Tag: remote-code-execution
-
Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks
Tags: attack, authentication, cve, cvss, cyber, exploit, flaw, hacker, rce, remote-code-execution, update, vpn, vulnerability, zero-dayCheck Point has warned customers about the active exploitation of two critical vulnerabilities in its VPN gateway and Security Management products: CVE-2026-85102 and the newly disclosed CVE-2026-93616. Both vulnerabilities have a CVSS score of 9.8 and allow for pre-authentication attacks, making immediate patching and reducing exposure essential. Check Point Flaws CVE-2026-85102 is an improper certificate-validation…
-
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).”An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file First seen on…
-
Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE
A SharePoint Server vulnerability tracked as CVE-2026-65660 turned out to be far more serious than Microsoft first indicated. The company originally described it as a spoofing issue with a CVSS score of 6.5. In reality, it is an authenticated RCE flaw rated 8.8. That gap matters, because security teams that trusted the first label may…
-
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been First seen…
-
Orkes Conductor RCE Draws Nearly 7,000 Exploit Attempts
A critical Orkes Conductor flaw is under active attack, with 6,696 exploit attempts blocked in a week. Defenders should upgrade to version 3.30.2 or later. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-orkes-conductor-rce-cve-2026-58138/
-
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server.WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed “Comment2Shell,” on September 17 in version 7.1.1 and told…
-
âš¡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side…
-
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
Tags: attack, cyber, data, flaw, github, malicious, rce, remote-code-execution, supply-chain, technology, threat“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code execution, sensitive-data exposure, and account compromise across major technology and enterprise platforms. The research, published by Hacktron, highlights a familiar but increasingly dangerous supply-chain weakness: applications often trust native image-decoding…
-
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.”SolarWinds…
-
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.”Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote First seen on…
-
Researchers use AI to find widespread software decoder flaw
The bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository. First seen on cyberscoop.com Jump to article: cyberscoop.com/hacktron-ai-heif-heist-vulnerability/
-
Over 100,000 WordPress Sites Exposed to RCE Through Tutor LMS Vulnerability
Tags: ai, control, cyber, data-breach, intelligence, rce, remote-code-execution, threat, vulnerability, wordpressMore than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on August 23, 2026, by Wordfence Argus, an AI-assisted vulnerability research agent, and validated by the Wordfence Threat Intelligence team.…
-
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/
-
Plugin4Shell Zero-Click RCE Hits Claude Code, Codex, Copilot and Gemini CLI
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interaction. Researchers Or Nevo, Dor Granat, and Niv Hoffman have identified that the issue impacts Anthropic Claude Code, OpenAI Codex,…
-
Konfigurationen prüfen – Samba-Schwachstellen ermöglichen Remote Code Execution
First seen on security-insider.de Jump to article: www.security-insider.de/samba-kritische-rce-luecken-updates-a-fd876cee91ffe494cffac65c82a8e097/
-
Konfigurationen prüfen – Samba-Schwachstellen ermöglichen Remote Code Execution
First seen on security-insider.de Jump to article: www.security-insider.de/samba-kritische-rce-luecken-updates-a-fd876cee91ffe494cffac65c82a8e097/
-
Konfigurationen prüfen – Samba-Schwachstellen ermöglichen Remote Code Execution
First seen on security-insider.de Jump to article: www.security-insider.de/samba-kritische-rce-luecken-updates-a-fd876cee91ffe494cffac65c82a8e097/
-
Konfigurationen prüfen – Samba-Schwachstellen ermöglichen Remote Code Execution
First seen on security-insider.de Jump to article: www.security-insider.de/samba-kritische-rce-luecken-updates-a-fd876cee91ffe494cffac65c82a8e097/
-
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.Unbound 1.26.1, released the same day, fixes the bug, tracked as…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theft
Tags: advisory, credentials, cyber, flaw, rce, remote-code-execution, theft, update, vulnerability, xssJenkins has released security updates addressing 20 vulnerabilities across 13 plugins, including multiple high-severity flaws that could allow authorized attackers to bypass Groovy sandbox protections and execute arbitrary code on Jenkins controllers. The advisory, dated September 16, 2026, also addresses stored cross-site scripting (XSS), server-side request forgery (SSRF), credential exposure, path traversal, OAuth token hijacking,…
-
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.”This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution,” Wordfence said.The WordPress security company said it has blocked over First seen…
-
Critical VMware RCE flaw now exploited by ransomware gangs
Tags: attack, cisa, cybersecurity, exploit, flaw, infrastructure, ransomware, rce, remote-code-execution, vcenter, vmware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/
-
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access.In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo…
-
Red Heron Hackers Exploit Critical Gitea RCE to Steal Source Code and Deploy Linux Rootkit
Tags: access, china, credentials, cyber, exploit, hacker, linux, rce, remote-code-execution, threat, vulnerabilityA Chinese-speaking threat actor known as Red Heron has exploited a critical remote code execution (RCE) vulnerability in Gitea to steal private source code, harvest credentials, establish persistent access, and move laterally within victim infrastructures. Researchers from the Acronis Threat Research Unit (TRU) have linked this operation to a newly documented Linux implant called JITTERLY,…
-
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
Tags: authentication, credentials, cve, cyber, exploit, flaw, hacker, rce, remote-code-execution, threat, vulnerabilityA threat actor exploited a critical pre-authentication remote code execution vulnerability in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in just eight seconds, according to the Sysdig Threat Research Team. This vulnerability, tracked as CVE-2026-39987, affects marimo versions up to 0.20.4 and…
-
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign.”Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems,” Acronis Threat Research Unit (TRU)…
-
OpenAI Agents Linked to 2,000 RubyGems Packages, Alleged RubyDoc RCE
Researchers linked OpenAI agents to RubyGems abuse and alleged RubyDoc RCE, highlighting risks around autonomous AI, build systems, and credentials. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-openai-rubygems-rubydoc-rce/
-
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/human-attacker-machine-speed/
-
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-51990, the vulnerability chains an insecure custom protocol handler, unrestricted embedded-browser navigation, and an obsolete Chromium build running without sandbox protections. Tencent addressed…

