Tag: unauthenticated rce
5 articles

F5 Discloses Zero-Day Flaw in BIG-IP APM Exploited for Unauthenticated RCE
A critical flaw in F5's BIG-IP Access Policy Manager is being exploited by attackers, allowing them to run code on the system without logging in. This severe vulnerability, tracked as CVE-2026-94127, has a near-perfect score of 9.8/10 on CVSS v3.1 and enables unauthenticated remote code execution.

SolarWinds Fixes Hard-Coded Key Flaw in Access Rights Manager
SolarWinds has patched a high-severity vulnerability in its Access Rights Manager software, known as CVE-2026-28326, which could have allowed hackers to remotely execute code without authentication due to a hard-coded static key. The flaw, scoring 8.8 out of 10 in severity, has been fixed in ARM 2026.2.1, and users are urged to update to prevent potential attacks.

Telerik UI Flaw Exposes Unauthenticated RCE Risk
A newly discovered flaw in Telerik UI for ASP.NET AJAX can be exploited to achieve unauthenticated remote code execution, thanks to a publicly released proof-of-concept that combines an AES-CBC padding oracle with a type-resolution bug in the RadAsyncUpload control. When certain preconditions are met, this vulnerability can be easily leveraged for devastating effect.

Researchers Expose AI-Assisted SharePoint Exploit Chain Enabling Unauthenticated RCE
In just 24 days, security researchers uncovered a shocking exploit chain that lets hackers impersonate any SharePoint user and run code on the server - no login required. This chain combines a clever JWT bypass with a second flaw, putting countless systems at risk.

Weaver E-cology Flaw Exploited Through Debug API Endpoint
A critical bug in Weaver E-cology, known as CVE-2026-22679, is being actively exploited - allowing hackers to take full control of your system with a CVSS score of 9.8. This severe vulnerability lets attackers execute commands without needing login credentials, putting your entire system at risk.