#remote code execution
72 stories taggedremote code execution · page 2 of 5.

N-able rushes emergency fix for critical flaw in tool used to run thousands of company networks
A maximum-severity bug in N-able's N-central platform lets attackers run their own code on unpatched servers. Nearly 1,500 sit exposed on the public internet.

HPE patches critical flaw in Aruba network switches that lets attackers take over without a password
A buffer overflow in ArubaOS-CX, tracked as CVE-2026-73749, lets unauthenticated attackers run code on switches used by hospitals and data centres.

Hackers Are Breaking Into Switchvox Phone Systems Through a Critical Flaw
A severe bug in Sangoma's business phone platform lets attackers run code on servers without a password. Exploitation is already happening.

Hackers Are Actively Exploiting a Critical Flaw in the AI Builder Langflow
A software vulnerability scored at near-maximum severity is being used right now to break into Langflow servers and steal credentials. Over 360 attacks hit tracking sensors in the UK in a single day.

WatchGuard Patches Five Critical Flaws That Could Let Attackers Seize Control Remotely
WatchGuard has fixed more than two dozen vulnerabilities in its firewall software and management tools, including five rated 9.3 out of 10 in severity.

Hackers Are Actively Exploiting a Near-Perfect-Score Flaw in Ruby on Rails
A critical vulnerability in the popular web framework lets criminals read files off a server and run their own code on it, and the official patch only closes half the door.

PaperCut Rushes Out Second Fix as Attackers Chain Bugs to Run Code
A newly patched flaw in the widely used print management software is being actively exploited, and PaperCut has shipped emergency hardening on top of the original patch.

Bluetooth to Root: Researcher Finds Two Ways Into Unitree's G1 Humanoid
Two flaws in Unitree's G1 EDU robot hand an attacker full control of the machine, and one of them needs nothing but a Bluetooth signal.

Next.js Rushes Fixes for Two Critical Bugs That Let Attackers Run Code Without Logging In
Vercel patched flaws in the popular web framework that could be triggered by a booby-trapped image or a rigged URL on Windows servers.

Hackers Are Now Chaining Two SharePoint Bugs to Take Over Servers
A public proof-of-concept turned into live attacks within a day, and researchers are watching the full two-step break-in play out in honeypots.

Two unpatched flaws in Kaltura's video player let attackers read files and run code
CERT/CC has gone public with a pair of bugs in Kaltura's mwEmbed library. Both trace back to the same old web-security sin: trusting user-supplied serialized data.

CISA: Hackers Are Actively Exploiting a Patched Gitea Flaw That Lets Them Run Malicious Commands
A security hole in Gitea, a widely used code-hosting platform, is being exploited in the wild. A patch has existed since late July, but federal agencies have until August 28 to apply it.

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity
A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

Microsoft Confirms Critical Entra ID Flaw Was Exploited, Says No Customer Action Needed
Redmond patched a perfect-10 remote code execution bug in its cloud identity service and says the fix was applied on its side.

Elementor Pro flaw let attackers plant executable files on WordPress sites
A bug in the paid version of the popular WordPress builder let strangers upload PHP files and run code on the server. A patch is out.