Topic: arbitrary code execution

  • Critical vm2 sandbox flaw enables host code execution

    Critical vm2 sandbox flaw enables host code execution

    A critical sandbox escape vulnerability (CVE-2026-26956) has been discovered in the popular Node.js library vm2, allowing attackers to execute arbitrary code on the host system via WebAssembly exception handling that bypasses JavaScript-level protections. The flaw, confirmed in vm2 version 3.10.4...

    Read More »
  • Adobe Fixes Critical Acrobat Reader Flaw Under Active Attack

    Adobe Fixes Critical Acrobat Reader Flaw Under Active Attack

    Adobe has urgently patched a critical zero-day vulnerability (CVE-2026-34621) in Acrobat Reader, actively exploited since last year, which allows arbitrary code execution via a malicious PDF. The in-the-wild exploit, discovered via a malicious PDF sample, performs system fingerprinting and commun...

    Read More »
  • SolarWinds Serv-U Exposes Critical RCE Vulnerabilities

    SolarWinds Serv-U Exposes Critical RCE Vulnerabilities

    SolarWinds has released critical patches for its Serv-U file transfer software to address four severe vulnerabilities that could allow attackers to gain full system control, requiring immediate updates. The vulnerabilities, which include broken access control and type confusion bugs, enable remot...

    Read More »
  • Apple Patches Critical Zero-Day Flaw Actively Exploited in Attacks

    Apple Patches Critical Zero-Day Flaw Actively Exploited in Attacks

    Apple has patched a critical zero-day vulnerability (CVE-2026-20700) in its dyld component, which was exploited in a sophisticated, targeted attack against older iOS versions. The updates also fix two related WebKit vulnerabilities, all discovered and reported by Google's Threat Analysis Group, t...

    Read More »
  • Dangerous VSCode Extensions Steal Crypto on OpenVSX

    Dangerous VSCode Extensions Steal Crypto on OpenVSX

    Malicious extensions in the VSCode ecosystem, such as C++ Playground and HTTP Format, have been downloaded thousands of times and are designed to steal cryptocurrency or create backdoors, with the threat actor TigerJack repeatedly uploading them under new names to evade detection. These extension...

    Read More »
  • Cisco Patches Critical Zero-Day Flaw Actively Under Attack

    Cisco Patches Critical Zero-Day Flaw Actively Under Attack

    Cisco has released critical security patches for 14 vulnerabilities in its IOS and IOS XE software, including a high-severity flaw (CVE-2025-20352) that has been actively exploited as a zero-day. The vulnerability is a stack overflow in the SNMP subsystem, affecting a wide range of devices, and c...

    Read More »
  • Windows 11 and Edge Hacked at Pwn2Own Berlin 2026

    Windows 11 and Edge Hacked at Pwn2Own Berlin 2026

    Day one of Pwn2Own Berlin 2026 awarded $523,000 for 24 zero-day exploits, with DEVCORE's Orange Tsai earning $175,000 for a Microsoft Edge sandbox escape and Windows 11 compromised three times for privilege escalation. Other notable exploits included Red Hat Linux, NVIDIA Container Toolkit, LiteL...

    Read More »
  • Urgent Apple Update Fixes Critical Security Exploits

    Urgent Apple Update Fixes Critical Security Exploits

    Apple has released urgent security patches for two actively exploited zero-day vulnerabilities (CVE-2025-14174 and CVE-2025-43529) in its WebKit browser engine, which is used across iPhones, iPads, and Macs. The flaws, discovered through a collaboration between Apple and Google, could allow memor...

    Read More »