Rhino Security Labs

Strategic & Technical Blog

Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution

Nicholas Hefty
September 15, 2026

Frappe LMS is an open-source learning management system built on the Frappe framework. It provides organizations with tools to create and manage online courses, track student progress, post job opportunities, and run learning batches.
While…

Referral Beware, Your Rewards are Mine (Part 1)

Multiple CVEs in Infoblox NetMRI: RCE, Auth Bypass, SQLi, and File Read Vulnerabilities  

CVE-2025-26147: Authenticated RCE In Denodo Scheduler 

John De Armas

Denodo provides a range of logical data management software.
This blog focuses on one such software, called “Scheduler”. Denodo Scheduler allows the scheduling and execution of data extraction and integration jobs…