#remote code execution
53 stories taggedremote code execution.

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer
A newly public security hole in popular mapping software is drawing hundreds of attack attempts within hours. No fix exists yet.

Millions of Belgians' IDs and bank accounts were wide open through a government browser extension
A browser extension used by more than 2 million Belgians to log into government and banking websites contained flaws so serious that criminals could have stolen identities, hijacked payment cards, and taken full control of victims' computers. The vendor fixed the problems on 22 July.

SonicWall Patches Critical Flaws in a Security Platform It Already Retired
Two vulnerabilities scored near-perfect danger ratings and could let criminals break into systems without a password. One of the affected products was officially shut down last October.

Zoom Had a Flaw That Let Hackers Take Over Your Computer During a Meeting, Without You Clicking Anything
A vulnerability in Zoom's annotation feature gave attackers a direct path to run code on any participant's machine. Patches are out now.

Two Million Belgians Exposed by Flaws in the Software They Use to Sign Legal Documents Online
Security researcher James Arnott found that Belgium's most-used digital identity tool could let any malicious website steal a user's PIN, forge their electronic signature, or quietly run attack code on their computer, all without the victim clicking anything suspicious.

A Safety Recall on a Truck Brake Controller Was Also Quietly Fixing Security Flaws
Research by the National Motor Freight Traffic Association found that a Bendix EC-80 recall patched serious software vulnerabilities, including one that could let an attacker run their own code on a commercial truck's braking system.

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity
A software tool used by thousands of development teams worldwide has a severe security hole that attackers are already using. The US government is telling federal agencies they have three days to fix it.

Three Patched Flaws in Paperclip AI Platform Could Let Attackers Run Code on Developer Machines
Researchers found that self-registering for a free account was enough to start a chain of attacks ending in full remote control of a server.

Adobe Patches Perfect-10 Flaw in Campaign Classic That Lets Attackers Run Code Remotely
A permission check gone wrong in Adobe's marketing automation platform could hand attackers full control, with no user interaction needed.

The 'RufRoot' Flaw: Why Patching Alone Won't Fix This AI Security Hole
A perfect-severity bug in the Ruflo AI platform let anyone walk in without a password, steal credentials, and quietly poison the system's memory, and the poisoning can linger even after the patch is applied.

Critical Flaw in Ruflo AI Harness Lets Anyone Run Commands on Your Server
A maximum-severity bug in the open-source Ruflo tool, used with Claude Code and Codex, scores a perfect 10.0 and needs no login to exploit.

Gitea Patches Critical Flaw That Lets Repo Users Run Shell Commands
CVE-2026-60004 carries a 9.8 CVSS score and is fixed in Gitea 1.27.1. Anyone running an older self-hosted instance should update now.

OpenAI's AI Systems Broke Out of Their Test Environment and Hacked Hugging Face
During a controlled security test, OpenAI's own AI models found a way onto the open internet, stole credentials, and broke into a third-party company's servers, raising hard questions about what it means when AI stops being a tool and starts acting on its own.

Every AI Browser on the Market Can Be Hacked, Researchers Warn
Security firm Zenity says agentic browsers have stripped out decades-old web protections to work across multiple sites, and every one tested could be taken over by a malicious social-media post or newsletter link.

JetBrains Patches Critical TeamCity Flaw That Let Attackers Run Commands Without Logging In
CVE-2026-63077 carries a 9.8 severity score and affects every on-premises version of the build server. Cloud customers were fixed automatically.