Tag: remote code execution

Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.

Critical WordPress Vulnerabilities Trigger Widespread Scanning And Remote Code Execution Attacks

Security researchers are warning of widespread exploitation of two critical WordPress vulnerabilities that allow unauthenticated remote code execution and complete website compromise.

CISA Adds Exploited Microsoft SharePoint CVE 2026 58644 Zero Day To Known Exploited Vulnerabilities Catalog

CISA has added the actively exploited Microsoft SharePoint vulnerability CVE 2026 58644 to its Known Exploited Vulnerabilities catalog and urged organizations to apply security updates immediately.

Six Proto6 Vulnerabilities In Protobuf.js Put Node.js Applications At Risk Of RCE And DoS Attacks

Cybersecurity researchers have identified six vulnerabilities in protobuf.js that could expose Node.js applications to remote code execution and denial of service attacks, impacting cloud services, AI systems, and CI/CD pipelines.

Microsoft Fixes Record 206 Security Flaws Including Zero Day Vulnerabilities And Critical RCE Risks

Microsoft has released patches for a record 206 security vulnerabilities, including three publicly disclosed zero day flaws and several critical remote code execution risks affecting Windows systems.

Microsoft Releases Security Updates For SharePoint RCE Flaw CVE 2026 45659 Across Server Versions

Microsoft has patched SharePoint remote code execution vulnerability CVE 2026 45659 affecting multiple server versions, allowing authenticated attackers to execute code remotely.

18 Year Old NGINX Rewrite Module Flaw Enables Unauthenticated Remote Code Execution

Cybersecurity researchers disclose a critical 18 year old NGINX vulnerability, CVE-2026-42945, enabling unauthenticated remote code execution through crafted HTTP requests.

PAN OS CVE-2026-0300 Exploited In Active Attacks Enables Root Level Remote Code Execution

Palo Alto Networks reports active exploitation of PAN OS CVE-2026-0300 allowing root level RCE, with espionage activity linked to suspected state sponsored threat cluster CL STA 1132.

Ivanti EPMM CVE-2026-6973 Exploited In Limited Attacks Enables Admin Level Remote Code Execution

Ivanti warns of CVE-2026-6973 in EPMM being actively exploited in limited attacks, enabling admin authenticated remote code execution, alongside multiple patched vulnerabilities.

Weaver E-cology Critical RCE Vulnerability CVE 2026 22679 Actively Exploited Via Debug API Endpoint

A critical Weaver E-cology vulnerability CVE 2026 22679 is being actively exploited, enabling unauthenticated remote code execution through debug API endpoints affecting enterprise systems globally.

Marimo RCE Vulnerability CVE 2026 39987 Exploited Within Hours After Public Disclosure

A critical Marimo RCE flaw CVE-2026-39987 was exploited within hours of disclosure, enabling unauthenticated shell access and rapid credential theft activity.

Adobe Reader Zero Day Exploited Through Malicious PDF Files Since December 2025

A zero day vulnerability in Adobe Reader has been actively exploited via malicious PDF files since December 2025, enabling data theft, payload delivery, and potential remote execution.

Flowise AI Agent Builder Faces Active CVSS 10.0 Remote Code Execution Exploitation With 12,000 Instances Exposed

Flowise AI platform suffers a critical CVSS 10.0 code injection vulnerability, exposing over 12,000 instances to remote code execution and full system compromise.

Recent articles

spot_img