Topic: command injection

  • Critical GitHub RCE Flaw CVE-2026-3854 Exploitable via Single Git Push

    Critical GitHub RCE Flaw CVE-2026-3854 Exploitable via Single Git Push

    A critical command injection vulnerability (CVE-2026-3854, CVSS 8.7) in GitHub.com and GitHub Enterprise Server allows any authenticated user with push access to execute arbitrary code via a single git push command, due to insufficient sanitization of push option values in internal headers. The f...

    Read More »
  • CISA Orders Agencies to Patch Critical Fortinet Flaw in 7 Days

    CISA Orders Agencies to Patch Critical Fortinet Flaw in 7 Days

    CISA has mandated a 7-day deadline for U.S. government agencies to patch CVE-2025-58034, a critical Fortinet FortiWeb vulnerability being actively exploited in zero-day attacks. The vulnerability is an OS command injection flaw that allows authenticated attackers to execute arbitrary code with ro...

    Read More »
  • Ubiquiti flags critical new UniFi OS vulnerability

    Ubiquiti flags critical new UniFi OS vulnerability

    Ubiquiti disclosed seven critical vulnerabilities in UniFi OS, including a maximum-severity flaw (CVSS 10.0) enabling command injection attacks that allow remote attackers to gain full device control without authentication. The remaining six vulnerabilities range from high to critical severity an...

    Read More »
  • Urgent CISA Alert: Active Attacks Exploit Critical CentOS Bug

    Urgent CISA Alert: Active Attacks Exploit Critical CentOS Bug

    A critical security flaw (CVE-2025-48703) in CentOS Web Panel allows unauthenticated attackers to execute arbitrary commands, prompting CISA to issue an urgent patch-or-discontinue directive by November 25. The vulnerability stems from improper handling of the 'changePerm' endpoint and unsanitize...

    Read More »
  • Urgent WD My Cloud Flaw Enables Remote Hacks

    Urgent WD My Cloud Flaw Enables Remote Hacks

    Western Digital released an urgent firmware update (version 5.31.108) to fix a critical security flaw (CVE-2025-30247) in multiple My Cloud NAS devices, which allows remote command execution via crafted HTTP requests. The update applies to several models, but end-of-support devices like the My Cl...

    Read More »
  • Patch Now: CISA Warns of Active FileZen Exploit (CVE-2026-25108)

    Patch Now: CISA Warns of Active FileZen Exploit (CVE-2026-25108)

    A critical vulnerability (CVE-2026-25108) in Soliton Systems' FileZen appliance is under active exploitation, allowing attackers to run arbitrary commands, prompting urgent patching and a CISA mandate for federal agencies. The flaw impacts specific versions of the secure file transfer server and ...

    Read More »
  • Critical Vulnerability Found in W3 Total Cache WordPress Plugin

    Critical Vulnerability Found in W3 Total Cache WordPress Plugin

    A critical security flaw (CVE-2025-9501) in the W3 Total Cache WordPress plugin allows unauthenticated attackers to execute arbitrary PHP commands via specially crafted comments, affecting all versions before 2.8.13. The vulnerability, located in the `_parse_dynamic_mfunc()` function, was fixed i...

    Read More »
  • Urgent: Critical Web Panel Flaw Actively Exploited (CVE-2025-48703)

    Urgent: Critical Web Panel Flaw Actively Exploited (CVE-2025-48703)

    A critical security vulnerability (CVE-2025-48703) in Control Web Panel (CWP) is being actively exploited, posing a severe threat to web hosting environments and prompting its addition to CISA's Known Exploited Vulnerabilities catalog. The flaw is an OS command injection that allows unauthenticat...

    Read More »
  • Libraesva ESG Zero-Day Exploited in Active Attacks (CVE-2025-59689)

    Libraesva ESG Zero-Day Exploited in Active Attacks (CVE-2025-59689)

    A critical zero-day vulnerability (CVE-2025-59689) in the Libraesva Email Security Gateway is being actively exploited by a suspected state-sponsored actor, allowing arbitrary command execution on affected systems. The flaw is a command injection vulnerability caused by improper input sanitizatio...

    Read More »
  • TP-Link Router Security Flaw Requires Immediate Patch

    TP-Link Router Security Flaw Requires Immediate Patch

    A critical security vulnerability (CVE-2025-15517) in several TP-Link Archer NX router models allows unauthenticated attackers to bypass login and take full control, requiring immediate firmware updates. TP-Link also patched additional flaws, including a hardcoded cryptographic key and command in...

    Read More »
  • Over 1,200 IceWarp Servers Exposed to Critical RCE Flaw

    Over 1,200 IceWarp Servers Exposed to Critical RCE Flaw

    A critical remote code execution vulnerability (CVE-2025-14500) in IceWarp software puts over 1,200 internet-facing servers at immediate risk, requiring urgent patching. The flaw is an unauthenticated OS command injection that grants attackers full system control, and patches have been available ...

    Read More »
  • Critical RCE flaw in Zyxel routers puts users at risk

    Critical RCE flaw in Zyxel routers puts users at risk

    A critical command injection vulnerability (CVE-2025-13942) in Zyxel devices allows remote code execution, but exploitation requires both UPnP and WAN access to be enabled, with WAN disabled by default. Zyxel has released firmware patches for this and other high-severity flaws, while also confirm...

    Read More »
  • Fortra Issues Critical Alert for GoAnywhere MFT Vulnerability

    Fortra Issues Critical Alert for GoAnywhere MFT Vulnerability

    Fortra has issued an urgent alert for a critical vulnerability (CVE-2025-10035) in GoAnywhere MFT software, allowing remote command injection due to unsafe data deserialization. The vulnerability can be exploited without user interaction, particularly affecting internet-exposed Admin Consoles, an...

    Read More »
  • CISA Warns of Active VMware RCE Attacks

    CISA Warns of Active VMware RCE Attacks

    A critical command injection vulnerability (CVE-2026-22719) in VMware Aria Operations is under active exploitation, allowing unauthenticated attackers to execute arbitrary commands and potentially take full control of systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has m...

    Read More »
  • Hackers Actively Exploit Critical BeyondTrust RCE Flaw

    Hackers Actively Exploit Critical BeyondTrust RCE Flaw

    A critical command injection vulnerability (CVE-2026-1731) in BeyondTrust's remote access software is being actively exploited, allowing unauthenticated attackers to run arbitrary commands on unpatched systems. Threat intelligence confirms widespread scanning and exploitation, with attackers abus...

    Read More »
  • Urgent: Actively Exploited FortiWeb Flaw Patched (CVE-2025-58034)

    Urgent: Actively Exploited FortiWeb Flaw Patched (CVE-2025-58034)

    A critical OS command injection vulnerability (CVE-2025-58034) in FortiWeb firewalls is being actively exploited, allowing attackers to execute arbitrary commands via manipulated HTTP or CLI requests. The vulnerability affects multiple FortiWeb versions, and organizations must upgrade to patched ...

    Read More »
  • CISA Orders Urgent Patch for Actively Exploited Fortinet Flaws

    CISA Orders Urgent Patch for Actively Exploited Fortinet Flaws

    CISA has added two critical FortiSandbox vulnerabilities (CVE-2026-39808 and CVE-2026-25089) to its Known Exploited Vulnerabilities catalog, with a CVSS score of 9.1, and is requiring federal agencies to patch by July 19. CVE-2026-39808 is an OS command injection flaw in FortiSandbox versions 4.4...

    Read More »
  • Microsoft Patches 56 Flaws, Including Two Zero-Days Under Active Attack

    Microsoft Patches 56 Flaws, Including Two Zero-Days Under Active Attack

    Microsoft's final 2025 security update patches 56 vulnerabilities, including three critical flaws, with two already being actively exploited. The most urgent fix is for CVE-2025-62221, a privilege escalation flaw in Windows that is under active attack and requires prompt patching. Other significa...

    Read More »
  • Thousands of Ruckus Networks Devices Vulnerable Due to Unpatched Flaws

    Thousands of Ruckus Networks Devices Vulnerable Due to Unpatched Flaws

    Thousands of Ruckus Networks devices are exposed to critical unpatched vulnerabilities, allowing attackers to take control of enterprise wireless environments. The flaws affect Ruckus Virtual Smart Zone (vSZ) and Ruckus Network Director (RND), enabling risks like hardcoded credentials, authentica...

    Read More »
  • Windows 11 Notepad Bug Executes Files Via Markdown Links

    Windows 11 Notepad Bug Executes Files Via Markdown Links

    A high-severity vulnerability in Windows 11 Notepad allowed attackers to execute malicious code remotely by tricking users into clicking a malicious link within a Markdown file. The flaw exploited the app's Markdown preview feature, where specially crafted links using non-standard protocols could...

    Read More »