Tag: remote-code-execution
-
Exploit for Fortinet Critical RCE Bug Allows SIEM Root Access
First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/exploit-fortinet-critical-rce-bug-siem-root-access
-
Details of Atlassian Confluence RCE Vulnerability Disclosed
SonicWall has shared technical details on a recently addressed high-severity remote code execution flaw in Confluence. The post l has shared technical… First seen on securityweek.com Jump to article: www.securityweek.com/details-of-atlassian-confluence-rce-vulnerability-disclosed/
-
PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)
Security researchers have published a proof-of-concept (PoC) exploit that chains together two vulnerabilities (CVE-2024-4358, CVE-2024-1800) to achiev… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/04/cve-2024-4358-cve-2024-1800-poc/
-
Zyxel issues emergency RCE patch for endlife NAS devices
Zyxel Networks has released an emergency security update to address three critical vulnerabilities impacting older NAS devices that have reached end-o… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/zyxel-issues-emergency-rce-patch-for-end-of-life-nas-devices/
-
High-risk Atlassian Confluence RCE fixed, PoC available (CVE-2024-21683)
If you’re self-hosting an Atlassian Confluence Server or Data Center installation, you should upgrade to the latest available version to fix a high-se… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/03/cve-2024-21683-poc/
-
Zyxel NAS Devices Vulnerability Let Attackers Execute Code Remotely
Zyxel has released patches addressing critical command injection and remote code execution vulnerabilities in two of its NAS products, NAS326 and NAS5… First seen on gbhackers.com Jump to article: gbhackers.com/zyxel-nas-devices-vulnerability/
-
Vulnerabilities in employee management system could lead to remote code execution, login credential theft
Talos also recently helped to responsibly disclose and patch other vulnerabilities in the Foxit PDF Reader and two open-source libraries that support … First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/vulnerability-roundup-may-1-2024/
-
Exploit for critical Progress Telerik auth bypass released, patch now
Researchers have published a proof-of-concept (PoC) exploit script demonstrating a chained remote code execution (RCE) vulnerability on Progress Teler… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/exploit-for-critical-progress-telerik-auth-bypass-released-patch-now/
-
Ivanti Patches Critical Remote Code Execution Flaws in Endpoint Manager
Ivanti on Tuesday rolled out fixes to address multiple critical security flaws in Endpoint Manager (EPM) that could be exploited to achieve remote cod… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/ivanti-patches-critical-remote-code.html
-
Security Advisory: Microsoft Windows DNS Server Remote Code Execution Vulnerability
Summary On July 14th, 2020 Microsoft publicly disclosed the existence of a critical severity vulnerability in all recent versions of the Microsoft Win… First seen on research.kudelskisecurity.com Jump to article: research.kudelskisecurity.com/2020/07/17/security-advisory-microsoft-windows-dns-server-remote-code-execution-vulnerability/
-
Fortinet FortiSIEM Vulnerabilities Expose Systems to Remote Code Execution
Multiple vulnerabilities have recently been discovered in Fortinet FortiSIEM, raising concerns over potential remote code execution exploits. FortiSIE… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/fortinet-fortisiem-vulnerability/
-
Experts released PoC exploit code for RCE in Fortinet SIEM
Researchers released a proof-of-concept (PoC) exploit for remote code execution flaw CVE-2024-23108 in Fortinet SIEM solution. Security researchers at… First seen on securityaffairs.com Jump to article: securityaffairs.com/163797/hacking/fortinet-siem-critical-rce-poc.html
-
TP-Link Archer C5400X gaming router is affected by a critical flaw
Researchers warn of a critical remote code execution vulnerability in TP-Link Archer C5400X gaming router. Researchers at OneKeydiscovered a a critica… First seen on securityaffairs.com Jump to article: securityaffairs.com/163762/hacking/tp-link-archer-c5400x-critical-flaw.html
-
Critical Netflix Genie Bug Opens Big Data Orchestration to RCE
The severe security vulnerability (CVE-2024-4701, CVSS 9.9) gives remote attackers a way to burrow into Netflix’s Genie open source platform, which is… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/netflix-fixes-critical-vulnerability-on-big-data-orchestration-service
-
Exploit released for maximum severity Fortinet RCE bug, patch now
‹Security researchers have released a proof-of-concept (PoC) exploit for a maximum-severity vulnerability in Fortinet’s security information and event… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/exploit-released-for-maximum-severity-fortinet-rce-bug-patch-now/
-
TP-Link fixes critical RCE bug in popular C5400X gaming router
The TP-Link Archer C5400X gaming router is vulnerable to security flaws that could enable an unauthenticated, remote attacker to execute commands on t… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/tp-link-fixes-critical-rce-bug-in-popular-c5400x-gaming-router/
-
Critical Bug Allows DoS, RCE, Data Leaks in All Major Cloud Platforms
An on-by-default endpoint in ubiquitous logging service Fluent Bit contains an oversight that hackers can toy with to rattle most any cloud environmen… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/critical-bug-dos-rce-data-leaks-in-all-major-cloud-platforms
-
AI-as-a-Service Platform Patches Critical RCE Vulnerability
Hackers Could Exploit Bug on Replicate to Steal Data, Manipulate AI Models. Attackers could have exploited a now-mitigated critical vulnerability in t… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ai-as-a-service-platform-patches-critical-rce-vulnerability-a-25324
-
Critical SQL Injection flaws impact Ivanti Endpoint Manager (EPM)
Ivanti addressed multiple flaws in the Endpoint Manager (EPM), including remote code execution vulnerabilities. Ivanti this week rolled out security p… First seen on securityaffairs.com Jump to article: securityaffairs.com/163587/security/ivanti-endpoint-manager-critical-sql-injection.html
-
Patch up 4 critical bugs in ArubaOS lead to remote code execution
First seen on theregister.com Jump to article: www.theregister.com/2024/05/02/hpe_aruba_patches/
-
Critical Fluent Bit flaw impacts all major cloud providers
‹A critical Fluent Bit vulnerability that can be exploited in denial-of-service and remote code execution attacks impacts all major cloud providers an… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-fluent-bit-flaw-impacts-all-major-cloud-providers/
-
Critical Flaw In Confluence Server Let Attackers Execute Arbitrary Code
The widely used team workspace corporate wiki Confluence has been discovered to have a critical remote code execution vulnerability. This vulnerabilit… First seen on gbhackers.com Jump to article: gbhackers.com/critical-confluence-server-flaw/
-
CISA Warns of Attacks Exploiting NextGen Healthcare Mirth Connect Flaw
CISA has added CVE-2023-43208, an unauthenticated remote code execution vulnerability, to its KEV catalog. The post added CVE-2023-43208, an unauthen… First seen on securityweek.com Jump to article: www.securityweek.com/cisa-warns-of-attacks-exploiting-nextgen-healthcare-mirth-connect-flaw/
-
Experts released PoC exploit code for RCE in QNAP QTS
Experts warn of fifteen vulnerabilities in the QNAP QTS, the operating system for the Taiwanese vendor’s NAS products. An audit of QNAP QTS conducted … First seen on securityaffairs.com Jump to article: securityaffairs.com/163470/hacking/fifteen-vulnerabilities-in-the-qnap-qts.html
-
QNAP Rushes Patch for Code Execution Flaw in NAS Devices
QNAP rolls out patches for multiple vulnerabilities after proof-of-concept exploit published for a remote code execution vulnerability. The post ls ou… First seen on securityweek.com Jump to article: www.securityweek.com/qnap-rushes-patch-for-code-execution-flaw-in-nas-devices/
-
AI Python Package Flaw ‘Llama Drama’ Threatens Software Supply Chain
The Llama Drama vulnerability in the Llama-cpp-Python package exposes AI models to remote code execution (RCE) attacks, enabling attackers to steal da… First seen on hackread.com Jump to article: www.hackread.com/ai-python-package-flaw-llama-drama-supply-chain/
-
PoC Exploit Released for QNAP QTS zero-day RCE Flaw
Researchers have shown a proof-of-concept (PoC) attack for a zero-day remote code execution (RCE) flaw in the QTS operating system from QNAP. Users of… First seen on gbhackers.com Jump to article: gbhackers.com/poc-exploit-released-2/
-
QNAP QTS zero-day in Share feature gets public RCE exploit
An extensive security audit of QNAP QTS, the operating system for the company’s NAS products, has uncovered fifteen vulnerabilities of varying severit… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/qnap-qts-zero-day-in-share-feature-gets-public-rce-exploit/
-
Critical Git Vulnerability Let Attackers Execute Remote Code : PoC Published
A critical remote code execution vulnerability has been discovered in the git clone which was assigned with CVE-2024-32002 and the severity has been g… First seen on gbhackers.com Jump to article: gbhackers.com/git-flaw-remote-code-execution/
-
6K-plus AI models may be affected by critical RCE vulnerability
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/6k-plus-ai-models-may-be-affected-by-critical-rce-vulnerability

