#remote-code-execution

[ follow ]
#ivanti-epmm
#smartermail
#n8n
#solarwinds
fromSecurityWeek
23 hours ago
Information security

SolarWinds Patches Critical Web Help Desk Vulnerabilities

SolarWinds released patches for six Web Help Desk vulnerabilities, including four critical unauthenticated deserialization and authentication-bypass flaws enabling remote code execution.
fromThe Hacker News
1 day ago
Information security

SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass

SolarWinds Web Help Desk has multiple critical vulnerabilities, including deserialization flaws enabling unauthenticated remote code execution; updates fixed issues in WHD 2026.1.
Information security
fromSecurityWeek
2 days ago

'PackageGate' Flaws Open JavaScript Ecosystem to Supply Chain Attacks

Six vulnerabilities in major JavaScript package managers (NPM, PNPM, VLT, Bun) allow bypassing supply chain protections and enable remote code execution.
Information security
fromThe Hacker News
3 days ago

Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas

A Pyodide sandbox escape (Cellbreak, CVE-2026-24002) in Grist-Core allows remote code execution; upgrade to Grist 1.7.9 or later to mitigate.
Information security
fromKotaku
3 days ago

Report Of Steam Game Exploit Leads To Online Dispute With Devs

A remote code execution vulnerability in Screeps: World allowed players to gain control of others' computers, prompting developers to patch after a disputed report.
Information security
fromTechRepublic
1 week ago

Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities - TechRepublic

Emergency patches for Zoom and GitLab fix critical vulnerabilities that could enable remote code execution, full network takeover, and development-operation crashes.
Apple
fromTechRepublic
1 week ago

New iOS and iPadOS Flaws Leave Millions of iPhones at Risk

Two WebKit vulnerabilities (CVE-2025-43529 and CVE-2025-14174) allow zero-click remote code execution in Safari, potentially giving attackers full access to iPhones and iPads.
Information security
fromSecurityWeek
4 days ago

2024 VMware Flaw Now in Attackers' Crosshairs

CVE-2024-37079, a critical DCERPC out-of-bounds write in VMware vCenter (CVSS 9.8), is being exploited in the wild; apply June 2024 patches immediately.
Information security
fromTechzine Global
1 week ago

Misuse of VS Code tasks poses risk to developers

VS Code tasks.json can automatically run commands when a folder is opened, enabling supply-chain attacks that execute malicious, persistent code across platforms.
Information security
fromComputerworld
1 week ago

Critical Cisco UC bug actively exploited

Critical RCE vulnerability CVE-2026-20045 affects Cisco Unified Communications products, is actively exploited, and patches have been released; CISA added it to its exploited vulnerabilities catalog.
#cve-2026-20045
fromThe Hacker News
1 week ago

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

The vulnerability, tracked as CVE-2026-1245 (CVSS score: N/A), affects all versions of the module prior to version 2.3.0, which addresses the issue. Patches for the flaw were released on November 26, 2025. Binary-parser is a widely used parser builder for JavaScript that allows developers to parse binary data. It supports a wide range of common data types, including integers, floating-point values, strings, and arrays. The package attracts approximately 13,000 downloads on a weekly basis.
Information security
Information security
fromTheregister
1 week ago

Anthropic quietly fixed flaws in its Git MCP server

Three mcp-server-git vulnerabilities allowed chaining with Filesystem MCP to achieve remote code execution; mcp-server-git prior to 2025.12.18 must be updated.
#cve-2025-37164
fromTechzine Global
1 week ago
Information security

RondoDox botnet exploits HPE OneView vulnerability on a massive scale

RondoDox botnet rapidly escalated automated exploitation of critical, unauthenticated remote code execution vulnerability CVE-2025-37164 in HPE OneView, causing tens of thousands of attack attempts.
fromTechzine Global
1 month ago
Information security

HPE OneView requires patch for vulnerability with highest CVE score

Hewlett Packard Enterprise OneView had a critical unauthenticated remote code execution vulnerability (CVE-2025-37164) fixed in version 11.00 with hotfixes for older releases.
fromThe Hacker News
2 weeks ago

Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways

The vulnerability, tracked as CVE-2025-20393 (CVSS score: 10.0), is a remote command execution flaw arising as a result of insufficient validation of HTTP requests by the Spam Quarantine feature. Successful exploitation of the defect could permit an attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. However, for the attack to work, three conditions must be met - The appliance is running a vulnerable release of Cisco AsyncOS Software The appliance is configured with the Spam Quarantine feature The Spam Quarantine feature is exposed to and reachable from the internet
Information security
#gogs
Information security
fromComputerworld
2 weeks ago

Trend Micro patches critical flaws in its Apex Central software

A vulnerability in Apex Central's management server lets remote attackers cause the server to load and execute a malicious DLL without authentication.
fromThe Hacker News
3 weeks ago

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions

"Trend Micro has released security updates to address multiple security vulnerabilities impacting on-premise versions of Apex Central for Windows, including a critical bug that could result in arbitrary code execution. The vulnerability, tracked as CVE-2025-69258, carries a CVSS score of 9.8 out of a maximum of 10.0. The vulnerability has been described as a case of remote code execution affecting LoadLibraryEX."
Information security
Information security
fromThe Hacker News
3 weeks ago

Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances

Multiple critical command-injection and information-disclosure vulnerabilities in Coolify allow authenticated or low-privileged users to achieve remote code execution, container escape, and root compromise.
#hpe-oneview
fromTechzine Global
3 weeks ago
Information security

HPE OneView flaw now actively exploited, CISA warns

CVE-2025-37164 permits unauthenticated remote code execution in HPE OneView; apply version 11.00 or provided hotfixes immediately and verify networks for compromise.
fromThe Hacker News
1 month ago
Information security

HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution

HPE OneView contains a maximum-severity RCE vulnerability (CVE-2025-37164) fixed in version 11.00; hotfixes are available for earlier releases.
#veeam-backup--replication
Information security
fromThe Hacker News
3 weeks ago

Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers

CVE-2026-0625 permits unauthenticated command injection in D-Link DSL gateway dnscfg.cgi, enabling remote code execution and active exploitation of legacy models.
Information security
fromInfoWorld
3 weeks ago

Open WebUI bug turns the 'free model' into an enterprise backdoor

Open WebUI's storage of long-lived JWTs in localStorage plus Direct Connections execute events enables account takeover and can escalate to remote code execution.
fromThe Hacker News
3 weeks ago

Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers

If a developer uses MultipartFile.move() without the second options argument or without explicitly sanitizing the filename, an attacker can supply a crafted filename value containing traversal sequences, writing to a destination path outside the intended upload directory," the project maintainers said in an advisory released last week. "This can lead to arbitrary file write on the server. However, successful exploitation hinges on a reachable upload endpoint.
Information security
#react2shell
fromInfoWorld
1 month ago
Information security

React2Shell: Anatomy of a max-severity flaw that sent shockwaves through the web

fromInfoWorld
1 month ago
Information security

React2Shell: Anatomy of a max-severity flaw that sent shockwaves through the web

#watchguard
#react-server-components
fromInfoQ
1 month ago
Information security

Patch Urgently - Critical Vulnerability CVE-2025-55182 in React Server Functions Actively Exploited

fromTechzine Global
1 month ago
Information security

Meta warns of critical vulnerability in React Server Components

A critical unauthenticated RCE in React Server Components (CVE-2025-55182) requires immediate updates to patched versions to prevent remote code execution.
fromThe Hacker News
1 month ago
React

Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution

Maximum-severity RSC vulnerability CVE-2025-55182 enables unauthenticated remote code execution; update affected React, RSC plugin, and Next.js packages immediately.
fromInfoQ
1 month ago
Information security

Patch Urgently - Critical Vulnerability CVE-2025-55182 in React Server Functions Actively Exploited

#browser-extensions
fromThe Hacker News
1 month ago

CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks

Details of the six-year-old flaw were publicly shared by Cisco Talos in April 2019, describing it as an exploitable remote code execution vulnerability in the ACEManager "upload.cgi" function of Sierra Wireless AirLink ES450 firmware version 4.9.3. Talos reported the flaw to the Canadian company in December 2018. "This vulnerability exists in the file upload capability of templates within the AirLink 450," the company said. "When uploading template files, you can specify the name of the file that you are uploading."
Information security
fromThe Hacker News
1 month ago

Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution

"Threat actors can potentially abuse this as a way to access the web.config file, opening the door for deserialization and remote code execution," security researcher Bryan Masters said. The use of hard-coded cryptographic keys could allow threat actors to decrypt or forge access tickets, enabling them to access sensitive files like web.config that can be exploited to achieve ViewState deserialization and remote code execution, the cybersecurity company added.
Information security
Information security
fromThe Hacker News
1 month ago

.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL

A .NET Framework SOAP handling flaw (SOAPwn) enables attackers to abuse WSDL-created HTTP client proxies to perform arbitrary file writes and achieve remote code execution.
fromTheregister
1 month ago

Microsoft won't fix .NET RCE bug affecting enterprise apps

Its name and the official documentation both paint a simple picture: it should handle SOAP messages transported over HTTP. Straightforward. Predictable. Safe. Reality is less cooperative.
Information security
Information security
fromComputerWeekly.com
1 month ago

Microsoft patched over 1,100 CVEs in 2025 | Computer Weekly

A Windows Cloud Files Mini Filter Driver use-after-free vulnerability (CVE-2025-62221) is being actively exploited and can enable SYSTEM privilege escalation.
Information security
fromThe Hacker News
1 month ago

Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks

A critical RCE (CVE-2025-6389) in Sneeit Framework WordPress plugin (≤8.3) is actively exploited; update to 8.4 to mitigate.
Information security
fromThe Hacker News
1 month ago

Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks

AI-powered IDEs have chained vulnerabilities that enable prompt injection, abuse of auto-approved tools, and weaponization of legitimate IDE features for data exfiltration and RCE.
Information security
fromComputerWeekly.com
1 month ago

Cloudflare fixes second outage in a month | Computer Weekly

Cloudflare briefly lost Dashboard and API availability due to a WAF parsing change deployed to mitigate a critical React Server Components RCE (React2Shell) vulnerability, now resolved.
Information security
fromTechzine Global
1 month ago

React2Shell exploited hours after discovery

Chinese state-backed groups actively weaponized React2Shell (CVE-2025-55182) within hours, enabling unauthenticated remote code execution against React 19.x and Next.js App Router.
Information security
fromInfoWorld
1 month ago

Developers urged to immediately upgrade React, Next.js

React 19's RSC Flight protocol contains a critical deserialization vulnerability enabling remote code execution; immediate upgrade and patching are required.
#react
Information security
fromThe Hacker News
1 month ago

Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation

Microsoft patched CVE-2025-9491, a Windows .LNK UI misinterpretation vulnerability enabling remote code execution via crafted shortcut files.
fromTechzine Global
1 month ago

OpenAI Codex CLI contained dangerous MCP security gap

This happened via the Model Context Protocol, intended to integrate external tools into the Codex environment. The CLI loaded MCP configurations from a .codex/config.toml file and executed the commands defined therein immediately upon startup. There was no approval prompt, no validation, and no check when the commands changed. MCP itself does not contain extensive built-in security, even after a series of updates.
Information security
Information security
fromThe Hacker News
1 month ago

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware

ShadyPanda operated a seven-year browser extension campaign that amassed over 4.3 million installs and escalated to remote code execution, data exfiltration, and affiliate fraud.
fromThe Hacker News
2 months ago

New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions

Cybersecurity researchers have discovered five vulnerabilities in Fluent Bit, an open-source and lightweight telemetry agent, that could be chained to compromise and take over cloud infrastructures. The security defects "allow attackers to bypass authentication, perform path traversal, achieve remote code execution, cause denial-of-service conditions, and manipulate tags," Oligo Security said in a report shared with The Hacker News. Successful exploitation of the flaws could enable attackers to disrupt cloud services, manipulate data, and burrow deeper into cloud and Kubernetes infrastructure.
Information security
#oracle-identity-manager
Information security
fromTheregister
2 months ago

Weaponized file name flaw allows RCE through glob

A shell-invocation flaw in glob's CLI -c option enables remote code execution on POSIX systems when processing attacker-controlled filenames; update affected glob versions immediately.
Information security
fromSecurityWeek
2 months ago

Imunify360 Vulnerability Could Expose Millions of Sites to Hacking

A critical flaw in Imunify360's Ai-Bolit scanner can allow arbitrary code execution and potential full compromise of shared hosting servers running the scanner.
#zeromq
fromInfoWorld
2 months ago
Information security

Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft

fromInfoWorld
2 months ago
Information security

Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft

#wsus
fromIT Pro
3 months ago
Information security

CISA issues alert after botched Windows Server patch exposes critical flaw

fromIT Pro
3 months ago
Information security

CISA issues alert after botched Windows Server patch exposes critical flaw

fromTechzine Global
2 months ago

Critical vulnerability exposed in JavaScript library expr-eval

A critical security vulnerability in the popular JavaScript library expr-eval allows remote code execution. The bug, with a CVSS score of 9.8, affects hundreds of projects and is forcing developers to migrate to a secure version quickly. The vulnerability, registered as CVE-2025-12735, is listed in the US National Vulnerability Database (NVD) and is considered one of the most serious security issues in recent JavaScript ecosystems.
Information security
Information security
fromBleepingComputer
2 months ago

Popular JavaScript library expr-eval vulnerable to RCE flaw

Critical RCE vulnerability (CVE-2025-12735) in expr-eval/expr-eval-fork allows remote code execution via unvalidated Parser.evaluate() context variables.
#redis
fromInfoQ
2 months ago
Information security

Redis Critical Remote Code Execution Vulnerability Discovered After 13 Years

fromInfoQ
2 months ago
Information security

Redis Critical Remote Code Execution Vulnerability Discovered After 13 Years

Information security
fromInfoWorld
2 months ago

RCE in React Native CLI opens Dev Servers to attacks

The Metro development server exposes an unsafe /open-url endpoint and defaults to listening on 0.0.0.0, allowing remote command execution unless patched.
Information security
fromThe Hacker News
2 months ago

New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands

A CSRF vulnerability in ChatGPT Atlas allows persistent-memory injection that can execute arbitrary code, persist across devices, and compromise accounts and systems.
fromThe Hacker News
2 months ago

Active Exploits Hit Dassault and XWiki - CISA Confirms Critical Flaws Under Attack

Both CVE-2025-6204 and CVE-2025-6205 affect DELMIA Apriso versions from Release 2020 through Release 2025. They were addressed by Dassault Systèmes in early August. According to details shared by ProjectDiscovery researchers Rahul Maini, Harsh Jaiswal, and Parth Malhotra last month, the two security flaws can be fashioned together into an exploit chain to create accounts with elevated privileges and then drop executable files into a web-served directory, resulting in a full application compromise.
Information security
Information security
fromTheregister
3 months ago

Windows Server WSUS bug exploits underway, Microsoft's mum

A critical RCE in Windows Server Update Services (CVE-2025-59287) enables unauthenticated full system takeover and is being actively exploited, prompting emergency patches.
#rust
fromThe Hacker News
3 months ago

Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control

Red Lion's Sixnet RTUs provide advanced automation, control, and data acquisition capabilities in industrial automation and control systems, primarily across energy, water, and wastewater treatment, transportation, utilities, and manufacturing sectors. These industrial devices are configured using a Windows utility called Sixnet IO Tool Kit, with a proprietary Sixnet "Universal" protocol used to interface and enable communication between the kit and the RTUs.
Information security
fromThe Cyber Express
3 months ago

Critical CVE-2025-61927 VM Context Escape In Happy DOM Library

A critical security flaw has been identified in Happy DOM, a widely used JavaScript library primarily employed for server-side rendering and testing frameworks. The vulnerability, cataloged as CVE-2025-61927, allows attackers to escape the library's virtual machine (VM) context, leading to potential remote code execution on vulnerable systems. This flaw threatens millions of applications that depend on Happy DOM. The root of this vulnerability lies in the improper isolation of the Node.js VM context within Happy DOM versions 19 and earlier.
Information security
Information security
fromSecurityWeek
3 months ago

ZDI Drops 13 Unpatched Ivanti Endpoint Manager Vulnerabilities

Multiple high-severity input-validation vulnerabilities in Ivanti Endpoint Manager allow authenticated attackers to achieve remote code execution or local privilege escalation.
Information security
fromThe Hacker News
3 months ago

Severe Figma MCP Vulnerability Lets Hackers Execute Code Remotely - Patch Now

A command injection vulnerability in the figma-developer-mcp MCP server (CVE-2025-53967) permits remote code execution via unsanitized user input.
Information security
fromThe Hacker News
3 months ago

Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks

Graceful Spider (Cl0p) is attributed with exploiting Oracle E-Business Suite CVE-2025-61882 on August 9, 2025, enabling unauthenticated remote code execution.
fromSecurityWeek
3 months ago

Unauthenticated RCE Flaw Patched in DrayTek Routers

DrayTek on Thursday announced patches for an unauthenticated remote code execution (RCE) vulnerability affecting DrayOS routers. Tracked as CVE-2025-10547, the issue can be exploited via crafted HTTP or HTTPS requests sent to a vulnerable device's web user interface. Successful exploitation of the bug, DrayTek explains in its advisory, may result in memory corruption and a system crash. In certain circumstances, it could be used to execute arbitrary code remotely, it says.
Information security
Information security
fromTheregister
4 months ago

Exploits using GoAnywhere perfect-10 bug confirmed

Threat actors exploited Fortra's critical GoAnywhere MFT vulnerability CVE-2025-10035, enabling remote code execution and creation of backdoor accounts on exposed systems.
fromTechzine Global
4 months ago

Critical zero-day affects Cisco IOS and IOS XE

Cisco has disclosed a serious security vulnerability in IOS and IOS XE software that allows both denial of service and remote code execution via the Simple Network Management Protocol, or SNMP for short. This is an actively exploited zero-day vulnerability. It is registered as CVE-2025-20352. The vulnerability has a CVSS score of 7.7. The vulnerability is caused by a stack overflow in the SNMP subsystem.
Information security
[ Load more ]