Tag

#RCE

24 stories taggedRCE.

Photoreal news-editorial overhead view of a developer workstation with a glowing terminal window and an open code editor, abstract cloud-shaped server racks in
Vulnerabilities

Weekly Roundup: Trusted Software Turned Against Defenders, Plus a Critical Gogs Flaw

From signed drivers hijacked to disable antivirus tools, to a code-execution bug in the Gogs source-code platform, this week's threats show how attackers keep lowering the bar.

4 min read
Photoreal news-editorial overhead shot of a darkened security operations center desk, multiple monitors glowing blue with abstract vulnerability dashboards and
Vulnerabilities

Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected

A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of thousands of WordPress sites at risk of full takeover.

4 min read
A digital shield protecting a SharePoint server
Vulnerabilities

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet

CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

4 min read
Vulnerabilities

Unpatched Argo CD Flaw Turns Your GitOps Engine Into a Deployment Backdoor

A gRPC endpoint that skips authentication, network policies off by default, and Redis credentials sitting in the environment. Synacktiv's research shows how one compromised pod can become a supply-chain pivot.

3 min read
Vulnerabilities

No Patch, No CVE: Argo CD Repo-Server Flaw Opens Door to Kubernetes Cluster Takeover

Synacktiv reported the unauthenticated RCE bug to maintainers. There's still no fix.

3 min read
Vulnerabilities

Langflow RCE Is Back on the Menu — This Time for a Monero Miner

Attackers are still pillaging exposed Langflow instances through CVE-2026-33017, turning forgotten AI workflow servers into XMR mining rigs.

3 min read
Vulnerabilities

PTC Windchill RCE Lands on CISA's KEV After Web Shells Show Up in the Wild

A pre-auth code execution bug in PTC's PLM stack is being actively exploited. If you run Windchill or FlexPLM, the patch clock started a while ago.

2 min read
Vulnerabilities

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain

CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

2 min read
Vulnerabilities

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications

A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

2 min read
Vulnerabilities

PixelSmash Bug in FFmpeg Decoder Opens RCE Path on Jellyfin

A newly disclosed flaw in FFmpeg's PixletVideo decoder enables remote code execution against Jellyfin under specific conditions, with denial-of-service fallout for Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

3 min read
AI Security

AutoJack: A Drive-By to RCE Hiding in AutoGen Studio's Dev UI

A prototyping tool nobody treated as production becomes a one-click code execution chain. The fix is out. The pattern is not.

2 min read
AI Security

AutoJack: When the AI Browser Becomes the Initial Access Broker

Microsoft researchers describe an exploit chain that turns an agentic browser into a one-click path from web page to host process execution.

3 min read
AI Security

AutoJack Exploit in Web-Enabled AI Agents: Bypassing Localhost Security

Microsoft uncovers RCE vulnerability in AutoGen Studio through local AI agent misuse.

2 min read
Vulnerabilities

Splunk Enterprise RCE Flaw Under Active Exploitation, CISA Gives Feds 72 Hours

CVE-2026-20253 allows unauthenticated remote code execution in Splunk Enterprise. Attackers didn't wait long.

2 min read
AI Security

Three-Bug Chain Turns Any LiteLLM User Into Root on the AI Gateway

A default low-privilege account on the popular open-source LLM proxy can escalate to admin and execute code, exposing every provider key the gateway holds.

2 min read
© 2026 Threat Vectr