Tag: unauthenticated code execution
3 articles

Ruflo Flaw Exposes AI Systems to Unauthenticated Code Execution
A critical vulnerability in Ruflo, known as RufRoot, allows hackers to execute code remotely without authentication, putting AI systems at risk. This severe flaw, rated 10.0 on the CVSS scale, affects all Ruflo versions before 3.16.3.

ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
A critical vulnerability in the ServiceNow AI Platform, known as CVE-2026-6875, has been discovered, allowing unauthenticated users to execute arbitrary code and potentially compromise entire instances and connected proxy servers. This severe flaw has been assigned a CVSS score of 9.5, highlighting the urgent need for enhanced security measures.

Splunk Enterprise Flaw Exposes Systems to Unauthenticated Code Execution
A critical vulnerability in Splunk Enterprise, rated 9.8 on the CVSS scale, leaves systems open to devastating attacks, allowing unauthenticated hackers to execute malicious code and wreak havoc. This shocking flaw, tracked as CVE-2026-20253, enables attackers to create or truncate files with ease, putting your entire system at risk.