#remote-code-execution

[ follow ]
Information security
fromSecurityWeek
2 hours ago

Vulnerabilities Allowed Full Compromise of Google Looker Instances

Two Looker vulnerabilities (LookOut) allow attackers with developer permissions to achieve remote code execution, full administrative access, data exfiltration, and potential cross-tenant access.
#docker
Information security
fromTechzine Global
5 hours ago

CISA warns of active exploitation of critical SolarWinds vulnerability

A critical remote-code-execution vulnerability CVE-2025-40551 in SolarWinds Web Help Desk is actively exploited; federal agencies must install the patch within three days.
Information security
fromTechzine Global
6 hours ago

Critical vulnerability in React Native development tool actively exploited

Critical CVE-2025-11953 in React Native's Metro server permits remote code execution via exposed /open-url endpoint, impacting many development environments on Windows and Linux.
#react2shell
fromInfoWorld
1 month ago
Information security

React2Shell: Anatomy of a max-severity flaw that sent shockwaves through the web

fromInfoWorld
1 month ago
Information security

React2Shell: Anatomy of a max-severity flaw that sent shockwaves through the web

#solarwinds
Information security
fromThe Hacker News
8 hours ago

CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog

A critical untrusted-data deserialization vulnerability in SolarWinds Web Help Desk (CVE-2025-40551) enables unauthenticated remote code execution and is actively exploited.
Information security
fromThe Hacker News
1 day ago

Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package

CVE-2025-11953 (Metro4Shell) is actively exploited to achieve unauthenticated remote command execution and deliver persistent, Rust-based malware via a PowerShell loader.
Information security
fromThe Hacker News
1 day ago

OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link

A token-exfiltration vulnerability in OpenClaw allowed one-click remote code execution by trusting an unvalidated gatewayUrl and auto-sending stored gateway tokens.
#ivanti-epmm
#smartermail
#n8n
Information security
fromSecurityWeek
1 week ago

'PackageGate' Flaws Open JavaScript Ecosystem to Supply Chain Attacks

Six vulnerabilities in major JavaScript package managers (NPM, PNPM, VLT, Bun) allow bypassing supply chain protections and enable remote code execution.
Information security
fromThe Hacker News
1 week ago

Critical Grist-Core Vulnerability Allows RCE Attacks via Spreadsheet Formulas

A Pyodide sandbox escape (Cellbreak, CVE-2026-24002) in Grist-Core allows remote code execution; upgrade to Grist 1.7.9 or later to mitigate.
Information security
fromKotaku
1 week ago

Report Of Steam Game Exploit Leads To Online Dispute With Devs

A remote code execution vulnerability in Screeps: World allowed players to gain control of others' computers, prompting developers to patch after a disputed report.
Information security
fromTechRepublic
1 week ago

Zoom and GitLab Patch RCE, DoS, and 2FA Bypass Vulnerabilities - TechRepublic

Emergency patches for Zoom and GitLab fix critical vulnerabilities that could enable remote code execution, full network takeover, and development-operation crashes.
Apple
fromTechRepublic
2 weeks ago

New iOS and iPadOS Flaws Leave Millions of iPhones at Risk

Two WebKit vulnerabilities (CVE-2025-43529 and CVE-2025-14174) allow zero-click remote code execution in Safari, potentially giving attackers full access to iPhones and iPads.
Information security
fromSecurityWeek
1 week ago

2024 VMware Flaw Now in Attackers' Crosshairs

CVE-2024-37079, a critical DCERPC out-of-bounds write in VMware vCenter (CVSS 9.8), is being exploited in the wild; apply June 2024 patches immediately.
Information security
fromTechzine Global
1 week ago

Misuse of VS Code tasks poses risk to developers

VS Code tasks.json can automatically run commands when a folder is opened, enabling supply-chain attacks that execute malicious, persistent code across platforms.
Information security
fromComputerworld
1 week ago

Critical Cisco UC bug actively exploited

Critical RCE vulnerability CVE-2026-20045 affects Cisco Unified Communications products, is actively exploited, and patches have been released; CISA added it to its exploited vulnerabilities catalog.
#cve-2026-20045
fromThe Hacker News
2 weeks ago

CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

The vulnerability, tracked as CVE-2026-1245 (CVSS score: N/A), affects all versions of the module prior to version 2.3.0, which addresses the issue. Patches for the flaw were released on November 26, 2025. Binary-parser is a widely used parser builder for JavaScript that allows developers to parse binary data. It supports a wide range of common data types, including integers, floating-point values, strings, and arrays. The package attracts approximately 13,000 downloads on a weekly basis.
Information security
Information security
fromTheregister
2 weeks ago

Anthropic quietly fixed flaws in its Git MCP server

Three mcp-server-git vulnerabilities allowed chaining with Filesystem MCP to achieve remote code execution; mcp-server-git prior to 2025.12.18 must be updated.
#cve-2025-37164
fromTechzine Global
2 weeks ago
Information security

RondoDox botnet exploits HPE OneView vulnerability on a massive scale

RondoDox botnet rapidly escalated automated exploitation of critical, unauthenticated remote code execution vulnerability CVE-2025-37164 in HPE OneView, causing tens of thousands of attack attempts.
fromTechzine Global
1 month ago
Information security

HPE OneView requires patch for vulnerability with highest CVE score

Hewlett Packard Enterprise OneView had a critical unauthenticated remote code execution vulnerability (CVE-2025-37164) fixed in version 11.00 with hotfixes for older releases.
fromThe Hacker News
2 weeks ago

Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways

The vulnerability, tracked as CVE-2025-20393 (CVSS score: 10.0), is a remote command execution flaw arising as a result of insufficient validation of HTTP requests by the Spam Quarantine feature. Successful exploitation of the defect could permit an attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. However, for the attack to work, three conditions must be met - The appliance is running a vulnerable release of Cisco AsyncOS Software The appliance is configured with the Spam Quarantine feature The Spam Quarantine feature is exposed to and reachable from the internet
Information security
#gogs
Information security
fromComputerworld
3 weeks ago

Trend Micro patches critical flaws in its Apex Central software

A vulnerability in Apex Central's management server lets remote attackers cause the server to load and execute a malicious DLL without authentication.
fromThe Hacker News
3 weeks ago

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions

"Trend Micro has released security updates to address multiple security vulnerabilities impacting on-premise versions of Apex Central for Windows, including a critical bug that could result in arbitrary code execution. The vulnerability, tracked as CVE-2025-69258, carries a CVSS score of 9.8 out of a maximum of 10.0. The vulnerability has been described as a case of remote code execution affecting LoadLibraryEX."
Information security
Information security
fromThe Hacker News
3 weeks ago

Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances

Multiple critical command-injection and information-disclosure vulnerabilities in Coolify allow authenticated or low-privileged users to achieve remote code execution, container escape, and root compromise.
#hpe-oneview
#veeam-backup--replication
Information security
fromThe Hacker News
4 weeks ago

Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers

CVE-2026-0625 permits unauthenticated command injection in D-Link DSL gateway dnscfg.cgi, enabling remote code execution and active exploitation of legacy models.
Information security
fromInfoWorld
4 weeks ago

Open WebUI bug turns the 'free model' into an enterprise backdoor

Open WebUI's storage of long-lived JWTs in localStorage plus Direct Connections execute events enables account takeover and can escalate to remote code execution.
fromThe Hacker News
4 weeks ago

Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers

If a developer uses MultipartFile.move() without the second options argument or without explicitly sanitizing the filename, an attacker can supply a crafted filename value containing traversal sequences, writing to a destination path outside the intended upload directory," the project maintainers said in an advisory released last week. "This can lead to arbitrary file write on the server. However, successful exploitation hinges on a reachable upload endpoint.
Information security
#watchguard
#react-server-components
fromInfoQ
1 month ago
Information security

Patch Urgently - Critical Vulnerability CVE-2025-55182 in React Server Functions Actively Exploited

fromTechzine Global
2 months ago
Information security

Meta warns of critical vulnerability in React Server Components

A critical unauthenticated RCE in React Server Components (CVE-2025-55182) requires immediate updates to patched versions to prevent remote code execution.
fromThe Hacker News
2 months ago
React

Critical RSC Bugs in React and Next.js Allow Unauthenticated Remote Code Execution

Maximum-severity RSC vulnerability CVE-2025-55182 enables unauthenticated remote code execution; update affected React, RSC plugin, and Next.js packages immediately.
fromInfoQ
1 month ago
Information security

Patch Urgently - Critical Vulnerability CVE-2025-55182 in React Server Functions Actively Exploited

#browser-extensions
fromThe Hacker News
1 month ago

CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks

Details of the six-year-old flaw were publicly shared by Cisco Talos in April 2019, describing it as an exploitable remote code execution vulnerability in the ACEManager "upload.cgi" function of Sierra Wireless AirLink ES450 firmware version 4.9.3. Talos reported the flaw to the Canadian company in December 2018. "This vulnerability exists in the file upload capability of templates within the AirLink 450," the company said. "When uploading template files, you can specify the name of the file that you are uploading."
Information security
fromThe Hacker News
1 month ago

Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution

"Threat actors can potentially abuse this as a way to access the web.config file, opening the door for deserialization and remote code execution," security researcher Bryan Masters said. The use of hard-coded cryptographic keys could allow threat actors to decrypt or forge access tickets, enabling them to access sensitive files like web.config that can be exploited to achieve ViewState deserialization and remote code execution, the cybersecurity company added.
Information security
Information security
fromThe Hacker News
1 month ago

.NET SOAPwn Flaw Opens Door for File Writes and Remote Code Execution via Rogue WSDL

A .NET Framework SOAP handling flaw (SOAPwn) enables attackers to abuse WSDL-created HTTP client proxies to perform arbitrary file writes and achieve remote code execution.
fromTheregister
1 month ago

Microsoft won't fix .NET RCE bug affecting enterprise apps

Its name and the official documentation both paint a simple picture: it should handle SOAP messages transported over HTTP. Straightforward. Predictable. Safe. Reality is less cooperative.
Information security
Information security
fromComputerWeekly.com
1 month ago

Microsoft patched over 1,100 CVEs in 2025 | Computer Weekly

A Windows Cloud Files Mini Filter Driver use-after-free vulnerability (CVE-2025-62221) is being actively exploited and can enable SYSTEM privilege escalation.
Information security
fromThe Hacker News
1 month ago

Sneeit WordPress RCE Exploited in the Wild While ICTBroadcast Bug Fuels Frost Botnet Attacks

A critical RCE (CVE-2025-6389) in Sneeit Framework WordPress plugin (≤8.3) is actively exploited; update to 8.4 to mitigate.
Information security
fromThe Hacker News
1 month ago

Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks

AI-powered IDEs have chained vulnerabilities that enable prompt injection, abuse of auto-approved tools, and weaponization of legitimate IDE features for data exfiltration and RCE.
Information security
fromComputerWeekly.com
2 months ago

Cloudflare fixes second outage in a month | Computer Weekly

Cloudflare briefly lost Dashboard and API availability due to a WAF parsing change deployed to mitigate a critical React Server Components RCE (React2Shell) vulnerability, now resolved.
Information security
fromTechzine Global
2 months ago

React2Shell exploited hours after discovery

Chinese state-backed groups actively weaponized React2Shell (CVE-2025-55182) within hours, enabling unauthenticated remote code execution against React 19.x and Next.js App Router.
Information security
fromInfoWorld
2 months ago

Developers urged to immediately upgrade React, Next.js

React 19's RSC Flight protocol contains a critical deserialization vulnerability enabling remote code execution; immediate upgrade and patching are required.
#react
Information security
fromThe Hacker News
2 months ago

Microsoft Silently Patches Windows LNK Flaw After Years of Active Exploitation

Microsoft patched CVE-2025-9491, a Windows .LNK UI misinterpretation vulnerability enabling remote code execution via crafted shortcut files.
fromTechzine Global
2 months ago

OpenAI Codex CLI contained dangerous MCP security gap

This happened via the Model Context Protocol, intended to integrate external tools into the Codex environment. The CLI loaded MCP configurations from a .codex/config.toml file and executed the commands defined therein immediately upon startup. There was no approval prompt, no validation, and no check when the commands changed. MCP itself does not contain extensive built-in security, even after a series of updates.
Information security
Information security
fromThe Hacker News
2 months ago

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware

ShadyPanda operated a seven-year browser extension campaign that amassed over 4.3 million installs and escalated to remote code execution, data exfiltration, and affiliate fraud.
fromThe Hacker News
2 months ago

New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions

Cybersecurity researchers have discovered five vulnerabilities in Fluent Bit, an open-source and lightweight telemetry agent, that could be chained to compromise and take over cloud infrastructures. The security defects "allow attackers to bypass authentication, perform path traversal, achieve remote code execution, cause denial-of-service conditions, and manipulate tags," Oligo Security said in a report shared with The Hacker News. Successful exploitation of the flaws could enable attackers to disrupt cloud services, manipulate data, and burrow deeper into cloud and Kubernetes infrastructure.
Information security
#oracle-identity-manager
Information security
fromTheregister
2 months ago

Weaponized file name flaw allows RCE through glob

A shell-invocation flaw in glob's CLI -c option enables remote code execution on POSIX systems when processing attacker-controlled filenames; update affected glob versions immediately.
Information security
fromSecurityWeek
2 months ago

Imunify360 Vulnerability Could Expose Millions of Sites to Hacking

A critical flaw in Imunify360's Ai-Bolit scanner can allow arbitrary code execution and potential full compromise of shared hosting servers running the scanner.
#zeromq
fromInfoWorld
2 months ago
Information security

Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft

fromInfoWorld
2 months ago
Information security

Copy-paste vulnerability hits AI inference frameworks at Meta, Nvidia, and Microsoft

#wsus
fromIT Pro
3 months ago
Information security

CISA issues alert after botched Windows Server patch exposes critical flaw

fromIT Pro
3 months ago
Information security

CISA issues alert after botched Windows Server patch exposes critical flaw

fromTechzine Global
2 months ago

Critical vulnerability exposed in JavaScript library expr-eval

A critical security vulnerability in the popular JavaScript library expr-eval allows remote code execution. The bug, with a CVSS score of 9.8, affects hundreds of projects and is forcing developers to migrate to a secure version quickly. The vulnerability, registered as CVE-2025-12735, is listed in the US National Vulnerability Database (NVD) and is considered one of the most serious security issues in recent JavaScript ecosystems.
Information security
Information security
fromBleepingComputer
2 months ago

Popular JavaScript library expr-eval vulnerable to RCE flaw

Critical RCE vulnerability (CVE-2025-12735) in expr-eval/expr-eval-fork allows remote code execution via unvalidated Parser.evaluate() context variables.
fromInfoQ
2 months ago

Redis Critical Remote Code Execution Vulnerability Discovered After 13 Years

Exploiting the so-called "RediShell" remote code execution vulnerability, an authenticated user can use a specially crafted script to manipulate the garbage collector, trigger a use-after-free, and potentially execute arbitrary code remotely. The vulnerability exploits a 13-year-old UAF memory corruption bug in Redis, allowing a post-auth attacker to send a crafted Lua script to escape the default Lua sandbox and execute arbitrary native code.
Information security
Information security
fromInfoWorld
2 months ago

RCE in React Native CLI opens Dev Servers to attacks

The Metro development server exposes an unsafe /open-url endpoint and defaults to listening on 0.0.0.0, allowing remote command execution unless patched.
Information security
fromThe Hacker News
3 months ago

New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands

A CSRF vulnerability in ChatGPT Atlas allows persistent-memory injection that can execute arbitrary code, persist across devices, and compromise accounts and systems.
fromThe Hacker News
3 months ago

Active Exploits Hit Dassault and XWiki - CISA Confirms Critical Flaws Under Attack

Both CVE-2025-6204 and CVE-2025-6205 affect DELMIA Apriso versions from Release 2020 through Release 2025. They were addressed by Dassault Systèmes in early August. According to details shared by ProjectDiscovery researchers Rahul Maini, Harsh Jaiswal, and Parth Malhotra last month, the two security flaws can be fashioned together into an exploit chain to create accounts with elevated privileges and then drop executable files into a web-served directory, resulting in a full application compromise.
Information security
Information security
fromTheregister
3 months ago

Windows Server WSUS bug exploits underway, Microsoft's mum

A critical RCE in Windows Server Update Services (CVE-2025-59287) enables unauthenticated full system takeover and is being actively exploited, prompting emergency patches.
#rust
fromThe Hacker News
3 months ago

Two CVSS 10.0 Bugs in Red Lion RTUs Could Hand Hackers Full Industrial Control

Red Lion's Sixnet RTUs provide advanced automation, control, and data acquisition capabilities in industrial automation and control systems, primarily across energy, water, and wastewater treatment, transportation, utilities, and manufacturing sectors. These industrial devices are configured using a Windows utility called Sixnet IO Tool Kit, with a proprietary Sixnet "Universal" protocol used to interface and enable communication between the kit and the RTUs.
Information security
fromThe Cyber Express
3 months ago

Critical CVE-2025-61927 VM Context Escape In Happy DOM Library

A critical security flaw has been identified in Happy DOM, a widely used JavaScript library primarily employed for server-side rendering and testing frameworks. The vulnerability, cataloged as CVE-2025-61927, allows attackers to escape the library's virtual machine (VM) context, leading to potential remote code execution on vulnerable systems. This flaw threatens millions of applications that depend on Happy DOM. The root of this vulnerability lies in the improper isolation of the Node.js VM context within Happy DOM versions 19 and earlier.
Information security
[ Load more ]