Tag: command injection
39 articles

Ubiquiti Disrupts Three Max-Severity Flaws in UniFi Systems
Ubiquiti has just dropped a critical security update to fix three massive vulnerabilities in its UniFi systems that hackers can exploit remotely without needing any special access. If you're using UniFi, now's the time to patch up and keep your network safe!

CISA Mandates Emergency Patching for Exploited Zimbra Flaw
A critical Zimbra flaw, CVE-2026-73570, allows hackers to inject malicious code, and the CISA is mandating emergency patching to prevent devastating attacks - don't wait, get protected now!

Zimbra SNMP Flaw Exploited for Remote Code Execution
A critical Zimbra SNMP flaw, CVE-2026-73570, with a CVSS score of 8.9, is under active exploitation, allowing attackers to execute remote code. This vulnerability can be triggered by sending specially crafted SNMP requests, putting unpatched Zimbra Collaboration systems at risk.

Zimbra Vulnerability Exploited in Active Attacks
A critical vulnerability in the Zimbra Collaboration Suite is under active attack, putting over 12,100 exposed servers worldwide at risk, with most located in Europe and Asia. Attackers can exploit this flaw, tracked as CVE-2026-73570, to execute remote code without authentication, simply by sending specially crafted SMTP requests.

Hackers Actively Exploit Critical LoadMaster Flaw in Global Attacks
Hackers are actively exploiting a critical flaw in LoadMaster, known as CVE-2026-8037, which allows them to run malicious commands on unpatched devices - putting your security at risk if you haven't updated yet. This vulnerability enables unauthenticated attackers to take control, making it crucial to patch Progress Kemp LoadMaster appliances ASAP.

CISA Warns of Active Progress Kemp LoadMaster Exploit Attempts
The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical flaw in Progress Kemp LoadMaster, warning of a surge in exploitation attempts - 792 attempts in just 41 days - and adding the bug to its list of known exploited vulnerabilities. This highly severe vulnerability, with a CVSS score of 9.6, allows attackers to execute arbitrary commands on the LoadMaster appliance without authentication.

Paperclip AI Flaws Expose Servers to Host Command Attacks
Harmless-looking configuration files can quickly turn into a nightmare, as Oasis Security warns that Paperclip AI flaws can allow attackers to execute host commands, all by treating agent configuration as executable input. This vulnerability, including one flaw scored 10.0 by CVSS, can be exploited by unauthenticated actors to gain control of servers.

Arista VeloCloud Flaw Exposes On-Premises Networks to Active Exploitation
A critical security flaw in Arista VeloCloud, tracked as CVE-2026-16812, is under active exploitation, allowing remote attackers to access sensitive internal functionality and potentially leading to arbitrary code execution. This maximum-severity vulnerability could compromise the confidentiality, integrity, and availability of on-premises networks.

Arista Disrupts Zero-Day Attacks on VeloCloud Orchestrator
Arista has patched a critical zero-day vulnerability in its VeloCloud Orchestrator that allowed attackers to launch devastating, maximum-severity attacks with just network access - no login credentials required. The flaw, rated 10.0 in severity, could compromise the confidentiality, integrity, and availability of sensitive data managed by the orchestrator.

Bing Image Flaws Expose Microsoft Servers to Command Injection Attacks
Microsoft's Bing Image processing pipeline had a shocking vulnerability that allowed hackers to inject malicious commands, thanks to two critical flaws discovered by XBOW. These flaws enabled attackers to gain alarming levels of access, running commands as the system's highest authority on both Windows and Linux hosts.

Zimbra Fixes Command Injection Flaw, Four XSS Bugs
Zimbra has patched a critical command injection flaw and four cross-site scripting bugs in its latest update, ensuring users are protected from potential security threats. The fixes, part of version 10.1.20, address vulnerabilities that could allow malicious commands to be executed or sensitive data to be compromised.

Ubiquiti Fixes Flaws in UniFi Ecosystem
Ubiquiti has patched a critical vulnerability in its UniFi ecosystem, specifically a command injection flaw with a perfect 10.0 CVSS score, that could let hackers take control of your device. The update fixes issues across UniFi products, shielding you from potential attacks that could escalate privileges or make unauthorized changes.

Ubiquiti Discloses Max-Severity UniFi OS Vulnerability
Ubiquiti has urgently patched a critical vulnerability in its UniFi OS, warning customers of a maximum-severity flaw that could allow malicious actors to inject commands on host devices - and it's crucial to upgrade to version 3.4.20 or later to stay safe.

Mandiant Exposes Cisco SD-WAN Zero-Day Attacks' Root Access Methods
Cisco's SD-WAN system was exploited in active attacks using a high-severity flaw, allowing hackers to create a rogue root account and take full control of targeted devices. This vulnerability, tracked as CVE-2026-20245, was triggered through a simple tenant-upload feature in the command-line interface.

Cisco SD-WANs Hit by Seventh Zero-Day Exploit This Year
Cisco SD-WANs have been hit by a seventh zero-day exploit this year, with the latest vulnerability, CVE-2026-20245, already being actively exploited by attackers. A security patch is currently in the works, but no workaround is available to mitigate the issue in the meantime.

LiteLLM Flaw Exploited in Wild, Enables Unauthenticated RCE
A high-severity flaw in BerriAI's LiteLLM, known as CVE-2026-42271, has been actively exploited, allowing unauthenticated users to execute commands remotely. This critical vulnerability affects LiteLLM versions 1.74.2 to 1.83.7 and has been deemed a major security risk.

Cisco SD-WAN Manager Flaw Actively Exploited
Cisco is warning of a high-severity vulnerability in its Catalyst SD-WAN Manager that allows attackers to execute commands as root, and it's already being exploited by hackers. This flaw, rated 7.8 on the CVSS scale, could give attackers control over your system if they're able to upload a malicious file.

GitHub Flaw Exposes Remote Code Execution to Authenticated Users
A single git push command was all it took to exploit a flaw in GitHub's internal protocol, allowing authenticated users to execute code on backend infrastructure. This shocking vulnerability, tracked as CVE-2026-3854, highlights the potential for devastating remote code execution attacks.

SGLang Flaw Enables Remote Code Execution via Malicious Model Files
A single malicious file can become a powerful gateway for attackers to run arbitrary commands on vulnerable machines - and a newly disclosed flaw in SGLang, CVE-2026-5760, reveals just how easily this can happen through specially crafted GGUF model files. This highly severe vulnerability, scoring 9.8 out of 10.0, enables remote code execution on systems that trust it.

Mirai Botnet Targets TP-Link Routers via CVE-2023-33538 Exploits
Your home router could be a ticking time bomb, vulnerable to exploitation by malicious actors - in fact, a known weakness (CVE-2023-33538) in TP-Link routers has already been targeted by the notorious Mirai botnet. Is your small but mighty box at risk of becoming a launchpad for someone else's agenda?

Fortinet Sandbox Flaws Allow Attackers to Bypass Authentication, Execute Commands
Two critical flaws in Fortinet's sandbox could let attackers skip login and run malicious commands, putting your system at risk - so don't wait, patch now! A recent report urges administrators to act fast, as these vulnerabilities could be exploited by unauthenticated attackers over HTTP.

PHP Composer Flaws Expose Code Execution Risk, Prompting Patches
Critical flaws in PHP Composer, a popular package manager, leave countless websites vulnerable to code execution attacks - but fortunately, patches have been released to swiftly mitigate this risk. If exploited, these high-severity vulnerabilities could allow hackers to execute arbitrary commands, putting entire systems at risk.

Claude Desktop Extensions Exclusive: Critical Prompt Risk
Claude Desktop extensions make assistants truly useful — but when they execute local actions, attackers can turn innocent prompts into harmful commands. The recent command‑injection flaws in three extensions, now patched by Anthropic, are a reminder that convenience brings new security risks.

Libraesva ESG Urgent Patch: Critical Risk Exposed
A newly patched command-injection flaw in Libraesva’s Email Security Gateway was reportedly exploited by state-sponsored actors, putting email perimeters at risk of lateral movement and data theft. If you run ESG, update immediately, segment management interfaces, and hunt for signs of compromise.