Tag: remote code execution
320 articles

WordPress Plugin Flaw Enables Unauthenticated Remote Code Execution
A critical vulnerability in the Forminator Forms WordPress plugin can let hackers upload malicious PHP files to your site, allowing them to take control and wreak havoc - all without needing a login. This flaw, tracked as CVE-2026-15748, has a near-perfect severity score of 9.8, making it a high-priority threat.

UNISOC Modem Flaw Enables Remote Code Execution
A newly discovered flaw in UNISOC modem firmware can be exploited to execute arbitrary code with kernel privileges, allowing hackers to gain deep access to Android devices. Simply making a video call to a vulnerable phone can trigger the attack.

Unisoc Exploit Chain Grants Attackers Full Android Kernel Access
Security researchers have uncovered a two-stage exploit chain that can give attackers full access to the Android kernel on devices using Unisoc modem firmware, and alarmingly, the vendor has remained unresponsive to disclosure efforts. This chain can be triggered by a simple malformed video call, putting countless devices at risk.

SAP Commerce Cloud Vulnerability Now Under Active Attack
Hackers are actively exploiting a critical vulnerability in SAP Commerce Cloud, allowing them to remotely execute code without any login credentials. This severe flaw, tracked as CVE-2026-58231, was patched by SAP just three days before attacks began.

Zoom Flaws Let Meeting Participants Hijack Other Attendees' Clients
Critical security flaws in Zoom's annotation code, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could have allowed a meeting participant to hijack others' clients without warning. Fortunately, Zoom has patched these vulnerabilities, and no exploitation has been reported.

Researchers Expose AI-Assisted SharePoint Exploit Chain Enabling Unauthenticated RCE
In just 24 days, security researchers uncovered a shocking exploit chain that lets hackers impersonate any SharePoint user and run code on the server - no login required. This chain combines a clever JWT bypass with a second flaw, putting countless systems at risk.

Ransomware gangs exploit Microsoft SharePoint flaw
Ransomware gangs are actively exploiting a high-severity Microsoft SharePoint flaw, known as CVE-2026-45659, that allows them to execute arbitrary code on unpatched servers, and it's crucial to patch up ASAP to avoid falling victim. Microsoft has already released security updates for affected SharePoint versions, so make sure to get those installed pronto!

CISA Warns of Active TeamCity Exploit
Warning: a critical vulnerability in JetBrains TeamCity (CVE-2026-63077) is being actively exploited in the wild, allowing unauthenticated attackers to execute malicious code remotely. This severe flaw has a CVSS score of 9.8, highlighting the urgent need for immediate action.

IBM Langflow AI Platform Under Active Exploitation
A critical flaw in IBM's Langflow AI platform, tracked as CVE-2026-9198, is under active exploitation by hackers, who can use it to execute code remotely on vulnerable deployments. CISA has urged organizations to upgrade to Langflow OSS version 1.10.1 or later to mitigate the vulnerability.

Paperclip AI Flaws Expose Servers to Host Command Attacks
Harmless-looking configuration files can quickly turn into a nightmare, as Oasis Security warns that Paperclip AI flaws can allow attackers to execute host commands, all by treating agent configuration as executable input. This vulnerability, including one flaw scored 10.0 by CVSS, can be exploited by unauthenticated actors to gain control of servers.

CISA Warns of Active Exploits in Langflow, N-central, Apache Tomcat Flaws
A critical flaw in IBM's Langflow, rated 9.8 out of 10, allows hackers to remotely execute code on vulnerable systems - and multiple easy-to-follow exploits have already surfaced online. This severe vulnerability enables attackers to bypass login and wreak havoc, making it a pressing concern for Langflow users.

CISA Warns of Active Exploits Targeting Langflow, Tomcat, and N-central Flaws
Stay safe online: CISA has flagged three major cybersecurity vulnerabilities, including a critical remote code execution flaw in Langflow, that are being actively exploited by hackers. A patch is available for the Langflow flaw, which was fixed in version 1.10.1.

TP-Link Omada ZTP Flaws Expose Networks to Remote Attacks
Critical flaws in TP-Link's Omada ZTP mechanism leave networks vulnerable to devastating remote attacks, including code execution, device hijacking, and eavesdropping. Forescout's Vedere Labs has discovered 15 vulnerabilities, now patched by TP-Link, that put small- to medium-sized businesses and enterprises at risk.

Rails patches Active Storage flaw with RCE potential
A critical vulnerability in Rails' Active Storage, known as CVE-2026-66066, can allow an unauthenticated attacker to read sensitive files and potentially execute remote code, putting your application at risk. This flaw can be exploited under specific conditions, making it crucial to patch immediately.

Hackers Exploit AnySign4PC Flaw via Compromised Korean Sites
Cyber attackers have cleverly exploited a flaw in popular South Korean security software, AnySign4PC, by hijacking legitimate websites to deliver backdoors to unsuspecting users at 72 organizations. The vulnerability, affecting software versions 1.1.4.4 through 1.1.4.6, allows hackers to execute remote code without users even clicking a download prompt.

Ruflo Flaw Exposes AI Systems to Unauthenticated Code Execution
A critical vulnerability in Ruflo, known as RufRoot, allows hackers to execute code remotely without authentication, putting AI systems at risk. This severe flaw, rated 10.0 on the CVSS scale, affects all Ruflo versions before 3.16.3.

Gitea Flaw Lets Writers Run Shell Commands via Git Hook
A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.

Check Point Flaw Exploited as Researchers Release Public PoC
A critical flaw in Check Point's SmartConsole, known as CVE-2026-16232, allows hackers to bypass authentication and gain full administrative privileges with a staggering CVSS score of 9.3. This vulnerability lets unauthenticated remote attackers obtain a login token and take control, potentially modifying security policies and configurations.

TeamCity Flaw Enables Unauthenticated Remote Code Execution
A critical TeamCity vulnerability, CVE-2026-63077, with a near-perfect CVSS score of 9.8, leaves all on-premise servers open to unauthenticated remote code execution - allowing attackers to run malicious commands with ease. Update your TeamCity server immediately to prevent exploitation.

Hackers Exploit FastJson Zero-Day in Targeted US Firm Attacks
US-based organizations are being targeted in a series of attacks exploiting a critical zero-day flaw in the FastJson Java library, with researchers warning that the threat is likely to spread globally. The vulnerability, CVE-2026-16723, allows hackers to execute remote code without user interaction or elevated privileges.

n8n Flaw Lets Authenticated Editors Run OS Commands
A security flaw in n8n allows authenticated editors to run OS commands, thanks to two overlooked vulnerabilities that let them break free from the platform's protective sandbox. This weakness was uncovered by Security Joes' research team, who found that the flaws could be exploited to execute operating-system commands as the n8n process.

Cl0p Ransomware Gang Exploits PTC Windchill Flaw in Data Extortion Drive
PTC Windchill users are under attack, with threat actors actively exploiting a critical flaw (CVE-2026-12569) that allows for remote code execution, prompting PTC to warn customers of heightened threat activity. This vulnerability, with a CVSS score of 9.3, has already been added to the US government's list of known exploited vulnerabilities.

GitLab RCE Exploit Published, Targets Unpatched Servers
A security researcher has just published a working exploit that can execute commands on unpatched GitLab servers, putting sensitive data and systems at risk. If your GitLab server is unpatched, it's crucial to update now to prevent potential code execution and data breaches.

Redis Exposes Zero-Days, RCE Exploit in Latest Security Releases
Redis just released seven security updates to fix major vulnerabilities that could let attackers run malicious code remotely, thanks to newly published proof-of-concept exploits targeting several Redis versions. The fixes cover multiple branches, including 6.x, 7.x, and 8.x, and patch memory-corruption flaws that can be triggered using the RESTORE command and other requirements.