August 3, 2026
about 10 hours ago
Summary
- Added the ability to use OAuth authentcation for the
cencliPlatform command line tool. - Added 12 new fingerprints to the Platform.
- Added three new risk fingerprints to ASM.
- One new Censys ARC Rapid Response advisory for JetBrains TeamCity Unauthenticated RCE [CVE-2026-63077].
Platform
- You can now configure the
cenclicommand line tool to use OAuth authentication. When you runcensys auth login, you will be redirected to an authenticaiton page to select your account and approve the connection.- Manage your OAuth connections on the Connected Applications page in the Platform web console.
New fingerprints and risks
Added 12 new fingerprints to the Platform and three new risk fingerprints to ASM.
Note that new ASM risk fingerprints may be disabled by default in your workspace. Reference your risk type configuration in the ASM web console to review new risk types.
New fingerprints
| Type | Name | Description | Query |
|---|---|---|---|
| software | Bitwarden Server | Open-source password management server. | Platform query |
| software | json-server | Node.js tool that serves a full REST API from a static JSON file, typically used for prototyping. | Platform query |
| software | nPerf Server | Network speed and performance testing server. | Platform query |
| software | Alinto SOGo | Open-source groupware server providing email, calendar, and contacts via web and native clients. | Platform query |
| software | TileServer GL | Open-source map tile server for rendering and serving vector and raster map tiles. | Platform query |
| software | FMSoft uniGUI | Delphi framework for building web applications. | Platform query |
| software | Vaultwarden | Lightweight, self-hosted Bitwarden-compatible password manager server written in Rust. | Platform query |
| software | PTC Windchill | Product lifecycle management (PLM) platform for managing engineering and product design data. | Platform query |
| software | DevExpress | Web application UI component framework. | Platform query |
| software | OpenJS Foundation Express | Node.js web application framework. | Platform query |
| software | SearXNG | Open-source, privacy-focused metasearch engine that aggregates results from multiple search providers. | Platform query |
| software | Vaadin | Java framework for building web applications. | Platform query |
New risks
| Name | Description | Query |
|---|---|---|
| Exposed json-server Instance | An HTTP service is exposing json-server, a Node.js tool that serves a full CRUD REST API from a JSON file with no authentication by default. json-server is intended for local development and mocking only; exposing it to the internet permits unauthenticated read and write access to whatever data it is serving. | |
| Exposed PTC Windchill Application | This host exposes a PTC Windchill application. Windchill is a Product Lifecycle Management (PLM) platform that stores sensitive engineering and product design data, and should not be directly reachable from the public internet. | |
| Exposed Express Default Page | This host is exposing the default, unconfigured Express.js scaffold page in production. This indicates the application was never finished being configured or deployed, which may signal an abandoned or forgotten deployment. | |
Censys ARC Rapid Response
The Censys ARC team published information about the following issue.
- July 31 Advisory: JetBrains TeamCity Unauthenticated RCE [CVE-2026-63077]
- The following queries can be used to identify exposed instances. Not all of these services are necessarily vulnerable.
