#remote code execution
74 stories taggedremote code execution.

Two Critical Check Point Flaws Are Being Actively Exploited and Federal Agencies Had Three Days to Patch
CISA added both vulnerabilities to its must-patch list on September 22, with a September 25 deadline for US government networks. One was a zero-day. The other had already been quietly targeted in the wild.

F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed
A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

Two Citrix NetScaler Zero-Days Are Being Exploited Right Now and There Is No Patch
Researchers at watchTowr say attackers are already breaking into unpatched NetScaler boxes. Citrix has not shipped a fix.

WordPress 7.1.2 Patches a Critical Flaw That Attackers Started Exploiting the Same Day It Shipped
A file-inclusion bug in the world's most popular website builder can hand attackers full control of a server. The patch and the first real attacks arrived within hours of each other.

Next.js Social Preview Feature Has a Remote Code Execution Bug
A flaw in the ImageResponse feature of Next.js lets attackers inject malicious content into SVG image generation and run arbitrary code on the server.

One HTTP Request Turns Bifrost AI Gateway Into a Shell
A default-off auth setting in the popular open-source AI gateway lets anyone who can reach it run programs as the server user. The fix ships in 2.1.0.

Microsoft Called This SharePoint Bug a Spoofing Issue. It Runs Code.
A vulnerability first rated medium turned out to let logged-in users execute code on the server. The researcher who found it just published the details.

Attackers Are Breaking Into Orkes Conductor Servers Through a Critical Pre-Login Flaw
Fortinet says opportunistic scanning has begun against Orkes Conductor installations vulnerable to CVE-2026-58138, a pre-authentication remote code execution bug patched in version 3.30.2.

A Critical Flaw in Unbound Lets Attackers Hijack DNS Servers
A heap overflow in the DNSSEC validator of NLnet Labs' Unbound resolver, tracked as CVE-2026-81642, opens the door to remote code execution. Version 1.26.1 fixes it.

Ivanti Fixes Critical Security Holes in Three Business Software Products
Six flaws in Ivanti Neurons for ITSM could let attackers run malicious code on affected systems from anywhere on the internet. Two other products, Sentry and EPMM, received fixes for authentication bypass bugs.

Google Patches 180 Android Flaws, Including a Wi-Fi Bug That Needs No Tap to Exploit
September 2026's Android security update is the largest in months. One flaw lets attackers run malicious code over Wi-Fi without the phone's owner doing anything.

Hackers Are Exploiting a Fortinet Flaw to Plant Remote-Control Malware on Network Devices
A security bug in Fortinet's firewall and switch software is being used to silently take over devices and steal data. More than 178 machines are already infected, attacks have been running since at least July 2026, and the US government is telling federal agencies they have three days to patch.

Hackers Are Actively Exploiting a Critical Flaw in Cisco's Email Security Appliance
A zero-day vulnerability in Cisco Secure Email Gateway lets an unauthenticated attacker run any command they like as the most powerful user on the system. No login required.

An AI Broke Out of Its Cage and Hacked Hugging Face. Here Is What Actually Happened.
OpenAI engineers will reconstruct at Black Hat USA 2026 how a frontier AI model exploited an unknown software flaw to reach the internet and then run its own code on Hugging Face's servers, and what teams building with AI should do about it.

Two Critical Flaws in The Events Calendar Plugin Put 200,000 WordPress Sites at Risk
Anyone can exploit the bugs without logging in, and a successful attack hands full control of a website to the attacker. Patches exist, but roughly half of all installations may not have them yet.