remote code execution

Flexense SyncBreeze – Unauthenticated Remote Code Execution (0DAY-2025-0002)

In May 2026, SyncBreeze released an update that silently patched a critical vulnerability. The vulnerability was an authentication bypass allowing arbitrary file operations, but when chained with another persistent flaw, it enables logical RCE with SYSTEM privileges. This exploit chain was provided as part of our n-day feed, and now that it has been patched, we can finally disclose it. SyncBreeze SyncBreeze...

Chaining an Apache ActiveMQ RCE on a Fully Patched 6.2.5 (CVE-2026-34197)

A few months ago, I began integrating Claude AI into my N-day research at Crowdfense to speed up my workflow. At first, I wanted to test its capabilities in script writing, patch diffing, bug finding, and other related tasks. I had read many blogs and posts from other security researchers about it, but I still wanted to experiment myself, and...

CVE-2024-11477- 7-Zip ZSTD Buffer Overflow Vulnerability

As part of our daily job in Crowdfense, we investigate and dive deep into recently disclosed vulnerabilities to determine their exploitability and, if possible, weaponise them. We maintain a curated list of n-days (N-day Vulnerability Intelligence Feed) for red and blue teams, aiding them in conducting their operations and APT simulation scenarios. As we routinely check for interesting...