<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — cve-2026-28372</title><link>https://exploit-intel.com/blog/tags/cve-2026-28372/</link><description>EIP research articles tagged cve-2026-28372.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/cve-2026-28372/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Fri, 27 Feb 2026 18:00:00 -0400</lastBuildDate><item><title>Foreman Command Injection and Telnetd Privilege Escalation - A Dropdown, a Blacklist, and Two Very Different Fixes</title><link>https://exploit-intel.com/blog/posts/two-cves-two-outcomes-foreman-command-injection-telnetd-privilege-escalation/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/two-cves-two-outcomes-foreman-command-injection-telnetd-privilege-escalation/</guid><description>Foreman command injection via the REST API (CVE-2025-10622) and telnetd privilege escalation through environment variable injection (CVE-2026-28372) - CVEForge analyzes both end-to-end. One fix is a proper server-side whitelist. The other is a single unsetenv() call on a blacklist from 1995. Both produced working PoCs. Only one produced a fix we'd trust.</description><pubDate>Fri, 27 Feb 2026 18:00:00 -0400</pubDate></item></channel></rss>
