Core Certified Exploits

Library of expert validated exploits for safe and effective pen tests

Browse the Core Certified Exploit Library  

 

Exploit development can be an advanced penetration testing skill that takes time to master. Additionally, when on a job, pen testers often don’t have the resources to create a new exploit. Many resort to searching for and using pre-written exploits that have not been tested and must go through the timely effort of quality assurance testing in order to ensure they are secure and effective.

Core Impact users can save time by finding all the up-to-date exploits they need in one place. We provide a robust library of exploits designed to enable pen testers to safely and efficiently conduct successful penetration tests. Witten by our own internal team, you can trust they have been thoroughly tested and validated by our experts.

The universe of vulnerabilities is huge and not all of them represent the same risk for the customers. Vulnerabilities do not all have the same level of criticality. Some may be easily exploitable by a low-level user, while others may not be exploitable at all. To increase the efficiency of the attacks and the quality of the exploits provided, the Core Impact team has developed selection criteria to prioritize its analysis and implementation. We determine which exploits warrant creation based on the following questions:

  • What are the most critical attacks from the attacker’s perspective?
  • What new vulnerabilities are more likely to be exploited in real attacks?
  • What exploits are the most valuable for Core Impact?

Once an exploit is approved, its priority order considers the following variables: 

  • Vulnerability Properties: CVE, disclosure date, access mechanism and privileges needed.
  • Target Environment Setup: OS, application prevalence, version and special configurations needed.
  • Value Provided to Core Impact: Customer request, usage in multiple attacks, allows the installation of an agent, etc.
  • Technical Cost vs. Benefit: An analysis weighing the resources needed to build an exploit with the internal and external knowledge gained in its creation. 

Each one of these variables has a different weight and provides a ranking of the potential exploits to be developed. Following those criteria, the top of the list would contain, for example, a vulnerability on Windows (most popular OS) that can be exploited remotely, without authentication and that provides super user privileges. 

Correspondingly, a vulnerability on an application that is rarely installed, needs special configurations, and requires User Interaction, would be at the bottom.

Stay Informed of New Core Certified Exploits

Subscribe to receive regular email updates on new exploits available for Core Impact

Browse the Core Certified Exploit Library

We provide pen testers with real-time updates for a wide range of exploits for different platforms, operating systems, and applications. 

Search our continuously growing library to discover an exploit that will allow you to gain and retain access on the target host or application.

Title Description Date Added CVE Link Exploit Platform Exploit Type Product Name
Drupal i18n sso Authentication Bypass Vulnerability Exploit This module performs the following steps: 1. Checks whether the Drupal i18n_sso token endpoint is present. 2. Submits a random token as a negative control and verifies that it is rejected. 3. Sends unauthenticated wildcard-token requests to the Drupal i18n_sso login endpoint. 4. Repeats the wildcard request according to MAX ATTEMPTS and POLL INTERVAL until a matching active token is found. 5. Confirms the authentication bypass only when Drupal reports success and returns a valid Drupal session cookie. 6. Uses the acquired session to identify the authenticated Drupal account. 7. Linux Exploits / Authentication Weakness / Known Vulnerabilities Impact
Microsoft Windows CBS OnePackage UpdateAgent Elevation of Privilege Vulnerability Exploit (CVE-2026-81963) A Windows Component Based Servicing elevation of privilege vulnerability allows a local attacker to make a SYSTEM TiWorker process load an unsigned sibling dpx.dll from a controlled OnePackage metadata directory. The module performs the following steps: Generates a per-run CORE Impact agent DLL named dpx.dll. Copies the target's installed, signed UpdateAgent.dll and builds a reduced DesktopDeployment cabinet with the controlled dpx.dll. Builds a small standalone OnePackage carrier on the target by using the Windows makecab utility. Windows Exploits / Local / Privilege Escalation Impact
Cisco ISE enableStrongSwanTunnel Unauthenticated Remote Code Execution Exploit This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Exploits / OS Command Injection / Known Vulnerabilities Impact
Cisco ISE enableStrongSwanTunnel Unauthenticated Remote Code Execution Webapp Exploit This module exploits CVE-2025-20281, a critical unauthenticated command injection vulnerability in the enableStrongSwanTunnel API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Insufficient validation of user-supplied API input allows a remote attacker without valid credentials to execute arbitrary commands. The module performs the following steps: Build the deployment-rpc/enableStrongSwanTunnel endpoint from the selected target, protocol, port, and optional base path. Exploits / OS Command Injection / Known Vulnerabilities Impact
JoomShaper SP Page Builder Unauthenticated File Upload Remote Code Execution Exploit CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. Linux Exploits / OS Command Injection / Known Vulnerabilities Impact
JoomShaper SP Page Builder Unauthenticated File Upload Remote Code Execution Webapp Exploit CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without requiring authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. Linux Exploits / OS Command Injection / Known Vulnerabilities Impact
Nginx Stream Rift Unauthenticated Remote Code Execution Exploit This module exploits the nginx stream ssl_preread/SNI variant of CVE-2026-42533. A crafted TLS Server Name Indication triggers two-pass complex-value evaluation, allowing an unauthenticated attacker to disclose process addresses and corrupt the nginx worker heap. The module captures the leaked addresses, sprays a forged cleanup handler through the HTTP listener, and triggers the corruption through the stream listener to invoke system() in the nginx worker. It then downloads and executes a Core Impact Linux agent. The attack is layout-dependent and may interrupt the nginx worker. Linux Exploits / Remote Code Execution Impact
GitLab Repository Commits API Path Traversal Arbitrary File Read Exploit CVE-2026-85706 is an improper path confinement and missing authentication vulnerability in the GitLab repository commits API. A remote unauthenticated attacker can forge Workhorse body-upload metadata and make GitLab read an arbitrary local file before authentication is enforced. This module sends a crafted form to the repository commits API and extracts file content reflected by a parser error. The request does not require a GitLab account, but PROJECT ID must identify an existing project that is available to unauthenticated users. Linux Exploits / Remote File Disclosure Impact
PaperCut NG and MF ConfigEditor Authentication Bypass Vulnerability Remote Code Execution Exploit This module exploits CVE-2026-81578, an improper access control vulnerability combined with CVE-2026-82078, an unsafe dynamic class loading vulnerability in the database connection utilities of PaperCut NG and MF to deploy an OSCI agent. The module will use the vulnerability chain via a crafted Apache Tapestry complex-direct request to invoke privileged ConfigEditor components through the public Home page. On version 26 of the affected software, the module reconfigures external user lookup to use an H2 JDBC URL whose initialization SQL evaluates Groovy code. Linux, Windows Exploits / Authentication Weakness / Known Vulnerabilities Impact
Langflow AUTO_LOGIN Unauthenticated Remote Code Execution WebApp Exploit CVE-2026-9198 is an unauthenticated remote code execution vulnerability chain in Langflow OSS when AUTO_LOGIN is enabled. An unauthenticated network attacker can exploit CVE-2026-9103 to obtain a superuser access token from /api/v1/auto_login without credentials, then leverage CVE-2026-8481 in /api/v1/validate/code to execute user-controlled Python through exec(). By chaining these vulnerabilities, CVE-2026-9198 allows arbitrary command execution on the Langflow server. Langflow OSS versions 1.0.0 through 1.10.0, inclusive, are vulnerable. The vulnerability is fixed in version 1.10.1. Linux Exploits / Remote Code Execution Impact
Langflow AUTO_LOGIN Unauthenticated Remote Code Execution Exploit CVE-2026-9198 is an unauthenticated remote code execution vulnerability chain in Langflow OSS when AUTO_LOGIN is enabled. An unauthenticated network attacker can exploit CVE-2026-9103 to obtain a superuser access token from /api/v1/auto_login without credentials, then leverage CVE-2026-8481 in /api/v1/validate/code to execute user-controlled Python through exec(). By chaining these vulnerabilities, CVE-2026-9198 allows arbitrary command execution on the Langflow server. Langflow OSS versions 1.0.0 through 1.10.0, inclusive, are vulnerable. The vulnerability is fixed in version 1.10.1. Linux Exploits / Remote Impact
Microsoft Configuration Manager CAB Extraction Remote Code Execution Exploit The module authenticates to Configuration Manager AdminService with a low-privileged domain identity and calls UploadExtensionInChunks. The exploit uses an Authenticode-signed CAB to extract a path traversal to place an adsource.dll proxy and a preserved original DLL in the Configuration Manager bin X64 directory. Active Directory System Discovery subsequently loads the proxy in SMS_EXECUTIVE and modifies the built-in RID-500 account as NT AUTHORITY\\SYSTEM. The module then authenticates over SMB with that local administrator and deploys an Impact agent as SYSTEM. Windows Exploits / Remote Code Execution Impact
Microsoft Windows Kerberos Improper Authorization ResetNightmare ResetNightmare is an authorization flaw in the Microsoft Kerberos Change Password protocol. On an unpatched domain controller, an attacker who can write the userPrincipalName attribute of a controlled account can obtain a kadmin/changepw ticket whose client name identifies another account while its PAC identifies the controlled account. The module temporarily changes the controlled account's UPN to the target sAMAccountName, requests a kadmin/changepw ticket with an NT-ENTERPRISE client name, restores the original UPN, and uses the ticket in an RFC 3244 password-change exchange. Windows Exploits / Authentication Weakness / Known Vulnerabilities Impact
Linux Kernel VsockDrop Local Privilege Escalation Exploit This module exploits CVE-2026-53365, to elevate privileges on a Linux target. The vulnerability is a page-reference-count underflow in the Linux kernel io_uring zero-copy send path over AF_VSOCK. It can free a page that remains pinned and allow the page to be reclaimed as privileged file page-cache data. The exploit uses the vulnerability to modify the interpreter path in the page-cache contents of "/usr/bin/su" and execute a caller-supplied ELF with root privileges. Linux Exploits / Local / Privilege Escalation Impact
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability Exploit This module exploits CVE-2026-66804, an improper access control vulnerability in the Microsoft Windows Cross Device Service, to execute a CORE Impact agent with NT AUTHORITY\SYSTEM privileges. Windows registers the Cross Device virtual-camera COM server at PROGRAMDATA\CrossDevice\CrossDevice.Streaming.Source.dll. On affected systems, the machine-wide registration can exist while PROGRAMDATA\CrossDevice is absent and creatable by a standard user. An attacker can create that missing directory and plant the registered COM DLL. Windows Exploits / Local / Privilege Escalation Impact
Microsoft Windows Snipping Tool NTLM Information Disclosure Exploit This module exploits an information disclosure vulnerability in Microsoft Windows Snipping Tool. A malicious web page invokes the ms-screensketch URI handler with an attacker-controlled UNC path. When the victim allows the browser to open Snipping Tool, the application connects to the SMB server and discloses the current user's Net-NTLM response. This exploit does not install an agent. Windows Exploits / Client Side / Authentication Coercion Impact
Microsoft Windows Win32k xxxInterceptSetWindowPos Elevation of Privilege Vulnerability Exploit Microsoft Windows is vulnerable to a use-after-free in win32kfull!WindowActions::xxxInterceptSetWindowPos. The vulnerability can be triggered while processing deferred window-position operations for intercept windows, allowing freed kernel memory to be reclaimed with attacker-controlled allocations. This module allows a local unprivileged user to execute arbitrary code with SYSTEM privileges. Windows Exploits / Local / Privilege Escalation Impact
Jetbrains TeamCity Agent Polling Protocol XML Deserialization Vulnerability Remote Code Execution Exploit This module exploits CVE-2026-63077, a pre-authentication unsafe XML deserialization vulnerability in JetBrains TeamCity On-Premises. It registers a synthetic build agent through the agent polling protocol and submits a crafted XML document using the resulting agent session, without requiring TeamCity user credentials. Deserialization of the payload initializes an in-memory HSQLDB data source and uses HSQLDB's SCRIPT functionality to write a temporary JSP payload into the TeamCity ROOT web application. Linux, Windows Exploits / OS Command Injection / Known Vulnerabilities Impact
Jetbrains TeamCity Agent Polling Protocol XML Deserialization Vulnerability Remote Code Execution Webapp Exploit This module exploits CVE-2026-63077, a pre-authentication unsafe XML deserialization vulnerability in JetBrains TeamCity On-Premises. It registers a synthetic build agent through the agent polling protocol and submits a crafted XML document using the resulting agent session, without requiring TeamCity user credentials. Deserialization of the payload initializes an in-memory HSQLDB data source and uses HSQLDB's SCRIPT functionality to write a temporary JSP payload into the TeamCity ROOT web application. Linux, Windows Exploits / OS Command Injection / Known Vulnerabilities Impact
Microsoft Defender ShieldBreak Elevation of Privilege Vulnerability Exploit This module exploits the ShieldBreak local privilege escalation vulnerability in Microsoft Defender to execute a Core Impact agent with SYSTEM privileges. ShieldBreak bypasses the fix for the RoguePlanet vulnerability (CVE-2026-50656). The exploit combines the Windows Cloud Files API, Object Manager shadow directories and symbolic links, the Common Log File System, and Defender's privileged remediation workflow to redirect a file operation into the native Windows System32 directory. Windows Exploits / Local / Privilege Escalation Impact
HPE OneView Unauthenticated Remote Code Execution Exploit This module exploits CVE-2025-37164, an unauthenticated remote code execution vulnerability in HPE OneView. The module first queries the appliance version endpoint, then validates the vulnerability by sending a benign command to the ID Pools executeCommand REST endpoint. If the target is vulnerable, commands are executed through the same endpoint to deploy an OSCI agent or a classic network agent. The vulnerable endpoint does not return command output, so the OSCI agent is committed as a blind command execution primitive. Exploits / OS Command Injection / Known Vulnerabilities Impact
Fortinet FortiClient EMS API Certificate Authentication Bypass Vulnerability Exploit This module uses a pre-authentication access-control bypass in the API of Fortinet FortiClient EMS. The module will use the vulnerability by impersonating the trusted component that normally reports a successfully verified client TLS certificate. The module will check if the target is vulnerable to the authentication bypass by sending crafted HTTP requests to the /api/v1/system/capabilities endpoint. If the target is vulnerable, the module will log and output the value returned by the /api/v1/system/version endpoint. Linux Exploits / Authentication Weakness / Known Vulnerabilities Impact
Fortinet FortiClient EMS API Certificate Authentication Bypass Vulnerability Webapp Exploit This module uses a pre-authentication access-control bypass in the API of Fortinet FortiClient EMS. The module will use the vulnerability by impersonating the trusted component that normally reports a successfully verified client TLS certificate. The module will check if the target is vulnerable to the authentication bypass by sending crafted HTTP requests to the /api/v1/system/capabilities endpoint. If the target is vulnerable, the module will log and output the value returned by the /api/v1/system/version endpoint. Linux Exploits / Authentication Weakness / Known Vulnerabilities Impact
Microsoft Windows WalletService Elevation of Privilege Vulnerability Exploit (CVE-2026-49176) This module exploits an elevation of privilege vulnerability in Windows WalletService to achieve arbitrary code execution with NT AUTHORITY\\SYSTEM privileges. The exploit performs the following steps: Prepares a controlled Wallet store containing a persisted callback. Temporarily redirects the current user's Documents known folder to the controlled store. Triggers WalletService through the Windows Wallet APIs. Starts a SYSTEM-level CORE Impact agent from the WalletService callback. Restores the original Documents known folder and removes temporary artifacts when possible. Windows Exploits / Local / Privilege Escalation Impact
WordPress Core wp2shell REST batch route-confusion and SQL Injection Vulnerability Exploit This module uses a chain of a REST batch route-confusion combined with a SQL injection vulnerability to deploy a network agent in WordPress Core that will run with the same user privileges than the affected software. The module will use the vulnerability chain and perform the following steps: * Check if the target is vulnerable. If it's not, the attack will stop. * Query the current number of wp_posts rows whose type is oembed_cache. This is saved so cleanup can later verify the run restored the cache count. Linux Exploits / Remote Code Execution Impact