Tag: rce
-
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job.This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.Nothing here…
-
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Researchers disclosed critical flaws in AI coding agents from Anthropic, Google, and OpenAI that could enable credential theft, RCE, and supply chain attacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/black-hat-2026-critical-flaws-found-in-anthropic-google-and-openai-coding-agents/
-
KHunt Toolkit Turns Oracle SQL Injection Into SYSTEM-Level RCE and Credential Theft
Tags: credentials, cyber, data, infrastructure, injection, oracle, rce, remote-code-execution, sql, theft, threatKHunt shows how a “routine” SQL injection against an Oracle”‘backed web app can be weaponized into SYSTEM”‘level remote code execution and credential theft by compiling a full post”‘exploitation toolkit directly inside the database engine. This incident materially shifts the Oracle threat model: the database itself becomes attacker infrastructure, not just a data store. Subsequent triage…
-
Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines. First seen on hackread.com Jump to article: hackread.com/black-hat-usa-2026-github-compromise-ai-coding/
-
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
Tags: access, cisa, cve, cybersecurity, data, exploit, flaw, infrastructure, rce, remote-code-execution, vulnerabilityA newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).The vulnerability in question is CVE-2026-63077 (CVSS score: 9.8), a case of deserialization of untrusted data that could allow an unauthenticated attacker with access to a TeamCity…
-
CISA Alerts Issues on Actively Exploited TeamCity Remote Code Execution Vulnerability
Tags: cisa, cve, cyber, cybersecurity, data-breach, exploit, flaw, infrastructure, kev, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in JetBrains TeamCity, tracked as CVE-2026-63077, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. This flaw allows unauthenticated remote code execution (RCE) on vulnerable TeamCity On-Premises servers exposed via HTTP or HTTPS. CISA Issues on TeamCity RCE…
-
Oracle SQL Injection Attack Enables Remote Code Execution
A Huntress investigation reveals how attackers used SQL injection to achieve RCE and steal credentials. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/oracle-sql-injection-attack-enables-remote-code-execution/
-
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/
-
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.The list of vulnerabilities is as follows – CVE-2026-9198 (CVSS score: 9.8) – A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full…
-
Django Flaws Let Attackers Trigger RCE, SSRF, DoS, and XSS Attacks
The Django project has released security updates, specifically Django 6.0.8 and Django 5.2.17, to address four vulnerabilities that could lead to server-side request forgery (SSRF), arbitrary file writes with potential for remote code execution (RCE), denial-of-service (DoS), and stored cross-site scripting (XSS) attacks. An advisory posted by Natalia Bidart on August 4, 2026, urges all…
-
Metasploit Exploit Targets Critical Ruby on Rails Active Storage RCE Flaw
A new Metasploit Framework module has been submitted for review, targeting the critical Ruby on Rails Active Storage vulnerability, tracked as CVE-2026-66066. This submission poses an increased risk to applications that utilize the Vips image-processing backend. The proposed module is named `exploit/multi/http/rails_activestorage_vips_rce` and was introduced in Rapid7 Metasploit Framework pull request #21733 by contributor jburgess-r7.…
-
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rails-patches-critical-active-storage-flaw-with-rce-potential/
-
FastJson RCE Zero-Day Actively Targets Organizations
Threat actors are actively exploiting the FastJson CVE-2026-16723 zero-day, with no patch available for affected FastJson 1.x versions. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/fastjson-rce-zero-day-actively-targets-organizations/
-
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/
-
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/teamcity-rce-cve-2026-63077-fixed/
-
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/
-
vBulletin Pre-Auth RCE Flaw Allows Remote PHP Code Execution
A critical pre-authentication remote code execution vulnerability in vBulletin, tracked as CVE-2026-61511, could allow unauthenticated attackers to execute arbitrary PHP code on vulnerable forum servers. This issue affects vBulletin versions 6.2.1 and earlier, as well as 6.1.6 and earlier, according to a July 27, 2026, disclosure from SSD Secure Disclosure. If exploited successfully, this vulnerability…
-
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain
Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in Oj, a Ruby JSON parser with a native C implementation, into full command execution inside…
-
GitLab RCE Flaws Allow Attackers to Execute Commands via Malicious Jupyter Notebooks
A critical remote code execution (RCE) vulnerability chain in GitLab’s Jupyter Notebook diff renderer. This issue is rooted in two long-standing memory safety vulnerabilities within the Oj Ruby JSON parser. The vulnerabilities impact both GitLab Community Edition and Enterprise Edition releases from version 15.2.0 through 19.0.1. They allow an authenticated project member to execute commands…
-
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large companies run more than … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/26/week-in-review-servicenow-pre-auth-rce-exploited-in-the-wild-hugging-face-breached/
-
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires…
-
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Tags: authentication, data, data-breach, endpoint, exploit, extortion, flaw, Internet, login, ransomware, rce, remote-code-execution, threatThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.”Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling…
-
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server.An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The chain needs no administrator rights, continuous integration (CI) runner access, victim interaction First seen…
-
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code…
-
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. >>WatchTowr is … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/sharepoint-cve-2026-50522-exploited/
-
CISA orders urgent action on actively exploited Langflow RCE flaw
Tags: ai, cisa, cybersecurity, exploit, flaw, framework, government, infrastructure, rce, remote-code-execution, update, vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-langflow-rce-flaw/
-
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers. Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization…
-
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/
-
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.The…

