Tag

#RCE

21 stories taggedRCE.

A corporate network security gateway or firewall device being examined, with critical vulnerability alerts displayed on adjoining monitors showing password bypa
Vulnerabilities

Check Point Fixes Two Critical VPN Flaws That Could Let Hackers In Without a Password

Both bugs score 9.8 out of 10 and affect the firewall gear that guards corporate networks.

3 min read
A map showing Taiwan and six other countries highlighted, with a network diagram overlaid displaying Gitea repository servers and scanning patterns radiating ou
Threat Intelligence

China-Linked Red Heron Turns Gitea Flaw Into a Seven-Country Break-In Spree

Acronis researchers say the group scanned nearly 1,400 self-hosted code servers and singled out 477 systems in Taiwan.

3 min read
Server racks in a data center with warning lights illuminated, a computer terminal showing Telerik software interface with cryptographic error messages, chains
Vulnerabilities

Public exploit turns Telerik padding-oracle flaw into full server takeover

TantoSec's proof-of-concept chains a cryptographic weakness in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution, but only bites sites in a non-default setup that Progress patched in July.

4 min read
A government geospatial data center with map servers and portal systems, security researchers analyzing code vulnerabilities in the open-source mapping applicat
Vulnerabilities

Two Bugs in GeoNetwork Let Attackers Take Over Government Map Portals

A chain of flaws in the open-source software behind many public geoportals allowed strangers on the internet to run their own code on the server. Fixes landed in July 2026.

3 min read
A WordPress dashboard displaying the Avada theme interface, with a security vulnerability warning overlay showing code injection and unauthorized access pathway
Vulnerabilities

Critical Avada WordPress theme flaw lets attackers hijack sites with no clicks

A six-step bug chain in the popular Avada theme and Fusion Builder plugin, tracked as CVE-2026-18431, hands unauthenticated attackers full control of vulnerable WordPress sites.

3 min read
Close-up of a computer screen displaying system security software with warning alerts and red error indicators flooding the interface, while in the background a
Vulnerabilities

Weekly Roundup: Trusted Software Turned Against Defenders, Plus a Critical Gogs Flaw

Signed drivers hijacked to kill antivirus, a code-execution bug in the Gogs source-code platform, and AI shortening the gap between disclosure and working exploit: this week's threats run on tools defenders already trust.

4 min read
A WordPress dashboard displaying the Forminator plugin panel, with a file upload interface prominently shown and warning symbols indicating the critical vulnera
Vulnerabilities

Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected

A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of hundreds of WordPress sites at risk of full takeover.

3 min read
Server room with multiple rack-mounted machines and blinking indicator lights, highlighting one unit with a red alert status, code scrolling across a monitoring
Vulnerabilities

Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet

CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.

3 min read
Illustration: dense server rack cable management inside a data center
Vulnerabilities

Unpatched Argo CD Flaw Turns Your GitOps Engine Into a Deployment Backdoor

A gRPC endpoint that skips authentication, network policies off by default, and Redis credentials sitting in the environment. Synacktiv's research shows how one compromised pod can become a supply-chain pivot.

3 min read
Illustration: a dimly lit server rack with exposed network cables glowing faintly blue, one cable disconnected and dangling
Vulnerabilities

No Patch, No CVE: Argo CD Repo-Server Flaw Opens Door to Kubernetes Cluster Takeover

Synacktiv reported the unauthenticated RCE bug to maintainers and published without a fix in place.

3 min read
Illustration: a dimly lit server rack with glowing amber status LEDs, faint heat shimmer rising from the top
Vulnerabilities

Langflow RCE Is Back on the Menu — This Time for a Monero Miner

Attackers are still pillaging exposed Langflow instances through CVE-2026-33017, turning forgotten AI workflow servers into XMR mining rigs.

3 min read
Illustration: a dimly lit enterprise server rack in a manufacturing facility
Vulnerabilities

PTC Windchill RCE Lands on CISA's KEV After Web Shells Show Up in the Wild

A pre-auth code execution bug in PTC's PLM stack is being actively exploited. If you run Windchill or FlexPLM, the patch clock started a while ago.

3 min read
Illustration: a dimly lit enterprise telecom server rack with VoIP gateway hardware and blinking amber status LEDs
Vulnerabilities

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain

CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

3 min read
Illustration: A digital representation of software code with the FFmpeg logo subtly integrated into a background of data
Vulnerabilities

FFmpeg Vulnerability 'PixelSmash' Threatens Media Applications

A critical flaw in FFmpeg's MagicYUV decoder reveals the fragility of software supply chains.

3 min read
Illustration: a darkened server rack with one blade pulled partially out
Vulnerabilities

PixelSmash Bug in FFmpeg Decoder Opens RCE Path on Jellyfin

A newly disclosed flaw in FFmpeg's PixletVideo decoder enables remote code execution against Jellyfin media servers under specific conditions, with denial-of-service exposure for Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

3 min read
© 2026 Threat Vectr