Tag

#RCE

24 stories taggedRCE · page 2 of 2.

Vulnerabilities

Splunk Patches CVE-2026-20253, a 9.8-Rated Unauthenticated RCE in Enterprise

The advisory covers Splunk Enterprise builds below 10.2.4 and 10.0.7, with fixed versions now available.

2 min read
AI Security

LangGraph Patches Three Bugs, Including an SQLi-to-RCE Chain in Self-Hosted Agents

The framework underpinning a wave of multi-agent AI deployments shipped fixes for a flaw chain that let attackers pivot from SQL injection to code execution on self-hosted nodes.

3 min read
Vulnerabilities

ShinyHunters Rode a PeopleSoft Zero-Day Into University Networks

A CVSS 9.8 RCE flaw in Oracle PeopleSoft gave UNC6240 a two-week head start before Oracle even confirmed the bug existed.

2 min read
Vulnerabilities

Microsoft's October Dump: 206 CVEs, Three Already Public

A record Patch Tuesday hauls in 39 Critical bugs and a trio of zero-days that were knocking around before the fix shipped.

2 min read
Vulnerabilities

protobuf.js Ships Six Bugs That Turn Schemas Into RCE Triggers

A single malicious descriptor is enough. Node.js services parsing untrusted Protobuf are the obvious blast radius.

2 min read
Vulnerabilities

Everest Forms Pro RCE Under Active Exploitation on WordPress Sites

CVE-2026-3300 carries a 9.8 CVSS. Attackers are using it to take over sites running unpatched versions of the premium form-builder plugin.

3 min read
AI Security

One Click, Full Shell: Flowise MCP Flaw Scores 9.9 CVSS

A sandboxing failure in Flowise's MCP stdio implementation lets an attacker execute arbitrary OS commands with process-level privileges — and the patches so far don't close the hole.

2 min read
Vulnerabilities

Authenticated RCE in Gogs Hits CVSS 9.4 — and There's No CVE Yet

A critical flaw in the self-hosted Git service lets any logged-in account execute arbitrary code on the server. The auth bar is low. The blast radius isn't.

2 min read
Vulnerabilities

SharePoint's latest RCE bug hands attackers the keys with no extra paperwork

CVE-2026-45659 is a deserialization flaw that doesn't ask for much — and that's exactly why Microsoft is shipping fixes across every supported SharePoint Server build.

2 min read
© 2026 Threat Vectr