Security Research & Blog

Alexander Constantinou

Penetration tester with 9+ years in offensive security. CVE analysis, Hack The Box writeups, and red team research.

Recent Posts

CVE analysis, Hack The Box writeups, and security research.

CVE-2026-60188: Zimbra Collaboration amavisd cpio Path-Traversal to RCE

amavisd falls back to cpio to unpack attachments → traversal path in the archive → JSP webshell in the webroot → RCE as zimbra, just by sending an email. CVSS 9.8.

Read more
HTB: Tempest — Windows Hard

Password spray → Kerberoast a weak service account → GenericWrite over a computer object → RBCD to local admin → cached DA credential → DCSync → Domain Admin.

Read more
CVE-2026-59637: Jenkins Pipeline Groovy Sandbox Bypass to RCE

A Groovy coercion the Script Security sandbox forgot to intercept lets a low-priv Job/Configure user escape the sandbox and run code on the controller → full CI/CD compromise.

Read more
HTB: Foundry — Linux Medium

Jinja2 SSTI in a Flask preview feature → RCE as the web user → leaked config password reused on SSH → cap_setuid on python3 → root in one line.

Read more
CVE-2026-59214: Oracle WebLogic Server T3 Deserialization Pre-Auth RCE

T3/IIOP listener deserializes before auth → a gadget chain outside Oracle's blocklist triggers a JNDI lookup → code execution. The latest bypass of the same decade-old filter. CVSS 9.8.

Read more
CVE-2026-58004: Fortra GoAnywhere MFT Pre-Auth Deserialization RCE

Licensing servlet calls readObject() before verifying the bundle signature, reachable pre-auth → ysoserial gadget chain against bundled libs → RCE as the service. CVSS 9.8.

Read more

Get In Touch

Questions, opportunities, or just want to talk security.