Tag

#remote code execution

72 stories taggedremote code execution · page 2 of 5.

An emergency response situation in an IT operations center with multiple screens showing N-central platform alerts, critical severity warnings flashing, exposed
Vulnerabilities

N-able rushes emergency fix for critical flaw in tool used to run thousands of company networks

A maximum-severity bug in N-able's N-central platform lets attackers run their own code on unpatched servers. Nearly 1,500 sit exposed on the public internet.

3 min read
A data center equipment room with HPE Aruba network switches stacked in a rack, warning alert lights illuminated, representing vulnerability exposure in critica
Vulnerabilities

HPE patches critical flaw in Aruba network switches that lets attackers take over without a password

A buffer overflow in ArubaOS-CX, tracked as CVE-2026-73749, lets unauthenticated attackers run code on switches used by hospitals and data centres.

3 min read
A business telephone system data center with Sangoma equipment racks, security alerts visible on monitoring stations indicating unauthorized code execution atte
Vulnerabilities

Hackers Are Breaking Into Switchvox Phone Systems Through a Critical Flaw

A severe bug in Sangoma's business phone platform lets attackers run code on servers without a password. Exploitation is already happening.

3 min read
A hacker's workstation with multiple displays showing attack logs, credential theft timelines, and server breach patterns mapped across a digital interface, red
Vulnerabilities

Hackers Are Actively Exploiting a Critical Flaw in the AI Builder Langflow

A software vulnerability scored at near-maximum severity is being used right now to break into Langflow servers and steal credentials. Over 360 attacks hit tracking sensors in the UK in a single day.

3 min read
A firewall management console displaying multiple critical vulnerability alerts at severity level 9
Vulnerabilities

WatchGuard Patches Five Critical Flaws That Could Let Attackers Seize Control Remotely

WatchGuard has fixed more than two dozen vulnerabilities in its firewall software and management tools, including five rated 9.3 out of 10 in severity.

3 min read
A Ruby on Rails framework logo-adjacent visual of server logs cascading down, with red error indicators and file-access permission hierarchies highlighted
Vulnerabilities

Hackers Are Actively Exploiting a Near-Perfect-Score Flaw in Ruby on Rails

A critical vulnerability in the popular web framework lets criminals read files off a server and run their own code on it, and the official patch only closes half the door.

3 min read
Office printers and print management equipment arranged in a corporate environment, with network cables and digital screens displaying status information and re
Vulnerabilities

PaperCut Rushes Out Second Fix as Attackers Chain Bugs to Run Code

A newly patched flaw in the widely used print management software is being actively exploited, and PaperCut has shipped emergency hardening on top of the original patch.

3 min read
A humanoid robot hand in close focus with intricate mechanical joints and articulated fingers, positioned near a small device or Bluetooth transmitter suggestin
Vulnerabilities

Bluetooth to Root: Researcher Finds Two Ways Into Unitree's G1 Humanoid

Two flaws in Unitree's G1 EDU robot hand an attacker full control of the machine, and one of them needs nothing but a Bluetooth signal.

4 min read
A web server error page with booby-trapped image file thumbnails and malicious URL bars highlighted in red against lines of Next
Vulnerabilities

Next.js Rushes Fixes for Two Critical Bugs That Let Attackers Run Code Without Logging In

Vercel patched flaws in the popular web framework that could be triggered by a booby-trapped image or a rigged URL on Windows servers.

4 min read
A network diagram displayed on a security operations center screen showing attack chain progression through server nodes, with two highlighted vulnerabilities c
Vulnerabilities

Hackers Are Now Chaining Two SharePoint Bugs to Take Over Servers

A public proof-of-concept turned into live attacks within a day, and researchers are watching the full two-step break-in play out in honeypots.

3 min read
A video player interface rendered in a web browser window, displaying code injection points where serialized data is being deserialized without validation, with
Vulnerabilities

Two unpatched flaws in Kaltura's video player let attackers read files and run code

CERT/CC has gone public with a pair of bugs in Kaltura's mwEmbed library. Both trace back to the same old web-security sin: trusting user-supplied serialized data.

3 min read
A code repository interface showing file directories and command execution logs, with a highlighted patch notice dated late July and a federal agency seal in th
Vulnerabilities

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands

A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

3 min read
A Microsoft security patch notification dashboard showing 22 fixes rolling out across cloud services, with six critical severity indicators glowing red at maxim
Vulnerabilities

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity

A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

3 min read
Microsoft cloud infrastructure with an Entra ID vulnerability being remotely exploited, followed by a patch installation completing on the server side
Identity & Access

Microsoft Confirms Critical Entra ID Flaw Was Exploited, Says No Customer Action Needed

Redmond patched a perfect-10 remote code execution bug in its cloud identity service and says the fix was applied on its side.

3 min read
A WordPress admin dashboard displaying a plugin interface with upload fields and file manager sections, with a warning banner about unauthorized file access vis
Vulnerabilities

Elementor Pro flaw let attackers plant executable files on WordPress sites

A bug in the paid version of the popular WordPress builder let strangers upload PHP files and run code on the server. A patch is out.

4 min read
© 2026 Threat Vectr