<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — fix-bypass</title><link>https://exploit-intel.com/blog/tags/fix-bypass/</link><description>EIP research articles tagged fix-bypass.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/fix-bypass/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Fri, 13 Mar 2026 22:00:00 -0400</lastBuildDate><item><title>CVE-2026-4105: systemd-machined Privilege Escalation - 72 Minutes from Drop to Bypass</title><link>https://exploit-intel.com/blog/posts/cve-2026-4105-systemd-machined-privilege-escalation/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2026-4105-systemd-machined-privilege-escalation/</guid><description>CVE-2026-4105 dropped this morning - local privilege escalation to root on desktop Linux via systemd-machined. Two D-Bus calls, no authentication. We fed it to CVEForge before the advisory was an hour old. Seventy-two minutes later: confirmed exploit, Docker labs for vulnerable and patched builds, and a bypass proving the vendor's fix is incomplete. The analysis agent said the fix was thorough. The bypass agent proved it wrong.</description><pubDate>Fri, 13 Mar 2026 22:00:00 -0400</pubDate></item><item><title>72 Hours, 24 CVE Proof of Concept Exploits, and 8 Disclosure Submissions: The CVEForge Stress Test</title><link>https://exploit-intel.com/blog/posts/72-hours-24-cves-the-cveforge-stress-test/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/72-hours-24-cves-the-cveforge-stress-test/</guid><description>We left CVEForge running for three days. Twenty-four CVEs went in. All twenty-four produced working PoCs. Ten incomplete fixes triggered eight responsible disclosure submissions - six GitHub issues, one MITRE report, one HackerOne 0-day. Here's the full accounting.</description><pubDate>Sat, 28 Feb 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-60355 (OneBlog): CVEForge Finds 3 Bypass/Incomplete Fixes in 5 CVE Runs</title><link>https://exploit-intel.com/blog/posts/five-cves-three-bypasses-java-case-study/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/five-cves-three-bypasses-java-case-study/</guid><description>In this CVEForge patch-validation run, we analyze CVE-2025-60355 in OneBlog (Java/FreeMarker) and compare outcomes across five CVEs. Three of five runs ended in confirmed bypass or incomplete-fix results.</description><pubDate>Fri, 27 Feb 2026 12:00:00 -0400</pubDate></item><item><title>Zero to RCE: Autonomous Exploit Development Across Three Vulnerability Classes</title><link>https://exploit-intel.com/blog/posts/zero-to-rce-autonomous-exploit-development/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/zero-to-rce-autonomous-exploit-development/</guid><description>After CVEForge's first successful run, we needed to know if it was luck or a pattern. Two more CVEs, zero hand-holding, and an AI agent that found a fix bypass the developers missed.</description><pubDate>Thu, 26 Feb 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2026-28296: From CRLF Injection PoC to Fix Bypass - One Prompt, One AI Agent</title><link>https://exploit-intel.com/blog/posts/from-cve-to-bypass-with-mcp/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/from-cve-to-bypass-with-mcp/</guid><description>One prompt kicked off an AI agent that built a full PoC lab for CVE-2026-28296 - and discovered the GVFS CRLF injection fix was incomplete. Here's how it happened.</description><pubDate>Tue, 24 Feb 2026 12:00:00 -0400</pubDate></item></channel></rss>
