Tag: unauthenticated attacks
22 articles

PaperCut Flaws Chained for Remote Code Execution
Researchers have uncovered a vulnerability in PaperCut that allows an unauthenticated attacker to gain remote control, enabling them to execute arbitrary Java code within the application's process. This flaw can be exploited through a clever two-step chaining technique, putting unpatched PaperCut NG and MF instances at risk.

ServiceNow Flaws Expose Code, SQL to Unauthenticated Attackers
Critical vulnerabilities in ServiceNow's Now Platform could allow unauthenticated attackers to execute arbitrary code or SQL, putting sensitive data at risk. Three flaws, earning the maximum CVSS score of 10.0, were recently disclosed, highlighting an urgent need for patching to prevent devastating attacks.

Next.js Patches Flaws Enabling Unauthenticated Remote Code Execution
If your Next.js application is hosted on Windows, upgrade immediately to patch a critical vulnerability that allows unauthenticated remote code execution. This flaw, tracked as CVE-2026-75604, affects apps using both Pages Router and App Router without Cache Components.

Keycloak Flaw Exposes Accounts to Unauthenticated Takeover
A critical flaw in Keycloak, rated 9.1 by Red Hat, allows hackers to hijack any account, including admin ones, by manipulating the password reset process. This vulnerability, CVE-2026-18963, lets attackers take control without even logging in.

GitLab Patches Flaw That Exposes Public Projects to Unauthenticated Deletion
GitLab has urgently patched a critical vulnerability that left public projects open to deletion by anyone, with no login required - a flaw that scored a near-perfect 9.4 on the severity scale. The fix addresses a GraphQL weakness that could let unauthenticated users remotely modify or delete public projects and user data.

SAP Patches Critical Flaw Allowing Unauthenticated Code Execution
A critical flaw in SAP Commerce Cloud, rated 10.0 on the CVSS scale, allows hackers to execute malicious code without any authentication, putting your entire system at risk. This severe vulnerability can be exploited with specially crafted input, making it essential to patch ASAP.

Gitea Flaw Exposes Server Files to Unauthenticated Attackers
A critical vulnerability, CVE-2026-59774, left self-hosted Gitea servers open to attack, allowing unauthenticated hackers to access sensitive files. Immediate action is required for self-hosted administrators to upgrade to version 1.27.1 and prevent exploitation.

Rails Flaw Exposes Server Files to Unauthenticated Attackers
A critical security flaw in Rails, known as CVE-2026-66066, could let hackers read sensitive files from your server, including secret keys, database passwords, and API tokens, by exploiting image uploads. This vulnerability affects various Rails releases, including versions 7.0.0 through 7.2.3.1, 8.0.0 through 8.0.5, and 8.1.0 through 8.1.3.

vBulletin Flaw Exploits Unpatched Servers
A critical vBulletin security flaw, tracked as CVE-2026-61511, leaves unpatched servers vulnerable to attacks, allowing hackers to execute malicious PHP code and putting forum operators and their communities at risk. This exploit affects vBulletin versions 5.x and 6.x, up to 5.7.5 and 6.2.1, respectively.

WordPress Exploits Spread as Attackers Chain Critical Vulnerabilities
Within hours of public disclosure, hackers leveraged AI models to exploit two critical WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, that when combined enable unauthenticated remote code execution. This potent pairing allows attackers to wreak havoc on websites, highlighting the urgent need for updates.

WordPress Discloses Core Flaw Enabling Unauthenticated Code Execution
WordPress has patched a critical flaw that allowed hackers to execute code remotely without authentication, releasing versions 6.9.5 and 7.0.2 to fix the vulnerability. The update addresses a REST API batch-route confusion and SQL injection issue that could be triggered by a simple HTTP request.

Cordyceps Flaws Compromise 300+ GitHub Repositories
A newly discovered flaw, dubbed Cordyceps, has left over 300 GitHub repositories vulnerable to exploitation by unauthenticated users, allowing for code execution, credential theft, and supply-chain compromise. This critical weakness can be easily exploited, putting countless open-source projects at risk.

Attackers Exploit Langflow Path Traversal Flaw in Active Attacks
A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, a popular AI development platform, allowing attackers to write arbitrary files to its filesystem. This is made possible by a path traversal vulnerability, CVE-2026-5027, which can be easily triggered due to Langflow's default unauthenticated auto-login feature.

LiteLLM Flaw Exploited in Wild, Enables Unauthenticated RCE
A high-severity flaw in BerriAI's LiteLLM, known as CVE-2026-42271, has been actively exploited, allowing unauthenticated users to execute commands remotely. This critical vulnerability affects LiteLLM versions 1.74.2 to 1.83.7 and has been deemed a major security risk.

CISA Warns of Actively Exploited Oracle WebLogic Server Vulnerability
The US Cybersecurity and Infrastructure Security Agency (CISA) is sounding the alarm on a highly exploitable Oracle WebLogic Server vulnerability, CVE-2024-21182, that's being actively targeted by threat actors. Over 1,592 vulnerable servers are currently exposed online, making it a pressing concern for organizations to patch up ASAP.

Hackers Exploit WP Maps Pro Bug to Hijack WordPress Sites
In just 24 hours, over 3,600 hacking attempts were made to exploit a critical flaw in the WP Maps Pro plugin, allowing attackers to create admin accounts and log in without a password. This vulnerability, affecting version 6.1.0 and older, puts countless WordPress sites at risk.

Gogs Zero-Day Flaw Enables Remote Code Execution on Exposed Servers
A zero-day flaw in Gogs, a self-hosted Git service, leaves exposed servers vulnerable to remote code execution - and it's surprisingly easy for attackers to exploit, as they can create an account and repository on default-configured instances. This critical-severity vulnerability affects the latest release versions and requires only an authenticated user without admin privileges to launch an attack.

Gitea Flaw Exposes Private Container Images to Unauthenticated Attacks
A newly disclosed vulnerability in Gitea, tracked as CVE-2026-27771, allows unauthenticated attackers to access private container images, potentially exposing tens of thousands of deployments worldwide. This flaw lets anyone on the internet pull private images without needing an account, password, or credentials.

KnowledgeDeliver LMS Flaw Exploited to Deploy Malware
A security flaw in the KnowledgeDeliver LMS, known as CVE-2026-5426, was exploited by a threat actor to inject malicious code and infect users visiting the site. This vulnerability was caused by a predictable secret in the system's web.config file, allowing attackers to execute remote code.

Mandiant Exposes KnowledgeDeliver Vulnerability via ViewState Deserialization
A critical vulnerability, CVE-2026-5426, was discovered in KnowledgeDeliver installations, allowing unauthenticated remote code execution across multiple customer sites due to identical ASP.NET machineKey values. This widespread flaw was caused by a standardized web.config with hardcoded keys, used across deployments, leaving sites vulnerable to attack.

NGINX Flaw Enables Unauthenticated Remote Code Execution
A critical 18-year-old vulnerability, known as NGINX Rift, has been discovered in NGINX Plus and NGINX Open Source, allowing unauthenticated attackers to remotely execute code with a single crafted HTTP request. This high-severity flaw, rated 9.2 on the CVSS v4 scale, poses a significant threat to vulnerable servers.

Hackers Exploit Weaver E-cology Bug in Targeted Attacks
Hackers are taking advantage of a critical bug in Weaver E-cology, using an exposed debug API endpoint to execute system commands on vulnerable servers without needing login credentials. This security flaw, tracked as CVE-2026-22679, affects Weaver E-cology 10.0 builds prior to March 12.