Tag: remote code execution
320 articles

PaperCut Zero-Days Exploited in Data Theft Attacks
Hackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF, using them to bypass authentication and steal sensitive data from vulnerable print management servers. Attackers have already been spotted chaining these flaws to launch data theft attacks, prompting emergency patches from PaperCut Software.

PaperCut Vulnerabilities Expose Enterprises to Elevated Threats
PaperCut's recent vulnerabilities, CVE-2026-82078 and CVE-2026-81578, pose a severe threat to enterprises, allowing attackers to gain remote access to sensitive information with ease - and no authentication required. This alarming weakness has security experts warning of elevated risks and potential breaches.

WordPress Flaws Expose Sites to Takeover, Code Execution
Critical vulnerabilities in popular WordPress plugins and themes have been exposed, putting sites at risk of takeover, remote code execution, and full compromise. Five flaws with near-maximum severity ratings have been disclosed, affecting specific versions of WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP.

Claude Code Exposed to High-Risk Prompt Injection Attacks
A security researcher has uncovered a vulnerability in Anthropic's Claude Code, demonstrating a clever exploit that tricks the AI into executing malicious code, highlighting the risks of prompt injection attacks. This alarming discovery was made by Johann Rehberger, who shared a step-by-step breakdown of the exploit, revealing a surprisingly simple path to remote code execution.

PaperCut Flaws Chained for Remote Code Execution
Researchers have uncovered a vulnerability in PaperCut that allows an unauthenticated attacker to gain remote control, enabling them to execute arbitrary Java code within the application's process. This flaw can be exploited through a clever two-step chaining technique, putting unpatched PaperCut NG and MF instances at risk.

Unitree Humanoid Robot Flaws Expose Root Code Execution Risk
A security researcher has uncovered two critical vulnerabilities in the Unitree G1 EDU robot, allowing hackers to remotely execute code with root access, potentially putting users and systems at risk. These flaws, tracked as CVE-2026-76639 and CVE-2026-76640, highlight the importance of robust security measures in robotics and AI technology.

Gitea Servers Exposed to Ongoing Code Execution Attacks
Thousands of Gitea servers remain vulnerable to code execution attacks, with 8393 Internet-exposed IPs still susceptible to CVE-2026-60004, a code injection bug that lets attackers execute arbitrary shell commands. This flaw can be easily exploited by anyone with write access to a repository, which is especially concerning since Gitea enables self-registration by default.

Next.js Patches Flaws Enabling Unauthenticated Remote Code Execution
If your Next.js application is hosted on Windows, upgrade immediately to patch a critical vulnerability that allows unauthenticated remote code execution. This flaw, tracked as CVE-2026-75604, affects apps using both Pages Router and App Router without Cache Components.

Avada WordPress Theme Flaw Enables Zero-Click Remote Code Execution
A critical vulnerability in the Avada WordPress theme, scored 9.8 out of 10, can be exploited through a zero-click remote code execution attack, allowing hackers to run malicious PHP code on affected sites without needing login credentials. This flaw enables attackers to take full control of a site, planting malware, stealing data, or creating rogue admin accounts.

Hackers Exploit Microsoft SharePoint Flaws in Ongoing RCE Attacks
Hackers are actively exploiting a pair of Microsoft SharePoint vulnerabilities, chaining them together in a potentially devastating attack that could give them remote control of your system. Threat intelligence firm Defused has detected live probes against its honeypots, sounding the alarm for businesses to take action now.

Unpatched Kaltura Flaws Expose Servers to Remote Code Execution
A pair of unpatched vulnerabilities in Kaltura's mwEmbed HTML5 player library could put servers at risk of remote code execution, allowing attackers to read sensitive files and run malicious code - and affecting not just individual customers, but also every tenant on shared hosting infrastructure. This critical security gap, tracked as CVE-2026-19913 and CVE-2026-19912, remains unpatched, leaving countless systems exposed.

Ubiquiti Disrupts Three Max-Severity Flaws in UniFi Systems
Ubiquiti has just dropped a critical security update to fix three massive vulnerabilities in its UniFi systems that hackers can exploit remotely without needing any special access. If you're using UniFi, now's the time to patch up and keep your network safe!

Gitea Flaw Exploited in Code Injection Attacks
A critical flaw in Gitea, tracked as CVE-2026-60004, is being actively exploited in code injection attacks, putting nearly 5,000 self-hosted Git service instances at risk. Attackers can inject malicious code by submitting patches via Gitea's diffpatch API endpoint, allowing them to execute arbitrary shell commands.

Hackers Breach 270 Zimbra Servers in Remote Code Execution Attacks
A massive wave of hacking attacks has hit 270 Zimbra servers, exploiting a vulnerability that lets attackers inject malicious code remotely, with fixes available since July 20. The attacks, tracked as CVE-2026-73570, have been spreading rapidly, sparking urgent security warnings.

CISA Mandates Emergency Patching for Exploited Zimbra Flaw
A critical Zimbra flaw, CVE-2026-73570, allows hackers to inject malicious code, and the CISA is mandating emergency patching to prevent devastating attacks - don't wait, get protected now!

Microsoft Entra ID Flaw Exploited, Enables Remote Code Execution
Microsoft warns of a critical flaw in Entra ID that lets hackers execute code remotely by exploiting a deserialization vulnerability, giving them free rein to wreak havoc over the network. This maximum-severity flaw, tracked as CVE-2026-69836, has been patched, but highlights the importance of staying vigilant against remote code execution threats.

Zimbra SNMP Flaw Exploited for Remote Code Execution
A critical Zimbra SNMP flaw, CVE-2026-73570, with a CVSS score of 8.9, is under active exploitation, allowing attackers to execute remote code. This vulnerability can be triggered by sending specially crafted SNMP requests, putting unpatched Zimbra Collaboration systems at risk.

Elementor Pro Flaw Enables RCE Attacks on WordPress Sites
A critical vulnerability in Elementor Pro, tracked as CVE-2026-32475, allows attackers to launch remote code execution (RCE) attacks on WordPress sites by exploiting a discrepancy in the plugin's File Upload module. This flaw affects Elementor Pro versions before 4.2.2 and can be triggered by a specially crafted multipart upload.

Zimbra Vulnerability Exploited in Active Attacks
A critical vulnerability in the Zimbra Collaboration Suite is under active attack, putting over 12,100 exposed servers worldwide at risk, with most located in Europe and Asia. Attackers can exploit this flaw, tracked as CVE-2026-73570, to execute remote code without authentication, simply by sending specially crafted SMTP requests.

Elementor Pro Flaw Enables Unauthenticated Code Execution
A critical vulnerability in Elementor Pro, rated CVSS 9.0, allows hackers to execute malicious code remotely - and it's surprisingly easy to exploit, thanks to a logic flaw in the plugin's Forms module. This loophole lets attackers bypass security checks and write PHP files to a public uploads directory.

Hackers Actively Exploit Windows IKE Flaw
Hackers are actively exploiting a critical Windows flaw, known as CVE-2026-33824, that lets them execute code over a network, putting your system at risk. This vulnerability, found in the Windows Internet Key Exchange (IKE) Service Extensions, affects all supported Windows 10 and other Windows systems.

CISA Mandates Swift Fix for Exploited Ray RCE Flaw
A critical bug in the Ray framework, scoring 9.4 under CVSS v4, can be exploited for remote code execution with a simple visit to a malicious web page or hostile ad in Firefox or Safari. This vulnerability can be triggered when an attacker crafts requests that appear browser-originated, allowing for a potentially disastrous security breach.

CISA Warns of Actively Exploited Ray Flaw Enabling Browser-Based RCE
A critical vulnerability, CVE-2025-62593, is under active exploitation, allowing hackers to execute remote code through web browsers like Firefox and Safari by using a clever DNS rebinding attack. This high-severity flaw, with a CVSS score of 9.4, stems from a weakness in the Ray project's defenses against browser-based attacks.

GitLab Patches Flaw That Exposes Public Projects to Unauthenticated Deletion
GitLab has urgently patched a critical vulnerability that left public projects open to deletion by anyone, with no login required - a flaw that scored a near-perfect 9.4 on the severity scale. The fix addresses a GraphQL weakness that could let unauthenticated users remotely modify or delete public projects and user data.