Skip to main content

Tag: remote code execution

320 articles

Laptop screen showing WordPress backend with file upload, in a cluttered office with city view.

WordPress Plugin Flaw Enables Unauthenticated Remote Code Execution

A critical vulnerability in the Forminator Forms WordPress plugin can let hackers upload malicious PHP files to your site, allowing them to take control and wreak havoc - all without needing a login. This flaw, tracked as CVE-2026-15748, has a near-perfect severity score of 9.8, making it a high-priority threat.

Analyst 207
Smartphone on a plain surface with blurred cityscape in background.

UNISOC Modem Flaw Enables Remote Code Execution

A newly discovered flaw in UNISOC modem firmware can be exploited to execute arbitrary code with kernel privileges, allowing hackers to gain deep access to Android devices. Simply making a video call to a vulnerable phone can trigger the attack.

Analyst 207
Smartphone on cluttered office desk with cityscape background through window.

Unisoc Exploit Chain Grants Attackers Full Android Kernel Access

Security researchers have uncovered a two-stage exploit chain that can give attackers full access to the Android kernel on devices using Unisoc modem firmware, and alarmingly, the vendor has remained unresponsive to disclosure efforts. This chain can be triggered by a simple malformed video call, putting countless devices at risk.

Analyst 207
Retail store checkout counter with point-of-sale terminal and shopping cart.

SAP Commerce Cloud Vulnerability Now Under Active Attack

Hackers are actively exploiting a critical vulnerability in SAP Commerce Cloud, allowing them to remotely execute code without any login credentials. This severe flaw, tracked as CVE-2026-58231, was patched by SAP just three days before attacks began.

Analyst 207
Blurred laptop screen on a table surrounded by chairs in a bright, daytime office setting.

Zoom Flaws Let Meeting Participants Hijack Other Attendees' Clients

Critical security flaws in Zoom's annotation code, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could have allowed a meeting participant to hijack others' clients without warning. Fortunately, Zoom has patched these vulnerabilities, and no exploitation has been reported.

Analyst 207
Rows of computer servers and network equipment in a corporate server room with a laptop screen in the foreground.

Researchers Expose AI-Assisted SharePoint Exploit Chain Enabling Unauthenticated RCE

In just 24 days, security researchers uncovered a shocking exploit chain that lets hackers impersonate any SharePoint user and run code on the server - no login required. This chain combines a clever JWT bypass with a second flaw, putting countless systems at risk.

Analyst 207
Rows of computer servers and storage systems in a brightly-lit server room.

Ransomware gangs exploit Microsoft SharePoint flaw

Ransomware gangs are actively exploiting a high-severity Microsoft SharePoint flaw, known as CVE-2026-45659, that allows them to execute arbitrary code on unpatched servers, and it's crucial to patch up ASAP to avoid falling victim. Microsoft has already released security updates for affected SharePoint versions, so make sure to get those installed pronto!

Analyst 207
Server terminal on a rack with generic screen, amidst technical infrastructure.

CISA Warns of Active TeamCity Exploit

Warning: a critical vulnerability in JetBrains TeamCity (CVE-2026-63077) is being actively exploited in the wild, allowing unauthenticated attackers to execute malicious code remotely. This severe flaw has a CVSS score of 9.8, highlighting the urgent need for immediate action.

Analyst 207
Blurred industrial control system in foreground, with brightly-lit equipment rows in the background.

IBM Langflow AI Platform Under Active Exploitation

A critical flaw in IBM's Langflow AI platform, tracked as CVE-2026-9198, is under active exploitation by hackers, who can use it to execute code remotely on vulnerable deployments. CISA has urged organizations to upgrade to Langflow OSS version 1.10.1 or later to mitigate the vulnerability.

Analyst 207
Technicians work in a network server room with rows of equipment racks and cables on the floor.

Paperclip AI Flaws Expose Servers to Host Command Attacks

Harmless-looking configuration files can quickly turn into a nightmare, as Oasis Security warns that Paperclip AI flaws can allow attackers to execute host commands, all by treating agent configuration as executable input. This vulnerability, including one flaw scored 10.0 by CVSS, can be exploited by unauthenticated actors to gain control of servers.

Analyst 207
Modern tech facility with server racks in background and laptop in foreground.

CISA Warns of Active Exploits in Langflow, N-central, Apache Tomcat Flaws

A critical flaw in IBM's Langflow, rated 9.8 out of 10, allows hackers to remotely execute code on vulnerable systems - and multiple easy-to-follow exploits have already surfaced online. This severe vulnerability enables attackers to bypass login and wreak havoc, making it a pressing concern for Langflow users.

Analyst 207
Rack of computer equipment with monitors in a neutral industrial setting.

CISA Warns of Active Exploits Targeting Langflow, Tomcat, and N-central Flaws

Stay safe online: CISA has flagged three major cybersecurity vulnerabilities, including a critical remote code execution flaw in Langflow, that are being actively exploited by hackers. A patch is available for the Langflow flaw, which was fixed in version 1.10.1.

Analyst 207
Office network setup with Wi-Fi access point and Ethernet switch on a table surrounded by generic office equipment.

TP-Link Omada ZTP Flaws Expose Networks to Remote Attacks

Critical flaws in TP-Link's Omada ZTP mechanism leave networks vulnerable to devastating remote attacks, including code execution, device hijacking, and eavesdropping. Forescout's Vedere Labs has discovered 15 vulnerabilities, now patched by TP-Link, that put small- to medium-sized businesses and enterprises at risk.

Analyst 207
Server room interior with rows of racks and a single workstation terminal.

Rails patches Active Storage flaw with RCE potential

A critical vulnerability in Rails' Active Storage, known as CVE-2026-66066, can allow an unauthenticated attacker to read sensitive files and potentially execute remote code, putting your application at risk. This flaw can be exploited under specific conditions, making it crucial to patch immediately.

Analyst 207
South Korean office with computers and people, one screen sharply focused on a webpage.

Hackers Exploit AnySign4PC Flaw via Compromised Korean Sites

Cyber attackers have cleverly exploited a flaw in popular South Korean security software, AnySign4PC, by hijacking legitimate websites to deliver backdoors to unsuspecting users at 72 organizations. The vulnerability, affecting software versions 1.1.4.4 through 1.1.4.6, allows hackers to execute remote code without users even clicking a download prompt.

Analyst 207
Shipping yard with container in foreground and blurred computer workstation in background.

Ruflo Flaw Exposes AI Systems to Unauthenticated Code Execution

A critical vulnerability in Ruflo, known as RufRoot, allows hackers to execute code remotely without authentication, putting AI systems at risk. This severe flaw, rated 10.0 on the CVSS scale, affects all Ruflo versions before 3.16.3.

Analyst 207
Cluttered coding workspace with computer, papers, and manuals, hinting at a Git project.

Gitea Flaw Lets Writers Run Shell Commands via Git Hook

A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.

Analyst 207
Network equipment and servers in a server room with a security appliance and workstation in focus.

Check Point Flaw Exploited as Researchers Release Public PoC

A critical flaw in Check Point's SmartConsole, known as CVE-2026-16232, allows hackers to bypass authentication and gain full administrative privileges with a staggering CVSS score of 9.3. This vulnerability lets unauthenticated remote attackers obtain a login token and take control, potentially modifying security policies and configurations.

Analyst 207
Rows of computer servers and equipment in a well-lit server room or data center.

TeamCity Flaw Enables Unauthenticated Remote Code Execution

A critical TeamCity vulnerability, CVE-2026-63077, with a near-perfect CVSS score of 9.8, leaves all on-premise servers open to unauthenticated remote code execution - allowing attackers to run malicious commands with ease. Update your TeamCity server immediately to prevent exploitation.

Analyst 207
Brightly-lit office workstation with laptop and router in background.

Hackers Exploit FastJson Zero-Day in Targeted US Firm Attacks

US-based organizations are being targeted in a series of attacks exploiting a critical zero-day flaw in the FastJson Java library, with researchers warning that the threat is likely to spread globally. The vulnerability, CVE-2026-16723, allows hackers to execute remote code without user interaction or elevated privileges.

Analyst 207
Laptop screen displays workflow editor in a tidy home office surrounded by notes and technical books.

n8n Flaw Lets Authenticated Editors Run OS Commands

A security flaw in n8n allows authenticated editors to run OS commands, thanks to two overlooked vulnerabilities that let them break free from the platform's protective sandbox. This weakness was uncovered by Security Joes' research team, who found that the flaws could be exploited to execute operating-system commands as the n8n process.

Analyst 207
Brightly-lit industrial control system terminal on a factory floor.

Cl0p Ransomware Gang Exploits PTC Windchill Flaw in Data Extortion Drive

PTC Windchill users are under attack, with threat actors actively exploiting a critical flaw (CVE-2026-12569) that allows for remote code execution, prompting PTC to warn customers of heightened threat activity. This vulnerability, with a CVSS score of 9.3, has already been added to the US government's list of known exploited vulnerabilities.

Analyst 207
Security researcher inspects a server in a data center.

GitLab RCE Exploit Published, Targets Unpatched Servers

A security researcher has just published a working exploit that can execute commands on unpatched GitLab servers, putting sensitive data and systems at risk. If your GitLab server is unpatched, it's crucial to update now to prevent potential code execution and data breaches.

Analyst 207
Technicians in a server room inspect equipment amidst rows of racks and storage devices.

Redis Exposes Zero-Days, RCE Exploit in Latest Security Releases

Redis just released seven security updates to fix major vulnerabilities that could let attackers run malicious code remotely, thanks to newly published proof-of-concept exploits targeting several Redis versions. The fixes cover multiple branches, including 6.x, 7.x, and 8.x, and patch memory-corruption flaws that can be triggered using the RESTORE command and other requirements.

Analyst 207