Topic: remote code execution

  • BeyondTrust Patches Critical Pre-Auth RCE Flaw in Remote Access Tools

    BeyondTrust Patches Critical Pre-Auth RCE Flaw in Remote Access Tools

    A critical security flaw (CVE-2026-1731) in BeyondTrust's self-hosted remote access software allows unauthenticated attackers to execute arbitrary OS commands, posing a severe risk of complete system compromise. The vulnerability impacts specific versions of Remote Support and Privileged Remote A...

    Read More »
  • Critical RCE Bug Threatens PTC Windchill and FlexPLM Users

    Critical RCE Bug Threatens PTC Windchill and FlexPLM Users

    A critical, unauthenticated remote code execution vulnerability (CVE-2024-xxxx) has been identified in PTC's Windchill and FlexPLM software, posing a severe security risk. Successful exploitation could allow attackers to steal intellectual property, tamper with critical product data, or deploy ra...

    Read More »
  • Microsoft Silent as Hackers Exploit WSUS Server Bug

    Microsoft Silent as Hackers Exploit WSUS Server Bug

    A critical Windows Server Update Services (WSUS) vulnerability (CVE-2025-59287) is being actively exploited, allowing attackers to execute arbitrary code and take full control of affected systems. Microsoft issued an emergency patch after an initial fix failed, but security researchers have alrea...

    Read More »
  • Elementor Pro flaw lets attackers run code on WordPress sites

    Elementor Pro flaw lets attackers run code on WordPress sites

    "Critical vulnerability (CVE-2026-32475) in Elementor Pro:" A file upload logic flaw allows attackers to upload malicious PHP files and achieve arbitrary code execution; affects all versions before 4.2.2. "Exploitation conditions:" Requires a published Elementor form with a File Upload field ...

    Read More »
  • Windows IKE Extension RCE Flaw Actively Exploited

    Windows IKE Extension RCE Flaw Actively Exploited

    CISA warns that threat actors are actively exploiting CVE-2024-38063, a critical 9.8-severity remote code execution vulnerability in Windows IKE Service Extensions, which allows unauthenticated attackers to take full control of systems without user interaction. Microsoft patched the flaw in its A...

    Read More »
  • Hackers exploit new FastJson zero-day in US corporate attacks

    Hackers exploit new FastJson zero-day in US corporate attacks

    Cybercriminals are exploiting a critical zero-day vulnerability (CVE-2026-16723) in the FastJson Java library, enabling remote code execution without user interaction, primarily targeting U.S. organizations across multiple critical sectors. The flaw exists in FastJson versions 1.2.68 through 1.2....

    Read More »
  • Critical Adobe ColdFusion bug exploited in active attacks

    Critical Adobe ColdFusion bug exploited in active attacks

    Attackers are actively exploiting a critical Adobe ColdFusion vulnerability, CVE-2026-48282, which allows unauthenticated remote code execution on unpatched versions 2025.9, 2023.20, and earlier. Adobe released a patch on Tuesday urging immediate deployment within 72 hours, and real-world exploit...

    Read More »
  • Critical SimpleHelp RMM bug CVE-2026-48558 exposes endpoints to takeover

    Critical SimpleHelp RMM bug CVE-2026-48558 exposes endpoints to takeover

    A critical unauthenticated vulnerability (CVE-2026-48558) in the SimpleHelp RMM platform allows attackers to remotely create a "Technician" account, enabling full control over managed networks and endpoints. The flaw requires no authentication or user interaction, and due to SimpleHelp's deep sys...

    Read More »
  • Oracle patches PeopleSoft zero-day used in data theft attacks

    Oracle patches PeopleSoft zero-day used in data theft attacks

    Oracle issued an urgent security alert for CVE-2026-35273, a critical PeopleSoft zero-day vulnerability with a CVSS score of 9.8 that allows unauthenticated remote code execution and is actively exploited in ShinyHunter data theft attacks. The ShinyHunters extortion gang has used this flaw to com...

    Read More »
  • USB Speaker Hack Infects PCs Without Physical Contact

    USB Speaker Hack Infects PCs Without Physical Contact

    A remote code execution vulnerability in the Sound Blaster Katana V2X speaker allows attackers within Bluetooth range to compromise connected computers without physical contact. Researcher Rasmus Moorats discovered the flaw after finding that the speaker's proprietary Creative Transport Protocol ...

    Read More »
  • Critical Gogs RCE Bug Enables Code Execution for Any Authenticated User

    Critical Gogs RCE Bug Enables Code Execution for Any Authenticated User

    A critical unpatched vulnerability in Gogs (CVSS 9.4) allows any authenticated user to achieve remote code execution by crafting a malicious branch name that injects the `--exec` flag into the `git rebase` command during a rebase merge operation. The exploit requires no admin privileges or user i...

    Read More »
  • Google Accidentally Reveals Details of Unpatched Chromium Bug

    Google Accidentally Reveals Details of Unpatched Chromium Bug

    A serious unpatched Chromium vulnerability allows JavaScript to continue running as a background service worker even after the browser is closed, enabling remote code execution and potential botnet creation through a single malicious webpage visit. The bug affects all Chromium-based browsers incl...

    Read More »
  • Critical NGINX Bug: DoS & Potential RCE in 18-Year-Old Flaw

    Critical NGINX Bug: DoS & Potential RCE in 18-Year-Old Flaw

    A critical heap buffer overflow vulnerability (CVE-2026-42945, CVSS 9.2) was discovered in NGINX's rewrite module, present for nearly two decades in versions 0.6.27 through 1.30.0, enabling denial of service and potential remote code execution when specific rewrite and set directives are combined...

    Read More »
  • Claude AI Discovers Vim and Emacs RCE File Open Flaws

    Claude AI Discovers Vim and Emacs RCE File Open Flaws

    Critical security vulnerabilities enabling remote code execution have been discovered in the widely used text editors Vim and GNU Emacs, posing a significant risk to developers and system administrators. The flaws, found by prompting an AI assistant, are triggered when a user opens a maliciously ...

    Read More »
  • Critical SolarWinds Serv-U Flaws Grant Root Server Access

    Critical SolarWinds Serv-U Flaws Grant Root Server Access

    SolarWinds has released critical security patches for its Serv-U file transfer software to fix four vulnerabilities that could allow remote code execution and full administrative takeover of servers. All four flaws require the attacker to already have high-privilege access, limiting exploitation ...

    Read More »
  • Critical VoIP Phone Bug Enables Stealthy Eavesdropping (CVE-2026-2329)

    Critical VoIP Phone Bug Enables Stealthy Eavesdropping (CVE-2026-2329)

    A critical security flaw (CVE-2026-2329) in Grandstream GXP1600 series VoIP phones allows unauthenticated attackers to gain full remote control via a buffer overflow in the web interface. Successful exploitation enables attackers to steal credentials and, most alarmingly, reconfigure the phone to...

    Read More »
  • Critical RCE Flaw Found in BeyondTrust Remote Support Software

    Critical RCE Flaw Found in BeyondTrust Remote Support Software

    A critical pre-authentication command injection flaw (CVE-2026-1731) in BeyondTrust's Remote Support and Privileged Remote Access software allows unauthenticated attackers to remotely execute arbitrary commands. The vulnerability, impacting thousands of on-premises instances, requires immediate m...

    Read More »
  • GitHub Codespaces RCE Flaw Exposed

    GitHub Codespaces RCE Flaw Exposed

    A critical vulnerability in GitHub Codespaces allows attackers to execute remote code by embedding malicious commands in configuration files, which run automatically when a developer opens a compromised repository or pull request. The attack exploits three main vectors: automatic tasks in `.vscod...

    Read More »
  • Critical n8n Vulnerabilities Exposed with Public Exploits

    Critical n8n Vulnerabilities Exposed with Public Exploits

    Critical vulnerabilities (CVE-2026-25049) in the n8n workflow platform allow users with workflow edit permissions to execute arbitrary code and fully compromise the host server, including stealing credentials. The flaws stem from incomplete AST-based sandboxing and a type-confusion vulnerability ...

    Read More »
  • Critical FortiSIEM Flaw Patched: Remote Code Execution Risk

    Critical FortiSIEM Flaw Patched: Remote Code Execution Risk

    A critical, unauthenticated OS command injection vulnerability (CVE-2025-64155) in Fortinet's FortiSIEM platform allows remote attackers to execute arbitrary code and take full control of systems. The flaw, found in the phMonitor service, involves a two-stage attack: unauthenticated argument inje...

    Read More »