Tag: remote-code-execution
-
Sangoma Switchvox RCE Flaw Actively Exploited in Wild via Unauthenticated SQL Injection
Tags: cve, cyber, data-breach, exploit, flaw, injection, Internet, rce, remote-code-execution, sql, voip, vulnerabilitySecurity researchers have reported active exploitation attempts targeting a critical vulnerability in Sangoma Switchvox, allowing unauthenticated attackers to execute code remotely via SQL injection. This vulnerability, tracked as CVE-2026-9586, affects internet-exposed Switchvox enterprise VoIP systems and was addressed in Switchvox version 8.4.0.2. Sangoma Switchvox RCE Flaw Zach Hanley, a researcher at Horizon3.ai, revealed that this…
-
Mythos helps bug bounty firm find critical hidden RCE
HackerOne used Anthropic’s controversial Claude Mythos 5 model on its codebase and found a critical hidden flaw. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650013/Mythos-helps-bug-bounty-firm-find-critical-hidden-RCE
-
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor’s edge devices. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/sonicwall-sma-1000-zero-days-unauthenticated-rce
-
Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance
Researchers have demonstrated that Anthropic’s Claude AI can assist in porting a remote code execution exploit between vulnerable models of WAGO programmable logic controllers (PLCs). However, this process requires significant human guidance, lengthy analysis sessions, and more than $500 in API usage. The experiment focused on CVE-2021-31886, a pre-authentication buffer overflow flaw in the Nucleus…
-
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31.GeoNetwork originated at the United Nations Food and…
-
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of the USER command First seen…
-
SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
-
SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
-
SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
-
SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
-
Forescout Research Tests Whether AI Can Create PLC Attacks
New research from Forescout’s Vedere Labs has demonstrated how artificial intelligence could begin to lower the barriers to developing sophisticated cyberattacks against industrial systems. The research set out to answer a potentially important question for operational technology (OT) security: can AI successfully adapt a remote code execution (RCE) exploit developed for one programmable logic controller…
-
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Tags: ai, credentials, exploit, flaw, framework, open-source, openai, remote-code-execution, threat, vulnerabilityThreat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
-
Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks
Tags: ai, attack, cloud, control, credentials, cve, cyber, exploit, flaw, hacker, rce, remote-code-execution, theft, threat, vulnerabilityThreat actors are actively exploiting two newly disclosed remote code execution vulnerabilities affecting Langflow and Ruby on Rails. These campaigns focus on cloud credential theft, host reconnaissance, and the establishment of command-and-control (C2) functions. VulnCheck researchers have reported exploitation targeting CVE-2026-0768 in Langflow, a low-code platform for building AI-powered applications and automated workflows. This vulnerability…
-
Hackers Exploit Langflow RCE Flaw to Harvest OpenAI and AWS Credentials
Tags: ai, credentials, cve, cyber, exploit, flaw, hacker, openai, rce, remote-code-execution, threat, vulnerabilityThreat actors are actively exploiting a critical remote code execution vulnerability in Langflow, a low-code platform used for building AI-powered applications and automating workflows. This vulnerability, tracked as CVE-2026-0768, affects the code validator in Langflow’s custom component editor. According to Caitlin Condon, VP of Security Research at VulnCheck, the flaw allows unauthenticated remote code execution…
-
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
Tags: authentication, cisa, cve, cybersecurity, exploit, flaw, healthcare, infrastructure, kev, office, remote-code-execution, software, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA)addedthe following vulnerabilities to itsKnown Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578,…
-
PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE Attack Chain
Tags: advisory, attack, authentication, cve, cyber, microsoft, rce, remote-code-execution, vulnerabilityA public proof-of-concept (PoC) repository has garnered attention for a pre-authentication remote code execution chain targeting Microsoft Exchange Server. This repository highlights CVE-2026-62911, an Exchange authentication-bypass vulnerability disclosed following Pwn2Own Berlin 2026. Defenders should treat the published code as unverified until it is independently validated in an isolated laboratory environment. Both the official advisory and…
-
Metasploit Adds Exploit for PaperCut MF/NG Zero-Day RCE Vulnerabilities
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving print management servers. The proposed module targets CVE-2026-81578 and CVE-2026-82078, two vulnerabilities that attackers can exploit to achieve remote code…
-
AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers
Security researchers have demonstrated how flaws in the AI shopping assistant of a major unnamed U.S. retailer could be exploited to enable remote code execution (RCE) on the company’s backend infrastructure through its public-facing mobile application. Netanel Rubin, co-founder and CTO of Rein Security, along with researcher Dan Avraham, presented their findings during a Black…
-
DoS und RCE möglich – Kritischer Out-of-Bounds Write in Dell PowerStore
First seen on security-insider.de Jump to article: www.security-insider.de/dell-powerstore-sdnas-smb-luecke-cve-2026-67271-a-c0c1d9732481f80544433117011d1c2e/
-
Exploited RCE Flaws and Infrastructure Attacks Define this Cybersecurity Week in August 2026
Weekly summary of Cybersecurity Insider newsletters for August 2026. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/weekly-roundup/exploited-rce-flaws-and-infrastructure-attacks-define-this-cybersecurity-week-in-august-2026/
-
Attackers Exploit MCP RCE, Blind Prompt Injection and Memory Credential Theft Against AI Infrastructure
Tags: ai, cloud, credentials, cyber, data-breach, exploit, framework, infrastructure, injection, rce, remote-code-execution, service, theftAttackers are increasingly treating AI infrastructure as a high-value cloud entry point, exploiting exposed Model Context Protocol (MCP) services, agent frameworks, and AI gateways to execute code, validate prompt injection, deploy cryptominers, and steal credentials from process memory. The campaigns show that attackers are no longer using only generic web-server tradecraft; they are tailoring reconnaissance,…
-
Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/
-
700 OpenAI Agents Coordinate Attack on Hugging Face and Gain Remote Code Execution
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways to communicate across supposedly isolated sandboxes. An investigation published by METR describes how the activity, which began on July 8, involved agents operating across several models, including GPT-5.6 Sol and an internally persistent model identified…
-
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot’s Locomotion PC.The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through chat_go and bashrunner and the…
-
Hackers Actively Exploiting Pre-Auth RCE Flaw in PaperCut Print Software
Tags: control, credentials, exploit, flaw, hacker, login, rce, remote-code-execution, software, vulnerabilityAttackers are actively exploiting a critical, unauthenticated remote code execution (RCE) vulnerability in PaperCut NG and PaperCut MF, widely used print management software, security researchers at Huntress have confirmed. The flaw allows an attacker to remotely take control of a PaperCut server’s configuration without needing any login credentials, ultimately enabling arbitrary code execution on the…
-
ServiceNow Patches Critical Flaws Enabling Unauthenticated RCE and SQL Injection
ServiceNow has issued security advisories for four vulnerabilities, including critical flaws in its AI platform. These vulnerabilities could allow unauthenticated attackers to execute arbitrary code, manipulate instance data, elevate privileges, or run SQL commands against underlying databases. On August 27, 2026, the company published KB3152242, which covers CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. ServiceNow reported that…
-
Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code execution (RCE) from nearby devices via Bluetooth Low Energy (BLE). This research, referred to as UniBLEed, indicates that the attack can compromise the robot’s Locomotion PC, the component responsible for essential functions, without requiring…
-
Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
Credit: HacktronVercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem.The Windows path traversal, tracked as CVE-2026-75604& First seen on…
-
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Tags: ai, botnet, data-breach, exploit, infrastructure, iot, login, malicious, rce, remote-code-execution, tool, windowsA fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and…
-
CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulnerability
Tags: cisa, cve, cyber, cybersecurity, exploit, infrastructure, kev, microsoft, rce, remote-code-execution, service, sql, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2019-1068, a remote code execution vulnerability affecting Microsoft SQL Server, to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. This vulnerability allows an attacker to execute code in the security context of the SQL Server Database Engine service account. Microsoft SQL Server…

