CVE-2025-2776

CRITICAL KEV NUCLEI

SysAid On-Prem <= 23.3.40 - XML External Entity

Title source: nuclei
STIX 2.1

Exploitation Summary

CVE-2025-2776 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2025. EIP tracks 2 public exploits from researchers including watchtowrlabs, mrk336. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional exploit PoC for a pre-authentication RCE chain in SysAid (CVE-2025-2776). The exploit leverages XXE to leak credentials and then executes arbitrary commands via API endpoint manipulation.

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

Exploits (2)

github WORKING POC 12 stars
by watchtowrlabs · pythonremote
https://github.com/watchtowrlabs/watchTowr-vs-SysAid-PreAuth-RCE-Chain

This repository contains a functional exploit PoC for a pre-authentication RCE chain in SysAid (CVE-2025-2776). The exploit leverages XXE to leak credentials and then executes arbitrary commands via API endpoint manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SysAid <= 23.3.40
No auth needed
Prerequisites: Network access to target SysAid server · Attacker-controlled server for XXE callback
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WRITEUP
by mrk336 · poc
https://github.com/mrk336/From-EternalBlue-to-CVE-2025-2776-The-Evolution-of-an-SMB-Attack

This repository provides a detailed writeup and detection strategies for CVE-2025-2776, an SMB-based attack evolving from EternalBlue. It includes PowerShell-based reverse shell techniques and KQL queries for detection.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Windows SMBv1
No auth needed
Prerequisites: SMBv1 enabled on target · Network access to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

SysAid On-Prem <= 23.3.40 - XML External Entity
CRITICALby johnk3r
Shodan: http.favicon.hash:"1540720428"
FOFA: icon_hash=1540720428

References (3)

Core 3

Scores

CVSS v3 9.3
EPSS 0.6260
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2025-07-22
VulnCheck KEV 2025-05-14
ENISA EUVD EUVD-2025-13875
CWE
CWE-611
Status published
Products (1)
sysaid/sysaid < 23.3.40
Published May 07, 2025
KEV Added Jul 22, 2025
Tracked Since Feb 18, 2026