#command-injection
8 stories taggedcommand-injection.

Zimbra mail server flaw exploited in the wild, Microsoft warns after weeks of quiet attacks
Microsoft Threat Intelligence says attackers used a specially crafted email to hijack Zimbra Collaboration Suite mail servers, drop web shells and steal mailbox data, before the flaw was patched.

CISA Flags Kemp LoadMaster Flaw After Nearly 800 Exploit Attempts
A critical command-injection bug in Progress Kemp LoadMaster is being actively abused. Federal agencies have three weeks to patch.

Arista rushes fix for VeloCloud flaw already being used in attacks
A perfect-10 command injection bug in on-premises VeloCloud Orchestrator lets anyone on the network take over the box. Attackers found it first.

Zimbra Patches Six Security Flaws, Including a Bug That Lets Strangers Run Commands on Your Email Server
The business email platform Zimbra has released a batch of fixes covering a serious command-injection flaw and five other vulnerabilities. No attacks in the wild have been confirmed, but the company is urging every customer to update immediately.

CISA gives federal agencies a weekend to patch two Fortinet flaws already under attack
Two critical bugs in Fortinet's FortiSandbox let intruders run code without a password. Attackers are already trying them. Federal agencies have until Sunday to install the fix.

Three flaws in OpenClaw AI assistant let attackers steal passwords and run code on your computer
A researcher chained three now-patched bugs in the OpenClaw personal AI assistant into a full takeover of the host machine, starting from a single WhatsApp message.

80,000 Hikvision Security Cameras Left Wide Open — and Criminals Are Selling the Keys
A critical flaw in one of the world's most popular surveillance cameras has sat unpatched for nearly a year on tens of thousands of devices. Hackers are now trading access on underground forums.

GuardFall: A 1970s Shell Trick Walks Past AI Coding Agent Safety Checks
Adversa AI says ten of eleven open-source coding agents fall to a command-substitution bypass that any sysadmin would recognize on sight.