Skip to main content

Tag: unauthenticated remote code execution

3 articles

Government employee examines laptop in geographic information system room with digital map display and server equipment.

GeoNetwork Flaw Exposes Government Geoportal Backends to Unauthenticated Code Execution

A shocking security flaw in GeoNetwork has been discovered, leaving government and agency geoportals vulnerable to unauthenticated code execution - and it's already been exploited in 121 internet-exposed deployments across 39 countries. The vulnerability allows attackers to upload malicious files, giving them free rein to wreak havoc on sensitive systems.

Analyst 207
Rows of computer servers and equipment in a well-lit server room or data center.

TeamCity Flaw Enables Unauthenticated Remote Code Execution

A critical TeamCity vulnerability, CVE-2026-63077, with a near-perfect CVSS score of 9.8, leaves all on-premise servers open to unauthenticated remote code execution - allowing attackers to run malicious commands with ease. Update your TeamCity server immediately to prevent exploitation.

Analyst 207
Brightly-lit tech setting with rows of equipment in the background and an unoccupied computer terminal in the foreground.

Langflow Vulnerability Exploited for Unauthenticated Remote Code Execution

A single, unauthenticated request is all it takes to exploit a high-severity flaw in Langflow, allowing attackers to execute remote code without needing any login credentials. This vulnerability, tracked as CVE-2026-5027, enables malicious actors to write files to any location on a host filesystem.

Analyst 207