Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
162 articles

#RCE

All CosmicBytez Labs articles tagged #RCE, across news, security advisories, how-to guides, and projects.

  • NewsJun 2, 2026

    Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

    A stack-based buffer overflow flaw in HP OfficeConnect VoIP phones can be exploited remotely to achieve code execution, potentially allowing attackers to pivot into enterprise networks from compromised desk phones.

  • SecurityJun 2, 2026

    CVE-2018-25427: Arm Whois 3.11 Stack-Based Buffer Overflow RCE

    A critical stack-based buffer overflow vulnerability in Arm Whois 3.11 (CVSS 9.8) allows remote attackers to execute arbitrary code by supplying oversized input, overwriting the structured exception handler with shellcode.

  • NewsJun 1, 2026

    Critical Windows Netlogon RCE Flaw Now Exploited in Attacks

    Belgium's national cybersecurity authority (CCB) has issued an urgent warning that threat actors are actively exploiting a recently patched critical Windows Netlogon Remote Protocol vulnerability that allows unauthenticated remote code execution on domain controllers.

  • SecurityJun 1, 2026

    CVE-2024-21182: Oracle WebLogic Server Unspecified Vulnerability

    Oracle WebLogic Server contains an unspecified vulnerability allowing unauthenticated attackers network access via T3 and IIOP protocols, potentially exposing all server data. CISA added this to its KEV catalog on June 1, 2026.

  • NewsMay 30, 2026

    Chrome 148 Update Patches 151 Vulnerabilities Including Critical RCE Flaws

    Google has released Chrome 148 with patches for 151 security vulnerabilities, including critical-severity flaws that could allow remote code execution....

  • SecurityMay 30, 2026

    CVE-2026-10042: manga-image-translator RCE via Unsafe Python Deserialization

    A critical CVSS 9.8 remote code execution vulnerability in manga-image-translator allows unauthenticated attackers to execute arbitrary commands by...

  • SecurityMay 30, 2026

    CVE-2026-7465: RCE in Spectra Gutenberg Blocks WordPress Plugin (CVSS 8.8)

    A high-severity remote code execution vulnerability in the Spectra Gutenberg Blocks plugin for WordPress allows authenticated Contributor-level attackers...

  • SecurityMay 30, 2026

    CVE-2026-9558: Critical SSTI in Mautic Enables Authenticated RCE

    A Server-Side Template Injection flaw in Mautic's Twig-based theme engine allows authenticated users with theme upload permissions to execute arbitrary...

  • SecurityMay 29, 2026

    CVE-2026-4408: Samba OS Command Injection via Check Password Script

    A CVSS 9.0 OS command injection flaw in Samba allows remote attackers to execute arbitrary commands on file servers and domain controllers using the %u...

  • SecurityMay 28, 2026

    CVE-2025-12686: Synology BeeStation OS Critical Buffer Overflow RCE

    Buffer overflow in Synology BeeStation OS AdminCenter lets unauthenticated attackers execute code remotely (CVSS 9.8) — patch to 1.3.2-65648 now.

  • SecurityMay 28, 2026

    CVE-2026-45083 — Goobi Viewer Unauthenticated RCE via Solr Streaming Expression Injection

    CVSS 9.8 in Goobi Viewer REST API lets unauthenticated clients inject Solr streaming expressions, enabling RCE on affected digital heritage platforms.

  • SecurityMay 27, 2026

    CVE-2026-44444: Lumiverse AI Plugin Install Scripts Enable RCE (CVSS 9.1)

    Critical Lumiverse <0.9.7 flaw lets malicious extensions execute arbitrary code via package.json lifecycle scripts run by the Spindle build pipeline.

  • SecurityMay 27, 2026

    CVE-2026-45247 — Mirasvit Magento 2 Cache Warmer PHP Object Injection RCE

    CVSS 9.8 PHP object injection in Mirasvit Full Page Cache Warmer for Magento 2 lets unauthenticated attackers achieve RCE — patch to 1.11.12 now.

  • SecurityMay 27, 2026

    CVE-2026-8450: HTTP::Daemon Perl OS Command Injection via send_file()

    OS command injection (CVSS 9.1) in Perl's HTTP::Daemon lets attackers run arbitrary commands via magic prefix abuse in send_file's two-arg open().

  • NewsMay 26, 2026

    Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell

    A hardcoded machineKey value in KnowledgeDeliver's configuration enabled ViewState deserialization attacks leading to remote code execution and web shell.

  • NewsMay 26, 2026

    KnowledgeDeliver Flaw Exploited as Zero-Day to Install Web

    Attackers exploited a critical zero-day vulnerability in KnowledgeDeliver LMS servers to deploy the Godzilla web shell, giving persistent backdoor access to.

  • NewsMay 26, 2026

    Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across

    Microsoft has released updates fixing CVE-2026-45659, a CVSS 8.8 remote code execution vulnerability in SharePoint Server that requires no specialized.

  • NewsletterMay 26, 2026

    May 26 Digest: SharePoint RCE, Megalodon CI/CD Blitz

    Microsoft patches a CVSS 8.8 SharePoint RCE; the Megalodon campaign poisons 5,561 GitHub repos in six hours; 7-Eleven's ShinyHunters breach hits 185,000; and a.

  • SecurityMay 22, 2026

    CVE-2026-34910 — UniFi OS Unauthenticated Command Injection

    A CVSS 10.0 command injection vulnerability in UniFi OS allows any network-accessible attacker with no credentials to execute arbitrary OS commands,...

  • SecurityMay 22, 2026

    CVE-2026-48207: Apache Fury PyFury Deserialization RCE

    A critical deserialization vulnerability in Apache Fury's Python library PyFury allows attackers to bypass DeserializationPolicy validation hooks via the...

  • SecurityMay 22, 2026

    CVE-2026-5433: Honeywell CNM Critical Command Injection RCE

    A CVSS 9.1 critical command injection vulnerability in Honeywell's Control Network Module web interface allows remote attackers to execute arbitrary...

  • NewsMay 21, 2026

    Google Accidentally Exposed Details of Unfixed Chromium Flaw

    Google accidentally leaked information about an unpatched Chromium vulnerability that allows JavaScript to continue running in the background even after...

  • NewsMay 21, 2026

    Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites

    Drupal has released emergency security updates for CVE-2026-9082, a highly critical vulnerability in Drupal Core that allows remote code execution,...

  • SecurityMay 21, 2026

    CVE-2026-33278 — NLnet Labs Unbound DNSSEC Validator RCE

    A critical heap-corruption flaw in NLnet Labs Unbound's DNSSEC validator allows denial of service and possible remote code execution. Affects versions...

  • SecurityMay 21, 2026

    CVE-2026-44050 — Netatalk CNID Daemon Heap Buffer Overflow

    A heap-based buffer overflow in the Netatalk CNID daemon comm_rcv() function allows a remote authenticated attacker to execute arbitrary code with...

  • SecurityMay 20, 2026

    CVE-2026-24207: NVIDIA Triton Inference Server Auth Bypass

    A critical authentication bypass vulnerability in NVIDIA Triton Inference Server could allow unauthenticated attackers to execute code, escalate...

  • SecurityMay 20, 2026

    GlassFish Administration Console Authenticated RCE

    An authenticated Remote Code Execution vulnerability in GlassFish's Administration Console (CVSS 9.1) allows users with panel access to execute arbitrary...

  • SecurityMay 20, 2026

    GlassFish Gadget Handler Expression Language RCE

    A critical CVSS 9.6 Remote Code Execution vulnerability in GlassFish's server-side gadget handler allows attackers to inject Expression Language...

  • SecurityMay 20, 2026

    CVE-2026-34234 — CtrlPanel Installer Unauthenticated Remote

    A CVSS 10.0 RCE vulnerability in CtrlPanel's web-based installer allows unauthenticated attackers to execute arbitrary code by exploiting a logic flaw...

  • NewsMay 19, 2026

    SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE

    Critical security vulnerabilities in SEPPMail Secure E-Mail Gateway — an enterprise email security appliance — could allow attackers to achieve remote...

  • SecurityMay 19, 2026

    CVE-2026-25244 — WebdriverIO Command Injection RCE via Git

    A command injection vulnerability in WebdriverIO below version 9.24.0 allows remote code execution through malicious git branch names containing shell...

  • SecurityMay 19, 2026

    CVE-2026-27130 — Dokploy OS Command Injection via appName

    Dokploy versions 0.26.6 and below contain a critical OS command injection vulnerability in the appName parameter, enabling unauthenticated remote code...

  • SecurityMay 19, 2026

    CVE-2026-7301: SGLang ROUTER Socket Exposes Unsafe

    A critical CVSS 9.8 vulnerability in SGLang's multimodal AI runtime scheduler binds its ROUTER socket to 0.0.0.0 by default and passes incoming messages...

  • SecurityMay 19, 2026

    CVE-2026-8838 — Amazon Redshift Python Driver RCE via

    The Amazon Redshift Python driver before version 2.1.14 contains a critical vulnerability where the vector_in() function executes arbitrary code received...

  • SecurityMay 18, 2026

    CVE-2018-25320: ACL Analytics Arbitrary Code Execution via

    ACL Analytics versions 11.x through 13.0.0.579 contain a critical arbitrary code execution vulnerability (CVSS 9.8) allowing attackers to run arbitrary OS...

  • SecurityMay 18, 2026

    CVE-2026-8507: Crypt::OpenSSL::PKCS12 Heap OOB Write — CVSS

    A critical heap out-of-bounds write vulnerability in Crypt::OpenSSL::PKCS12 for Perl (versions through 1.94) can be triggered by parsing a malformed...

  • SecurityMay 16, 2026

    CVE-2026-41258: OpenMRS Velocity Template Injection Enables

    A critical unsandboxed Apache Velocity template injection vulnerability in OpenMRS Core allows authenticated attackers to execute arbitrary code on the...

  • NewsMay 14, 2026

    18-Year-Old NGINX Rewrite Module Flaw Enables

    Researchers have disclosed multiple critical vulnerabilities in NGINX Plus and NGINX Open Source, including a heap buffer overflow in...

  • NewsMay 14, 2026

    18-Year-Old NGINX Vulnerability Allows DoS and Potential RCE

    An autonomous scanning system has uncovered an 18-year-old flaw in the NGINX open-source web server that can be exploited for denial of service and, under...

  • SecurityMay 14, 2026

    CVE-2026-44377: CubeCart Authenticated SSTI via Smarty

    An authenticated Server-Side Template Injection vulnerability in CubeCart prior to 6.7.0 allows attackers with API key access to execute arbitrary code...

  • SecurityMay 14, 2026

    CVE-2026-45053: CubeCart REST API Arbitrary PHP File Upload

    A critical arbitrary file upload vulnerability in CubeCart's REST API File Manager allows holders of a files:rw API key to upload PHP webshells to the web...

  • NewsMay 13, 2026

    Microsoft May 2026 Patch Tuesday Fixes 120 Flaws, No

    Microsoft's May 2026 Patch Tuesday delivers security updates for 120 vulnerabilities across Windows, Edge, Office, Azure, and more — with no zero-days...

  • NewsMay 13, 2026

    Microsoft Patches 138 Vulnerabilities Including DNS and

    Microsoft's May 2026 Patch Tuesday addresses 138 security vulnerabilities across its product portfolio, including 30 rated Critical — with notable DNS...

  • NewsMay 13, 2026

    New Critical Exim Mailer Flaw Allows Remote Code Execution

    A critical vulnerability in certain configurations of the Exim open-source mail transfer agent allows unauthenticated remote attackers to execute...

  • NewsMay 13, 2026

    New Exim BDAT Vulnerability Exposes GnuTLS Builds to

    Exim has released security updates to patch a severe vulnerability affecting GnuTLS-compiled builds of the world's most widely deployed mail transfer...

  • NewsMay 12, 2026

    Fortinet Warns of Critical RCE Flaws in FortiSandbox and

    Fortinet has released emergency security patches for two critical vulnerabilities in FortiSandbox and FortiAuthenticator that could enable attackers to...

  • SecurityMay 12, 2026

    CVE-2026-34263 — SAP Commerce Cloud Unauthenticated RCE

    A critical unauthenticated remote code execution vulnerability in SAP Commerce Cloud allows any unauthenticated user to upload malicious configurations...

  • NewsMay 10, 2026

    Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation

    Ivanti has disclosed a high-severity improper input validation vulnerability in Endpoint Manager Mobile (EPMM) that is being actively exploited in the...

  • NewsMay 10, 2026

    PAN-OS RCE Exploit Under Active Use Enabling Root Access

    Palo Alto Networks has disclosed that CVE-2026-0300, a critical CVSS 9.3 buffer overflow in the PAN-OS User-ID Authentication service, is being actively...

  • SecurityMay 8, 2026

    CVE-2026-41500: electerm macOS Command Injection via

    A critical command injection vulnerability in the electerm terminal client allows remote attackers to achieve unauthenticated code execution on macOS...

  • SecurityMay 8, 2026

    CVE-2026-41501: electerm Linux Command Injection via

    A critical command injection flaw in electerm's Linux installer allows remote attackers to execute arbitrary shell commands by injecting into unsanitized...

  • NewsMay 1, 2026

    EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

    Claroty researchers have disclosed two vulnerabilities in the EnOcean SmartServer IQ building management controller that can be chained for security...

  • SecurityMay 1, 2026

    Apache MINA Incomplete Deserialization Patch Leaves 2.1.X

    Apache MINA versions 2.1.X and 2.2.X remain vulnerable to unauthenticated remote code execution because the fix for CVE-2026-41409 was never backported,...

  • SecurityMay 1, 2026

    Critical Stack-Based Buffer Overflow in Totolink NR1800X

    A critical CVSS 9.8 stack-based buffer overflow in the Totolink NR1800X router's lighttpd component allows unauthenticated remote code execution via a...

  • NewsApr 30, 2026

    Critical Gemini CLI Flaw Enabled Host Code Execution

    A critical vulnerability in Google's Gemini CLI allowed an attacker to plant a malicious configuration file that executed commands outside the sandbox,...

  • SecurityApr 30, 2026

    CVE-2026-36841: TOTOLINK N200RE V5 Command Injection

    A critical CVSS 9.8 command injection vulnerability in TOTOLINK N200RE V5 allows unauthenticated remote code execution via the macstr and bandstr...

  • NewsApr 29, 2026

    Critical GitHub Vulnerability Exposed Millions of

    A critical remote code execution vulnerability, CVE-2026-3854, was found to impact GitHub.com and GitHub Enterprise Server, potentially exposing millions...

  • NewsApr 29, 2026

    GitHub Fixes RCE Flaw That Gave Access to Millions of

    GitHub has patched CVE-2026-3854, a critical remote code execution vulnerability exploitable via a single HTTP request that could have granted attackers...

  • NewsApr 29, 2026

    Hackers Exploit RCE Flaws in Qinglong Task Scheduler for

    Threat actors are actively exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptomining...

  • SecurityApr 29, 2026

    CVE-2024-1708: ConnectWise ScreenConnect Path Traversal

    ConnectWise ScreenConnect contains a path traversal vulnerability (CVE-2024-1708) that allows attackers to execute remote code or directly access...

  • SecurityApr 29, 2026

    Snap One WattBox 800/820 Diagnostic Auth Bypass

    A CVSS 9.8 critical vulnerability in Snap One WattBox 800 and 820 series firmware exposes undisclosed diagnostic HTTP endpoints protected only by the...

  • NewsApr 28, 2026

    Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to

    Cybersecurity researchers have disclosed CVE-2026-25874, a critical unauthenticated remote code execution vulnerability (CVSS 9.3) in Hugging Face's...

  • NewsApr 28, 2026

    Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw

    Cybersecurity researchers have disclosed a critical remote code execution vulnerability in GitHub.com and GitHub Enterprise Server that allows an...

  • SecurityApr 28, 2026

    CVE-2026-30352: Remote Code Execution in leonvanzyl

    A critical remote code execution vulnerability in the /devserver/start endpoint of the leonvanzyl autocoder AI coding tool allows unauthenticated...

  • SecurityApr 28, 2026

    CVE-2026-40453: Apache Camel Header Filter Case-Variant

    A critical incomplete fix in Apache Camel leaves five non-HTTP HeaderFilterStrategy implementations vulnerable to case-variant header injection, allowing...

  • SecurityApr 28, 2026

    CVE-2026-40860: Apache Camel JMS Unsafe ObjectMessage

    Apache Camel's JmsBinding class in camel-jms and camel-sjms deserializes incoming JMS ObjectMessage payloads via javax.jms.ObjectMessage.getObject()...

  • SecurityApr 28, 2026

    CVE-2026-41635: Apache MINA Class Allowlist Bypass Enables

    Apache MINA's AbstractIoBuffer.resolveClass() contains a branch for static classes and primitive types that skips allowlist validation entirely, letting...

  • SecurityApr 28, 2026

    CVE-2026-7136: Totolink A8000RU OS Command Injection via

    A critical OS command injection vulnerability in the Totolink A8000RU router allows remote attackers to execute arbitrary commands by manipulating the...

  • SecurityApr 28, 2026

    CVE-2026-7154: Totolink A8000RU OS Command Injection via

    A critical unauthenticated OS command injection vulnerability in the Totolink A8000RU router firmware 7.1cu.643_b20200521 allows remote attackers to...

  • NewsletterApr 28, 2026

    Apr 28 Digest: Medtronic 9M Breach, GitHub RCE, LiteLLM

    ShinyHunters hits Medtronic and ADT in the same week, exposing millions of records; a critical one-push RCE lands in GitHub; LiteLLM's pre-auth SQL...

  • SecurityApr 27, 2026

    CVE-2026-6786: Memory Safety Bugs in Firefox and Thunderbird

    Multiple memory safety bugs in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9 carry a CVSS 8.1 High rating. Some bugs show...

  • SecurityApr 25, 2026

    CVE-2026-6951: simple-git RCE via --config Option Bypass

    A critical remote code execution vulnerability in the simple-git npm package allows attackers to inject arbitrary git config options via the --config...

  • SecurityApr 24, 2026

    Pipecat AI Framework RCE via LivekitFrameSerializer

    A critical vulnerability in Pipecat's optional LivekitFrameSerializer class allows unauthenticated remote code execution in the popular AI voice agent...

  • SecurityApr 24, 2026

    Kofax Capture Unauthenticated RCE via Exposed .NET Remoting

    A critical unauthenticated RCE vulnerability in Kofax Capture (Tungsten Capture) exposes a deprecated .NET Remoting HTTP channel on port 2424 with no...

  • SecurityApr 24, 2026

    CVE-2026-26210: KTransformers Unsafe Deserialization RCE

    KTransformers through version 0.5.3 contains a critical unsafe deserialization vulnerability in its balance_serve backend mode, where an unauthenticated...

  • SecurityApr 24, 2026

    CVE-2026-6942: radare2-mcp OS Command Injection via Shell

    A critical OS command injection vulnerability in radare2-mcp 1.6.0 and earlier allows remote attackers to execute arbitrary commands by bypassing the...

  • SecurityApr 23, 2026

    CVE-2026-39987: Marimo Pre-Auth Remote Code Execution

    A critical pre-authorization remote code execution vulnerability in Marimo, the open-source reactive Python notebook, allows unauthenticated attackers to...

  • SecurityApr 23, 2026

    CVE-2026-41228 — Froxlor Path Traversal via def_language

    A critical path traversal vulnerability in Froxlor's Customers.update and Admins.update API endpoints allows authenticated low-privilege users to traverse...

  • SecurityApr 23, 2026

    CVE-2026-41229 — Froxlor PHP Code Injection via MySQL

    A critical PHP code injection vulnerability in Froxlor allows an admin with change_serversettings permission to inject arbitrary PHP code via unescaped...

  • NewsApr 22, 2026

    New Mirai Campaign Exploits RCE Flaw in End-of-Life D-Link

    A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability in end-of-life D-Link DIR-823X...

  • SecurityApr 22, 2026

    CVE-2017-20230: Perl Storable Stack Overflow — CVSS 10.0

    A stack overflow vulnerability in Perl's Storable module (versions before 3.05) stems from a signed/unsigned integer mismatch in retrieve_hook(), enabling...

  • SecurityApr 22, 2026

    CVE-2026-6748: Critical Uninitialized Memory Flaw in

    A critical CVSS 9.8 uninitialized memory vulnerability in Firefox and Thunderbird's Audio/Video Web Codecs component allows remote code execution. Update...

  • SecurityApr 21, 2026

    CVE-2026-32604: Spinnaker Clouddriver Remote Code Execution

    A critical unauthenticated RCE vulnerability in Spinnaker's clouddriver service allows attackers to execute arbitrary commands on clouddriver pods,...

  • SecurityApr 21, 2026

    CVE-2026-32613: Spinnaker Echo Spring Expression Language

    A critical code injection flaw in Spinnaker's Echo service allows unrestricted Spring Expression Language (SPeL) execution via artifact processing,...

  • SecurityApr 21, 2026

    CVE-2026-39918: Vvveb CMS Unauthenticated PHP Code

    Vvveb CMS versions prior to 1.0.8.1 allow unauthenticated attackers to inject arbitrary PHP code through the installation endpoint's unsanitized subdir...

  • NewsApr 20, 2026

    SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious

    A critical CVSS 9.8 command injection vulnerability in the SGLang AI inference framework allows attackers to achieve remote code execution by supplying a...

  • SecurityApr 20, 2026

    CVE-2026-32956: Critical Heap Buffer Overflow in silex

    silex technology SD-330AC and AMC Manager contain a CVSS 9.8 heap-based buffer overflow in redirect URL processing. Unauthenticated attackers can execute...

  • NewsApr 19, 2026

    Adobe Patches Actively Exploited Zero-Day That Lingered for

    Adobe has patched an actively exploited zero-day in Acrobat and Reader that threat actors have been weaponizing via malicious PDF files since at least...

  • NewsApr 18, 2026

    Critical Flaw in protobuf.js Library Enables JavaScript

    A critical remote code execution vulnerability in protobuf.js, the widely used JavaScript implementation of Google's Protocol Buffers, has been disclosed...

  • NewsApr 18, 2026

    Recent Apache ActiveMQ Vulnerability Exploited in the Wild

    CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ's Jolokia management API, is being actively exploited in the wild. CISA has added...

  • NewsApr 11, 2026

    Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

    Multiple vulnerabilities in the widely-used Orthanc open-source DICOM server expose medical imaging systems to denial-of-service, information disclosure,...

  • SecurityApr 11, 2026

    CVE-2026-34621: Adobe Acrobat Reader Prototype Pollution

    Adobe Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by a critical prototype pollution vulnerability (CWE-1321) that can lead...

  • SecurityApr 11, 2026

    CVE-2026-6057: FalkorDB Browser Unauthenticated Path

    FalkorDB Browser 1.9.3 contains a critical unauthenticated path traversal vulnerability in its file upload API that allows remote attackers to write...

  • NewsApr 8, 2026

    13-Year-Old Bug in ActiveMQ Lets Hackers Remotely Execute

    Security researchers discovered a remote code execution vulnerability in Apache ActiveMQ Classic that went undetected for 13 years, allowing attackers to...

  • SecurityApr 8, 2026

    CVE-2026-1340: Ivanti EPMM Code Injection Vulnerability

    Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the Android File Transfer module allowing unauthenticated remote code...

  • SecurityApr 8, 2026

    CVE-2026-20889: LibRaw x3f_thumb_loader Heap Buffer

    A critical heap-based buffer overflow in LibRaw's x3f_thumb_loader allows an attacker to trigger memory corruption via a specially crafted RAW image file,...

  • SecurityApr 8, 2026

    CVE-2026-20911: LibRaw HuffTable::initval Heap Buffer

    A critical heap-based buffer overflow in LibRaw's HuffTable::initval function allows an attacker to corrupt heap memory via a malicious RAW image file,...

  • SecurityApr 8, 2026

    CVE-2026-21413: LibRaw lossless_jpeg_load_raw Heap Buffer

    A critical heap-based buffer overflow in LibRaw's lossless_jpeg_load_raw function allows an attacker to cause memory corruption and potential code...

  • NewsApr 7, 2026

    Hackers Exploit Critical Flaw in Ninja Forms WordPress

    Attackers are actively exploiting a critical unauthenticated arbitrary file upload vulnerability in the Ninja Forms File Uploads premium add-on for...

  • SecurityApr 7, 2026

    CVE-2026-26026: GLPI Template Injection Enables

    GLPI versions 11.0.0 through 11.0.5 contain a server-side template injection vulnerability in the administrator interface that allows authenticated admins...

  • SecurityApr 4, 2026

    CVE-2017-20237: Hirschmann HiVision Auth Bypass Enables

    A critical authentication bypass in Hirschmann Industrial HiVision versions prior to 06.0.07 and 07.0.03 allows unauthenticated remote attackers to...

  • NewsApr 2, 2026

    New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE

    Two newly disclosed vulnerabilities in Progress ShareFile can be chained together to enable unauthenticated remote code execution and file exfiltration,...

  • NewsApr 2, 2026

    Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE

    Internet security watchdog Shadowserver has found over 14,000 BIG-IP APM instances exposed online amid ongoing attacks exploiting a critical-severity...

  • SecurityApr 2, 2026

    CVE-2026-31027: TOTOlink A3600R Buffer Overflow in

    A critical CVSS 9.8 buffer overflow in TOTOlink A3600R v5.9c.4959 allows remote attackers to exploit the rootSsid parameter in the setAppEasyWizardConfig...

  • NewsMar 31, 2026

    Claude AI Finds Vim and Emacs RCE Bugs That Trigger on File

    Anthropic's Claude AI assistant discovered remote code execution vulnerabilities in both Vim and GNU Emacs text editors using simple security research...

  • NewsMar 31, 2026

    F5 BIG-IP Vulnerability Reclassified from DoS to RCE Under

    CVE-2025-53521, initially disclosed as a high-severity denial-of-service flaw in F5 BIG-IP APM, has been reclassified as a remote code execution...

  • NewsMar 30, 2026

    Hackers Now Exploit Critical F5 BIG-IP Flaw in Attacks

    F5 has reclassified a BIG-IP APM vulnerability from denial-of-service to critical remote code execution, warning that attackers are actively exploiting...

  • SecurityMar 30, 2026

    CVE-2025-15379: MLflow Command Injection in Model Serving

    A maximum-severity command injection vulnerability in MLflow's model serving container initialization allows attackers to execute arbitrary OS commands...

  • SecurityMar 28, 2026

    CVE-2026-27876 — Grafana Critical RCE via SQL Expression

    A chained attack exploiting SQL Expressions combined with a Grafana Enterprise plugin can lead to remote arbitrary code execution. All Grafana users...

  • SecurityMar 27, 2026

    CVE-2025-53521: F5 BIG-IP APM Remote Code Execution — CISA

    A critical unauthenticated RCE vulnerability in F5 BIG-IP APM is being actively exploited in the wild. Malicious traffic targeting access policy virtual...

  • NewsMar 26, 2026

    PolyShell Attacks Target 56% of All Vulnerable Magento

    Mass exploitation is underway against Magento 2 and Adobe Commerce installations using the 'PolyShell' polyglot file upload vulnerability, with attackers...

  • NewsMar 25, 2026

    PTC Warns of Imminent Threat from Critical Windchill

    PTC is warning customers of an imminent exploit threat against a critical deserialization vulnerability in Windchill and FlexPLM — CVE-2026-4681, CVSS...

  • SecurityMar 24, 2026

    CVE-2026-33478: AVideo CloneSite Plugin Unauthenticated RCE

    A critical chain of vulnerabilities in WWBN AVideo's CloneSite plugin allows fully unauthenticated attackers to achieve remote code execution via key...

  • SecurityMar 23, 2026

    Tenda A15 UploadCfg Stack Buffer Overflow (CVE-2026-4567)

    A CVSS 9.8 Critical stack-based buffer overflow in Tenda A15 firmware 15.13.07.13 allows unauthenticated remote attackers to execute arbitrary code by...

  • SecurityMar 22, 2026

    D-Link DHP-1320 SOAP Handler Stack Buffer Overflow

    A CVSS 8.8 stack-based buffer overflow in D-Link DHP-1320 firmware 1.00WWB04 allows unauthenticated remote attackers to execute arbitrary code via a...

  • SecurityMar 21, 2026

    CVE-2025-54068: Laravel Livewire Code Injection

    A critical code injection vulnerability in Laravel Livewire v3 allows unauthenticated remote attackers to execute arbitrary commands. Over 130,000...

  • NewsMar 20, 2026

    Oracle Pushes Emergency Fix for Critical Identity Manager

    Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Oracle Identity Manager and...

  • SecurityMar 20, 2026

    CVE-2025-32432: Craft CMS Code Injection Vulnerability

    A critical code injection vulnerability in Craft CMS allows unauthenticated remote attackers to execute arbitrary code on affected servers. Added to...

  • SecurityMar 20, 2026

    CVE-2026-21992: Critical Oracle Identity Manager

    Oracle's March 2026 Critical Patch Update includes CVE-2026-21992, a CVSS 9.8 unauthenticated remote code execution vulnerability in Oracle Identity...

  • SecurityMar 20, 2026

    CVE-2026-32238: Critical Command Injection in OpenEMR

    OpenEMR versions prior to 8.0.0.2 contain a CVSS 9.1 command injection vulnerability in the backup functionality. Authenticated attackers with high...

  • SecurityMar 19, 2026

    CVE-2026-25449: Critical Object Injection in Shinetheme

    A CVSS 9.8 deserialization vulnerability in the Shinetheme Traveler WordPress plugin allows unauthenticated remote attackers to inject arbitrary PHP...

  • NewsMar 18, 2026

    Critical Unpatched GNU Telnetd Flaw (CVE-2026-32746)

    Researchers have disclosed a critical unauthenticated remote code execution vulnerability in the GNU InetUtils telnet daemon (telnetd). CVE-2026-32746...

  • SecurityMar 18, 2026

    CVE-2026-21994: Critical Unauthenticated RCE in Oracle Edge

    A critical unauthenticated remote code execution vulnerability (CVSS 9.8) in Oracle's Edge Cloud Infrastructure Designer and Visualisation Toolkit allows...

  • SecurityMar 18, 2026

    CVE-2026-25769: Wazuh Critical RCE via Insecure

    A critical remote code execution vulnerability (CVSS 9.1) in Wazuh versions 4.0.0–4.14.2 allows an attacker with access to a worker node to achieve root...

  • NewsMar 17, 2026

    AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable

    Security researchers disclosed critical flaws across three major AI platforms: Amazon Bedrock AgentCore's sandbox can be bypassed via DNS to exfiltrate...

  • NewsMar 16, 2026

    CISA Adds Wing FTP Server Flaw to KEV as RCE Chain Exploits

    CISA added CVE-2025-47813 to its Known Exploited Vulnerabilities catalog on March 16, warning that the medium-severity path disclosure flaw is being...

  • NewsMar 14, 2026

    Microsoft Releases Windows 11 OOB Hotpatch to Fix Three

    Microsoft has pushed an out-of-band hotpatch (KB5084597) to Windows 11 Enterprise devices to address three integer-overflow RCE flaws in RRAS, one rated...

  • NewsMar 14, 2026

    OpenClaw AI Agent Flaws Enable Prompt Injection, 1-Click

    China's CNCERT has warned that OpenClaw (formerly Clawdbot/Moltbot), the viral self-hosted AI agent, carries over 250 disclosed vulnerabilities including...

  • NewsMar 13, 2026

    Veeam Patches Five Critical RCE Vulnerabilities Exposing

    Veeam Software has released a critical security update for Backup & Replication, patching five remote code execution vulnerabilities with CVSS scores...

  • SecurityMar 13, 2026

    Veeam Backup & Replication Auth RCE — CVE-2026-21666

    A critical remote code execution vulnerability in Veeam Backup & Replication allows any authenticated domain user to execute arbitrary code on the Backup...

  • SecurityMar 13, 2026

    Veeam Backup & Replication 2nd Auth RCE — CVE-2026-21667

    A second critical remote code execution vulnerability in Veeam Backup & Replication lets any authenticated domain user execute code on the Backup Server,...

  • SecurityMar 13, 2026

    Critical RCE in Veeam Backup & Replication — Third Domain

    A third concurrent critical RCE vulnerability in Veeam Backup & Replication enables domain-authenticated attackers to execute code on the Backup Server,...

  • SecurityMar 13, 2026

    Critical RCE in Veeam Backup & Replication HA Deployments

    A critical RCE vulnerability in Veeam Backup & Replication high-availability deployments allows users with the Backup Administrator role to execute...

  • SecurityMar 13, 2026

    Critical RCE in Veeam Backup & Replication — Backup Viewer

    A critical CVSS 9.9 vulnerability in Veeam Backup & Replication allows users with the lowest-privileged Backup Viewer role to execute arbitrary code as...

  • NewsMar 12, 2026

    CISA Flags Actively Exploited n8n RCE Bug as 24,700

    CISA added CVE-2025-68613 — a CVSS 9.9 remote code execution flaw in n8n's workflow expression evaluator — to its Known Exploited Vulnerabilities catalog...

  • NewsMar 12, 2026

    CISA Orders Federal Agencies to Patch n8n RCE Flaw

    CISA mandated all federal civilian agencies patch CVE-2025-68613, a CVSS 9.9 remote code execution flaw in the n8n workflow automation platform, after...

  • NewsMar 12, 2026

    Researchers Disclose Critical n8n Flaws Enabling RCE and

    Security researchers have published details of two newly patched critical vulnerabilities in n8n — CVE-2026-27577 (CVSS 9.4), an expression sandbox escape...

  • SecurityMar 12, 2026

    CVE-2025-68613: n8n Remote Code Execution via Improper

    CISA adds CVE-2025-68613 to the Known Exploited Vulnerabilities catalog — a CVSS 9.9 flaw in n8n's workflow expression evaluation system that enables...

  • SecurityMar 11, 2026

    Critical RCE in Hitachi Vantara Pentaho via Unrestricted

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 fail to restrict Groovy scripts in PRPT reports, allowing privileged users...

  • SecurityMar 9, 2026

    Critical Stack-Based Buffer Overflow in Delta Electronics

    A critical CVSS 9.8 stack-based buffer overflow in Delta Electronics COMMGR2 allows unauthenticated remote code execution, posing severe risk to...

  • SecurityMar 4, 2026

    CVE-2026-28775: Unauthenticated Root RCE in IDC SFX

    A critical unauthenticated RCE vulnerability in International Datacasting Corporation's SFX Series satellite receivers allows attackers to execute...

  • SecurityMar 4, 2026

    Mail2Shell: Zero-Click RCE in FreeScout Helpdesk

    A maximum-severity zero-click vulnerability dubbed Mail2Shell allows unauthenticated attackers to compromise FreeScout mail servers by simply sending a...

  • SecurityMar 4, 2026

    CISA Adds Actively Exploited VMware Aria Operations RCE

    CISA has added CVE-2026-22719, a high-severity command injection vulnerability in VMware Aria Operations allowing unauthenticated remote code execution,...

  • SecurityFeb 20, 2026

    BeyondTrust Remote Support and PRA Critical RCE Under

    A critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access is under active exploitation,...

  • SecurityFeb 20, 2026

    Critical RCE in Microsoft Semantic Kernel Python SDK

    A maximum-severity code injection vulnerability in Microsoft's Semantic Kernel Python SDK allows authenticated attackers to execute arbitrary code through...

  • SecurityFeb 18, 2026

    Critical Grandstream VoIP Vulnerability Allows

    A critical CVSS 9.3 stack-based buffer overflow in Grandstream GXP1600 series VoIP phones allows unauthenticated remote code execution, enabling attackers...

  • SecurityFeb 17, 2026

    BeyondTrust Remote Support Pre-Authentication RCE Under

    A critical pre-authentication OS command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access with CVSS 9.9 is being...

  • SecurityFeb 17, 2026

    Cisco Unified Communications Zero-Day Exploited for

    An actively exploited zero-day in Cisco Unified Communications allows unauthenticated remote code execution with root privileges via crafted HTTP...

  • SecurityFeb 15, 2026

    GitHub Copilot Command Injection Flaws Enable Remote Code

    Multiple high-severity command injection vulnerabilities discovered in GitHub Copilot extensions for VS Code, Visual Studio, and JetBrains could allow...

  • SecurityFeb 12, 2026

    Critical RCE in WPvivid Backup Plugin Threatens 900,000+

    A critical unauthenticated arbitrary file upload vulnerability in the WPvivid Backup & Migration plugin allows remote code execution on over 900,000...

  • SecurityFeb 10, 2026

    BeyondTrust Zero-Day Allows Unauthenticated Command

    A critical zero-day in BeyondTrust Remote Support and Privileged Remote Access enables unauthenticated command execution, potentially compromising entire...

  • SecurityFeb 9, 2026

    Critical PAN-OS GlobalProtect Gateway RCE Vulnerability

    A critical unauthenticated remote code execution vulnerability in Palo Alto Networks PAN-OS GlobalProtect gateway allows complete firewall takeover. CVSS 9.8.

  • SecurityFeb 7, 2026

    Fortinet FortiOS SSL VPN Heap Overflow Enables Pre-Auth RCE

    Fortinet patches a critical heap-based buffer overflow in FortiOS SSL VPN that allows unauthenticated remote code execution on FortiGate appliances....

  • SecurityFeb 7, 2026

    Eight Critical n8n Vulnerabilities — Sandbox Escape to

    Popular workflow automation platform n8n hit with eight high-to-critical CVEs including a CVSS 10.0 unauthenticated RCE and sandbox escape bypassing...

  • SecurityFeb 6, 2026

    Apache Struts Critical RCE via OGNL Injection Returns

    A new critical OGNL injection vulnerability in Apache Struts allows unauthenticated remote code execution, reminiscent of the 2017 Equifax breach vector....

  • SecurityFeb 6, 2026

    Critical Fortinet FortiClientEMS SQL Injection

    Fortinet patches a CVSS 9.8 SQL injection in FortiClientEMS 7.4.4 allowing unauthenticated remote code execution. Endpoint management servers across...

  • SecurityFeb 5, 2026

    Microsoft Exchange Server SSRF to RCE Chain Actively

    A server-side request forgery vulnerability in Exchange Server is being chained with deserialization flaws for unauthenticated remote code execution....

  • SecurityFeb 5, 2026

    SolarWinds Web Help Desk RCE Vulnerability Added to CISA KEV

    Critical deserialization vulnerability in SolarWinds Web Help Desk enables unauthenticated remote code execution. CISA confirms active exploitation.

  • SecurityFeb 4, 2026

    Critical Google Looker Vulnerabilities Allow Full System

    Two severe vulnerabilities in Google Looker, dubbed 'LookOut', could allow attackers to gain complete control of self-hosted deployments affecting 60,000+...

  • SecurityFeb 4, 2026

    Critical n8n Vulnerability (CVSS 10.0) Enables Complete

    A maximum-severity flaw dubbed 'Ni8mare' in the popular workflow automation platform n8n allows unauthenticated attackers to gain full control of...

  • NewsJan 30, 2026

    Cisco Patches Critical Webex Vulnerability Allowing Remote

    Cisco has released emergency patches for a critical vulnerability in Webex that could allow unauthenticated remote code execution. Organizations urged to...

  • SecurityJan 18, 2026

    Critical D-Link Router RCE Under Active Exploitation - No

    CVE-2026-0625 allows unauthenticated remote code execution on legacy D-Link DSL routers. Devices are end-of-life with no patches forthcoming. Immediate...