Raxis original discovered vulnerabilities that were identified during real engagement work, validated with the vendor, and assigned a CVE identifier through MITRE.
The Exploit: Penetration Testing Insights From The Frontlines
Articles Categorized as Raxis Discovered Vulnerabilities
CVE-2026-36748: XSS in Rock RMS Leads to Privilege Escalation
Raxis Lead Pentester Jason Taylor recently discovered CVE-2026-36748, a high-risk XSS vulnerability in Rock RMS that allows privilege escalation to admin.
Bypassing a WAF and a CSP with Google Tag Manager: An Attacker’s Perspective and Remediation Advice
Ryan Chaplin takes an in-depth look at how attackers can use unsafe directives to bypass CSP, notably in Google Tag Manager, and how to remediate the issue.
This CSS vulnerability, discovered by Raxis’ Matt Mathur, lies in a device’s properties and how they are verified and displayed within PRTG Network Monitor.