Skip to main content

Tag: unauthenticated rce

5 articles

Network equipment and technicians in a blurred background with a prominent device or screen in the foreground.

F5 Discloses Zero-Day Flaw in BIG-IP APM Exploited for Unauthenticated RCE

A critical flaw in F5's BIG-IP Access Policy Manager is being exploited by attackers, allowing them to run code on the system without logging in. This severe vulnerability, tracked as CVE-2026-94127, has a near-perfect score of 9.8/10 on CVSS v3.1 and enables unauthenticated remote code execution.

Analyst 207
Server room equipment with a central computer server in sharp focus.

SolarWinds Fixes Hard-Coded Key Flaw in Access Rights Manager

SolarWinds has patched a high-severity vulnerability in its Access Rights Manager software, known as CVE-2026-28326, which could have allowed hackers to remotely execute code without authentication due to a hard-coded static key. The flaw, scoring 8.8 out of 10 in severity, has been fixed in ARM 2026.2.1, and users are urged to update to prevent potential attacks.

Analyst 207
Cluttered workstation with computer and technical equipment in a neutral room.

Telerik UI Flaw Exposes Unauthenticated RCE Risk

A newly discovered flaw in Telerik UI for ASP.NET AJAX can be exploited to achieve unauthenticated remote code execution, thanks to a publicly released proof-of-concept that combines an AES-CBC padding oracle with a type-resolution bug in the RadAsyncUpload control. When certain preconditions are met, this vulnerability can be easily leveraged for devastating effect.

Analyst 207
Rows of computer servers and network equipment in a corporate server room with a laptop screen in the foreground.

Researchers Expose AI-Assisted SharePoint Exploit Chain Enabling Unauthenticated RCE

In just 24 days, security researchers uncovered a shocking exploit chain that lets hackers impersonate any SharePoint user and run code on the server - no login required. This chain combines a clever JWT bypass with a second flaw, putting countless systems at risk.

Analyst 207
Industrial control system in a factory setting with a nearby computer screen.

Weaver E-cology Flaw Exploited Through Debug API Endpoint

A critical bug in Weaver E-cology, known as CVE-2026-22679, is being actively exploited - allowing hackers to take full control of your system with a CVSS score of 9.8. This severe vulnerability lets attackers execute commands without needing login credentials, putting your entire system at risk.

Analyst 207