Topic: arbitrary code execution
-
Critical vm2 sandbox flaw enables host code execution
A critical sandbox escape vulnerability (CVE-2026-26956) has been discovered in the popular Node.js library vm2, allowing attackers to execute arbitrary code on the host system via WebAssembly exception handling that bypasses JavaScript-level protections. The flaw, confirmed in vm2 version 3.10.4...
Read More » -
Adobe Fixes Critical Acrobat Reader Flaw Under Active Attack
Adobe has urgently patched a critical zero-day vulnerability (CVE-2026-34621) in Acrobat Reader, actively exploited since last year, which allows arbitrary code execution via a malicious PDF. The in-the-wild exploit, discovered via a malicious PDF sample, performs system fingerprinting and commun...
Read More » -
SolarWinds Serv-U Exposes Critical RCE Vulnerabilities
SolarWinds has released critical patches for its Serv-U file transfer software to address four severe vulnerabilities that could allow attackers to gain full system control, requiring immediate updates. The vulnerabilities, which include broken access control and type confusion bugs, enable remot...
Read More » -
Apple Patches Critical Zero-Day Flaw Actively Exploited in Attacks
Apple has patched a critical zero-day vulnerability (CVE-2026-20700) in its dyld component, which was exploited in a sophisticated, targeted attack against older iOS versions. The updates also fix two related WebKit vulnerabilities, all discovered and reported by Google's Threat Analysis Group, t...
Read More » -
Dangerous VSCode Extensions Steal Crypto on OpenVSX
Malicious extensions in the VSCode ecosystem, such as C++ Playground and HTTP Format, have been downloaded thousands of times and are designed to steal cryptocurrency or create backdoors, with the threat actor TigerJack repeatedly uploading them under new names to evade detection. These extension...
Read More » -
Cisco Patches Critical Zero-Day Flaw Actively Under Attack
Cisco has released critical security patches for 14 vulnerabilities in its IOS and IOS XE software, including a high-severity flaw (CVE-2025-20352) that has been actively exploited as a zero-day. The vulnerability is a stack overflow in the SNMP subsystem, affecting a wide range of devices, and c...
Read More » -
Windows 11 and Edge Hacked at Pwn2Own Berlin 2026
Day one of Pwn2Own Berlin 2026 awarded $523,000 for 24 zero-day exploits, with DEVCORE's Orange Tsai earning $175,000 for a Microsoft Edge sandbox escape and Windows 11 compromised three times for privilege escalation. Other notable exploits included Red Hat Linux, NVIDIA Container Toolkit, LiteL...
Read More » -
Urgent Apple Update Fixes Critical Security Exploits
Apple has released urgent security patches for two actively exploited zero-day vulnerabilities (CVE-2025-14174 and CVE-2025-43529) in its WebKit browser engine, which is used across iPhones, iPads, and Macs. The flaws, discovered through a collaboration between Apple and Google, could allow memor...
Read More »