Our research team discovered a critical pre-authentication RCE inside ServiceNow by bypassing their scripting sandbox (CVE-2026-6875). You can read more here:
Assetnote combines advanced reconnaissance and high-signal continuous security analysis to help enterprises gain insight and control of their evolving exposure.
Joined July 2017
- Our security research team discovered a pre-authentication arbitrary file read as root in cPanel (CVE-2026-29205) — a path traversal in cpdavd that we made exploitable by abusing Dovecot's + alias handling to create attacker-controlled directory names on disk. We've updated
- Our team discovered a vulnerability in Salesforce Marketing Cloud that allowed us to leak PII of subscribers and emails sent through SFMC, without any auth. Assigned CVE-2026-22585, CVE-2026-22586, CVE-2026-22582, CVE-2026-22583, CVE-2026-2298. Read our writeup here:
- We've released a high fidelity detection technique for CVE-2026-41940 (cPanel/WHM auth bypass). You can find the research post here: slcyber.io/research-cente… and the tool here: github.com/assetnote/cpan… All other scanners and detection mechanisms so far will lead to false negatives.
- Our team reverse engineered the Magento PolyShell pre-auth RCE - actively exploited in the wild. No auth needed to land a PHP webshell. RCE depends on server config, but the file persists regardless. Props to @sansecio for the heads up. slcyber.io/research-cente… @SLCyberSec

