Tag: remote-code-execution
-
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber…
-
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said…
-
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects CSF versions 14.00 through 16.29 and has been addressed in version 16.30 and later. CSF is widely used on Linux servers and in cPanel/WHM environments…
-
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only “under specific conditions” that it has not described.One flaw affects Check Point’s Security Gateways, its firewall appliances. The other affects those gateways…
-
WatchGuard RCE flaw now exploited in ransomware attacks
Tags: attack, cisa, cybersecurity, exploit, firewall, flaw, infrastructure, ransomware, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/
-
Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions…
-
Dell Secure Connect Gateway Critical Flaws Allow Unauthenticated Remote Code Execution and Admin Access
Dell has released security updates for the Secure Connect Gateway (SCG) Application and Appliance after discovering three critical vulnerabilities. These flaws can expose enterprise deployments to unauthenticated administrative access, remote command execution, and potential host-level compromise. Detailed in Dell Security Advisory DSA-2026-382, these issues affect SCG 5.0 appliance versions earlier than 5.36.00.16 and application versions…
-
PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells
Tags: access, backdoor, cve, cyber, exploit, flaw, linux, malware, remote-code-execution, vulnerabilityA sophisticated Linux implant linked to compromised F5 BIG-IP Access Policy Management (APM) environments. The activity has been associated with exploitation of CVE-2025-53521, an unauthenticated remote code execution flaw affecting BIG-IP APM when an access policy is configured on a virtual server. F5 has confirmed exploitation of the vulnerability and links the related compromise activity…
-
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE, Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution, but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.Security firm TantoSec has published a working exploit chain targeting vulnerabilities…
-
N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/nable-hotfix-critical-rce/
-
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/
-
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/
-
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
Every on-premises N-central build below 2026.3.1.14, including servers updated to Hotfix 3 a day earlier, needs Hotfix 4. N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed.N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this…
-
Telerik UI Flaws Let Attackers Chain AES-CBC Padding Oracle to Unauthenticated RCE
Security researchers have identified a critical vulnerability chain in Progress Telerik UI for ASP.NET AJAX, which allows unauthenticated attackers to escalate from a cryptographic padding oracle to remote code execution on exposed web applications. Documented by Tanto Security researcher Marcio Almeida, this vulnerability affects Telerik UI for ASP.NET AJAX versions 2010.1.309 through 2026.2.519. To address…
-
Critical N-able N-central Flaw Enables Pre-Auth Remote Code Execution
N-able has released a security update to address CVE-2026-86218, a critical-severity vulnerability in its N-central remote monitoring and management platform. This vulnerability could enable pre-authenticated remote code execution on an affected server. The issue is fixed in N-central version 2026.3 Hotfix 4, build 2026.3.1.14. Because an attacker may exploit this vulnerability before logging in, it…
-
Magento and Adobe Commerce StyleSmuggler 0-Day RCE Actively Exploited in Attacks
Tags: adobe, attack, cyber, exploit, Internet, open-source, rce, remote-code-execution, vulnerability, zero-daySecurity researchers have discovered an actively exploited, unauthenticated remote code execution vulnerability affecting installations of Magento Open Source and Adobe Commerce. This vulnerability, known as StyleSmuggler, allows attackers to inject PHP payloads into Magento’s template system and execute them via standard application workflows. Sansec’s Forensics Team reported that attacks began on September 4, targeting internet-facing…
-
N-able patches max severity N-central flaw amid ongoing attacks
N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks/
-
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 an authentication bypass and remote code execution chain to conduct command execution and reconnaissance, as well as First…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote code execution. This flaw, tracked as CVE-2026-14894, affects Super Forms versions 6.3.313 and earlier. Administrators are urged to upgrade to version 6.3.314 immediately. Super Forms WordPress Flaw Wordfence disclosed this unauthenticated arbitrary…
-
Google fixes the sixth actively exploited Chrome zero-day of 2026
Tags: browser, chrome, cve, exploit, flaw, google, remote-code-execution, update, vulnerability, zero-dayGoogle patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V8 type confusion flaw. The bug affects Chrome’s JavaScript and WebAssembly engine and could let a…
-
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.The vulnerabilities in question are – CVE-2026-14894 (CVSS score: 9.8) – A missing file type validation vulnerability in Super Forms Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type,…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
Tags: credentials, cve, cyber, flaw, login, network, password, remote-code-execution, router, service, theft, update, vulnerabilityTP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on the local network to crash a key networking service, potentially execute code, or steal administrator credentials from captured login traffic. The vulnerabilities, identified as CVE-2026-18167 and CVE-2026-18330, impact the router’s EasyMesh component and…
-
Cisco Fixed Critical RCE in Nexus 9000 Series Switches
Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges. Cisco’s Technical Assistance Center…
-
HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/
-
WordPress Plugin Flaw Lets Attackers Turn SQL Injection Into Complete Site Takeover
Tags: backup, cve, cyber, exploit, flaw, injection, remote-code-execution, sql, vulnerability, wordpressA high-severity vulnerability affecting over 5 million active WordPress installations could allow unauthenticated attackers to exploit stored SQL injection vulnerabilities, leading to remote code execution and complete website takeover. This issue, tracked as CVE-2026-19949, impacts the widely used All-in-One WP Migration and Backup plugin developed by ServMask. Wordfence has rated the vulnerability 8.8 out of…

