watchTowr enables organizations to get ahead of in-the-wild exploitation with Preemptive Exposure Management technology.
Posts
We're looking for new colleagues to join the phorce to work on "Project Red", our autonomous, LLM-driven N-day reproduction and 0-day discovery capability.
We're having fun, we promise ;-)
https://careers.watchtowr.com/jobs/7629309-ai-vulnerability-research-engineer
CVE-2026-0265, the PAN-OS auth bypass (when Cloud Auth Services are enabled) was fun to reproduce and load into the watchTowr Platform.
Our friends @ @HacktronAI are publishing their analysis this week, so we won’t be publishing. Looking forward to it 🚀
Rapid reaction gets you ahead.
1 day before CISA added CVE-2026-41940 to KEV, an Authentication Bypass vulnerability in cPanel & WHM, watchTowr clients were aware of their exposure.
Reach out via our website if you need support.
The Internet is falling down, falling down, falling down
Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940
Enjoy with us..
https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
We are currently rapidly reacting to cPanel Authentication Bypass Vulnerability, a security flaw that allows attackers to bypass authentication mechanisms affecting cPanel & WHM.
Active watchTowr Platform clients have been made aware of their exposure. Reach out for support.
whoever bought http://a-fun-hostname-for-f5-to-mark-as-an-ioc.com and redirected it to our blog post - please reach out, we love you
Rapid reaction gets you ahead. 67 days before CISA added CVE-2026-21643 (Fortinet FortiClientEMS SQL Injection) to KEV, watchTowr clients were aware of their exposure.
Reach out via our website if you need support.
The watchTowr team will be at VulnCon in Scottsdale next week!
Come find us to discuss how the watchTowr Platform, our Preemptive Exposure Management technology, helps organizations rapidly react to emerging threats, validate real-world exposure, and mitigate risk.
🚨The watchTowr Platform has autonomously deployed Active Defense mitigation rules into client envs for the currently exploited in-the-wild Fortinet FortiClient EMS zero-day, now tracked as CVE-2026-35616.
If you need support, please reach out directly or via our website.
🫡 We’re back.
Today, we’re publishing vulnerabilities we discovered, disclosed, and chained to achieve pre-auth RCE against Progress ShareFile.
Enjoy the journey with us, while you sob into your hands 🫠
Rapid reaction gets you ahead. 6 days before CISA added CVE-2026-3055 to KEV, a Citrix NetScaler Memory Overread (CitrixBleed++) vulnerability, watchTowr clients were aware of their exposure.
Reach out via our website if you need support.
What number CitrixBleed are we on?
Join us, yet again, for part 2 of our analysis of Citrix NetScaler CVE-2026-3055 - which now appears to be multiple vulnerabilities bundled into one.
Sigh.
Happy weekend! Enjoy our analysis of CVE-2026-3055 - yet another 'Memory Overread' vulnerability in Citrix NetScaler appliances.
while we’re eating our best writing crayons and using finger paint to finish our latest research, we’ve decided to take this opportunity to share research from the archives with new followers 🙂
happy Friday… for now 🥹
https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/
(Yes this is not new don’t @ us)
watchTowr Intel is detecting active reconnaissance against NetScalers for CVE-2026-3055 through our Attacker Eye honeypot network.
Exploitation is likely imminent. Patch now.
watchTowr clients already have access to internal mechanisms to confidently identify their exposure.
Rapid reaction gets you ahead. 4 days before CISA added CVE-2026-33017 (Langflow RCE) to KEV, watchTowr clients were already aware of their exposure.
Reach out via our website (watchTowr.com) if you need support.
It's Monday! We are currently rapidly reacting to CVE-2026-3055 - yet another unauth memory overread vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway appliances.
Active watchTowr Platform clients have been made aware of their exposure - reach out for support.
~150 S3 abandoned buckets. 8M+ requests. Two months. Software updates, binaries, VMs and more.
This week, AWS rolled out namespaces for new S3 buckets - finally.
This is why offensive security research is so important - to move the needle.
What's new is old, and what's old is new - as is relentlessly proven.
Join us in our analysis of CVE-2026-32746, the recent pre-auth RCE in inteutils' Telnetd.
Speak soon.
In 2025, we achieved pre-auth RCE against another solution in a ransomware gang favourite category. Today, we finally click publish.
Join us as we walk through a chain of vulnerabilities we identified in BMC’s FootPrints ITSM solution.
Enjoy!
Can you feel it too?
Join us today for our analysis of Juniper's recent pre-auth RCE - CVE-2026-21902 - affecting a very specific set of devices. Curious?
we're stuck in a blizzard, which means one thing - a watchTowr Labs blogpost is imminent.
in other news, we're at WT-2026-0030 for "impactful 0days reported in 2026"
https://labs.watchtowr.com/disclosed-vulnerabilities/
later, nerdz
2026, the year of the AI-driven attacker that could do back flips, they said.
Meanwhile, there's a magic number that allows Auth Bypass against Ivanti EPM (CVE-2026-1603)
something about a pledge 🙄
Someone knows Bash disgustingly well, and we love it.
Here's our analysis of the Ivanti EPMM Pre-Auth RCE vulnerabilities - CVE-2026-1281 & CVE-2026-1340.
This research fuels our technology, enabling our clients to accurately determine their exposure.
🚨 The watchTowr team is rapidly reacting to CVE-2026-1281 & CVE-2026-1340 - unauth RCE vulnerabilities within Ivanti's Endpoint Manager Mobile (EPMM).
Active watchTowr Platform clients have been made aware of their exposure - reach out via the watchTowr website for support.
Earlier this month, we reported a zero-day auth. bypass in the SmarterTools SmarterMail email solution.
Someone has reversed the patch (released on 15th Jan) and begun exploiting it in the wild.
Read our analysis and please, ASSUME BREACH + PATCH NOW.
And, we're back - analyzing CVE-2025-52691, a pre-auth RCE in SmarterTools SmarterMail mail server solution.
Speak soon (:^)) and enjoy..
🎄 As we near Christmas, on behalf of the watchTowr team, we want to wish all of our friends, industry colleagues, clients, and partners a happy Christmas! 🚀