of our vulnerability research with full root cause analysis, proof-of-concept code, detection signatures, and patch analysis. Our research is available on request — whether you need a deep-dive on a specific CVE affecting your environment, or a security audit of your own product. Contact business@aretiq.ai to discuss.
Research
Vulnerability research and security analysis by Aretiq AI
CVE-2026-48827
Apache MINA SSHD sshd-git Path Traversal Info Disclosure
1. Overview A path traversal vulnerability exists in the Apache MINA SSHD sshd-git module, which provides Git-over-SSH server functionality. …
1 Jun 2026
CVE-2026-8054
dotCMS Core Publish Audit API SQL Injection
1. Overview A critical SQL injection vulnerability exists in the dotCMS Core content management system’s Publish Audit API. The …
27 May 2026
CVE-2026-9256
NGINX ngx_http_rewrite_module Overlapping PCRE Captures Heap Buffer Overflow RCE
1. Overview A heap buffer overflow vulnerability exists in the NGINX ngx_http_rewrite_module when processing rewrite directives that use …
25 May 2026
CVE-2026-45434
Apache OFBiz LoginWorker checkLogin Password-Change Flow Authentication Bypass RCE
1. Overview A vulnerability exists in Apache OFBiz’s login authentication workflow that allows an attacker to bypass a forced …
20 May 2026
CVE-2026-23412
Linux Kernel Netfilter BPF Hook Use-After-Free LPE
1. Overview A use-after-free vulnerability exists in the Linux kernel’s BPF netfilter link implementation. The bpf_nf_link_lops …
18 May 2026
CVE-2026-41089
Microsoft Windows Netlogon BuildSamLogonResponse Stack-based Buffer Overflow RCE
1. Overview A stack-based buffer overflow vulnerability exists in the Windows Netlogon service’s DC locator ping response handler. …
13 May 2026