Posted by binreaper via Fulldisclosure on May 31
Hi all,
Posting a brief summary of a four-finding disclosure on bmcweb (the OpenBMC HTTP/Redfish web server), which ships in
BMC firmware on most modern enterprise servers — Intel, IBM, HPE, NVIDIA, and various ODMs.
Full timeline and analysis on the blog:
https://binreaper.pages.dev/posts/2026-05-27-bmcweb-disclosure/
## Why bmcweb matters
A Baseboard Management Controller boots before the host CPU, has full control over the server…
– Read More – Full Disclosure
![[KIS-2026-04] SmarterMail <= 9518 (MailboxId) Reflected Cross-Site Scripting Vulnerability AttackFeed by Joe Wagner | [KIS-2026-04] SmarterMail](https://attackfeed.com/wp-content/uploads/2026/02/fulldisclosure-img-jjsJpG.webp)


