#remote code execution
53 stories taggedremote code execution · page 2 of 4.

Anyone Can Now Attack Unpatched vBulletin Forums Thanks to Public Exploit Code
Working exploit code for a critical vBulletin flaw is out in the open, and it lets a stranger run commands on the server without logging in.

GitLab Flaw Lets Any Logged-In User Run Commands on Self-Hosted Servers
A researcher published working exploit code against GitLab 18.11.3 that hijacks the server through two booby-trapped notebooks and a diff request.

A Weaponised SVG File Let Researchers Run Commands on Bing's Own Servers
Security testers at XBOW uploaded a booby-trapped image to Bing's image search and ended up with full control over Microsoft's image-processing machines. Two critical patches followed.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild
CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

A Poisoned Web Page Was Enough to Hijack Amazon's AI Coding Assistant
Researchers showed that Kiro, Amazon's AI-powered coding tool, could be tricked into running attacker code just by reading a booby-trapped web page.

Hackers Chain Two WordPress Bugs to Hijack Sites Without a Password
The flaw pair, nicknamed wp2shell, lets attackers take over vulnerable WordPress sites remotely. Mass scanning is already underway.

WP2Shell: Two WordPress Flaws Let Attackers Take Over Websites Without Logging In
Criminals are actively exploiting a pair of newly discovered security holes in WordPress to seize full control of websites. Tens of millions of sites were at risk, and patching may already be too late for some.

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In
A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

Hackers Start Breaking Into ServiceNow AI Platform Through Critical Flaw CVE-2026-6875
Attackers are exploiting a pre-authentication bug in ServiceNow's flagship platform just days after patches shipped, researchers confirm.

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk
A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

7-Zip Ships Emergency Fix for Flaw That Lets Booby-Trapped Archives Run Code
Version 26.02 patches a heap buffer overflow in XZ decompression. There is no auto-update, so users have to grab it themselves.

A WordPress Bug Lets Strangers Run Code on Your Site. No Login Required.
Every WordPress 6.9 and 7.0 site was exposed until a Friday emergency patch. The fix is being force-installed.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Multiple vulnerabilities in two widely used pieces of networking software could have let attackers take control of systems, crash services, or steal data. Patches are now available.