<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — rce</title><link>https://exploit-intel.com/blog/tags/rce/</link><description>EIP research articles tagged rce.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/rce/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Fri, 01 May 2026 12:00:00 -0400</lastBuildDate><item><title>CVE-2026-41940: cPanel &amp; WHM Pre-Auth RCE - Two Write Paths, One Filter</title><link>https://exploit-intel.com/blog/posts/cve-2026-41940-cpanel-whm-auth-bypass/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2026-41940-cpanel-whm-auth-bypass/</guid><description>CVE-2026-41940: a CRLF session-injection in cPanel &amp; WHM that turns six unauthenticated HTTP requests into root SSH. Source-level walkthrough and audit.</description><pubDate>Fri, 01 May 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2025-62507: Redis Stack Overflow to RCE in 68 Minutes  -  Then We Turned ASLR On</title><link>https://exploit-intel.com/blog/posts/cve-2025-62507-redis-stackforge-from-crash-to-rce-with-aslr/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-62507-redis-stackforge-from-crash-to-rce-with-aslr/</guid><description>The public material available during this CVE-2025-62507 run was a crash PoC. StackForge pursued RCE, then repeated the work with ASLR enabled.</description><pubDate>Tue, 03 Mar 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-15467: From OpenSSL Stack Overflow to Three ROP Chains in 64 Minutes  -  Introducing Stackforge</title><link>https://exploit-intel.com/blog/posts/cve-2025-15467-openssl-stackforge-autonomous-binary-exploit/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-15467-openssl-stackforge-autonomous-binary-exploit/</guid><description>We forked Shannon again  -  this time for binary exploit development. Nine AI agents, GDB as an MCP tool, packet capture via SharkMCP, and a pipeline that turned an OpenSSL stack buffer overflow into three independent ROP chains with GDB-verified RCE. Eighty-five minutes. Twenty-five dollars. Here's how Stackforge works.</description><pubDate>Tue, 03 Mar 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2025-26866: From Undocumented Binary Protocol to Root Shell - AI Agent Meets Java Deserialization</title><link>https://exploit-intel.com/blog/posts/cve-2025-26866-hugegraph-hessian-deserialization-autonomous-exploit/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-26866-hugegraph-hessian-deserialization-autonomous-exploit/</guid><description>CVE-2025-26866 is a Hessian deserialization RCE in Apache HugeGraph PD. Our autonomous exploit pipeline CVEForge - which had completed 56 consecutive CVEs - hit a wall: an undocumented binary protocol, a non-standard serialization format, and a class blacklist blocking every known gadget chain. The agent spent $49 and four hours reverse-engineering SOFABolt, mapping sofa-hessian byte by byte, and finding a JDK-only gadget chain to bypass the blacklist. Then we took over to turn file creation into a proper root shell - navigating JNDI hardening, CC library defenses, and a gadget chain that silently dies on modern JDK. The result: a full Metasploit module.</description><pubDate>Sun, 01 Mar 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-53833: Autonomous PoC Generation with CVEForge - From CVE Number to Root Shell in 32 Minutes</title><link>https://exploit-intel.com/blog/posts/cveforge-from-shannon-to-autonomous-poc/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cveforge-from-shannon-to-autonomous-poc/</guid><description>We forked Shannon - the open-source AI pentesting framework - and wired it to the EIP MCP server. Six AI agents, one CVE number, 32 minutes: a working RCE PoC for a CVSS 10.0 vulnerability with zero existing public exploits. Here's how it happened.</description><pubDate>Wed, 25 Feb 2026 12:00:00 -0400</pubDate></item></channel></rss>
