Tag

#command-injection

10 stories taggedcommand-injection.

Photoreal editorial shot of a dimly lit server rack with amber warning LEDs reflecting off polished metal, rows of patch cables in soft focus, cool blue ambient
Vulnerabilities

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts

A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.

4 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Arista rushes fix for VeloCloud flaw already being used in attacks

A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

4 min read
Photoreal news-editorial image of a rack-mounted network load balancer appliance in a dim data center aisle, cooling fans glowing amber, cables hanging from the
Vulnerabilities

Zimbra Patches Six Security Flaws, Including a Bug That Lets Strangers Run Commands on Your Email Server

The business email platform Zimbra has released a batch of fixes covering a serious command-injection flaw and five other vulnerabilities. No attacks in the wild have been confirmed, but the company is urging every customer to update immediately.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dark server rack in a data centre with a single amber warning light glowing on one rack unit, cool b
Vulnerabilities

CISA gives federal agencies a weekend to patch two Fortinet flaws already under attack

Two critical bugs in Fortinet's FortiSandbox let intruders run code without a password. Attackers are already trying them. Federal agencies have until Sunday to install the fix.

3 min read
Full-frame photoreal editorial shot of a modern laptop on a dark wooden desk, screen glowing with an abstract chat interface and a faint warning glyph reflected
AI Security

Three flaws in OpenClaw AI assistant let attackers steal passwords and run code on your computer

A researcher chained three now-patched bugs in the OpenClaw personal AI assistant into a full takeover of the host machine, starting from a single WhatsApp message.

3 min read
A wall of modern black dome security cameras mounted on a concrete ceiling in a large, dimly lit industrial space, shot from a low angle looking upward, cool bl
Vulnerabilities

80,000 Hikvision Security Cameras Left Wide Open — and Criminals Are Selling the Keys

A critical flaw in one of the world's most popular surveillance cameras has sat unpatched for nearly a year on tens of thousands of devices. Now hackers are trading access on underground forums.

3 min read
Vulnerabilities

Active Exploitation Reported Against Progress Kemp LoadMaster Pre-Auth RCE (CVE-2026-8037)

Threat responders flag in-the-wild attempts against a 9.6-rated OS command injection flaw in the load balancer, days after Progress issued a fixed build.

2 min read
AI Security

GuardFall: A 1970s Shell Trick Walks Past AI Coding Agent Safety Checks

Adversa AI says ten of eleven open-source coding agents fall to a command-substitution bypass that any sysadmin would recognize on sight.

3 min read
AI Security

LiteLLM Command Injection Hits CISA KEV as Attackers Chain to RCE

CVE-2026-42271 lets any authenticated user run shell commands on the LiteLLM proxy. CISA says it's already being exploited.

2 min read
Vulnerabilities

Cisco SD-WAN Manager Has an Unpatched Privilege-Escalation Flaw Under Active Exploitation

A command-injection bug in Catalyst SD-WAN Manager is already being used in the wild. No patch exists yet — and a known espionage group may be involved.

2 min read
© 2026 Threat Vectr