Tag

#remote code execution

53 stories taggedremote code execution · page 3 of 4.

Photoreal news-editorial 16:9 image of a dense tangle of fiber optic cables glowing under pressure in a dark server room, light fragmenting through the cables a
Vulnerabilities

Four Security Firms Patch Serious Flaws in Their Own Products

Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

3 min read
Full-frame 16:9 photoreal editorial image of a dimly lit server rack in a data center, focused on a single rack unit with a glowing amber status LED, shallow de
Vulnerabilities

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform

A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.

3 min read
Photoreal editorial image of a dimly lit server room with rack-mounted enterprise servers, one status LED glowing amber, subtle blue ambient light, focus on cab
Vulnerabilities

CISA Warns of Active Attacks on SharePoint Servers, Urges Immediate Patching

Three flaws are being exploited to break into on-premises SharePoint, steal cryptographic keys, and plant malware. Two more just disclosed could be next.

3 min read
Photoreal news-editorial style, 16:9, close-up of glowing server rack hardware in a dark data center, cool blue and amber lighting, shallow depth of field, no p
Vulnerabilities

Seven Security Flaws Fixed in VMware Avi Load Balancer, One Rated Critical

Broadcom has patched a critical flaw that lets attackers break into a core networking component without a password, plus six more serious bugs found by two outside researchers.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

Hackers Are Breaking Into Websites Through Two Popular Joomla Add-Ons

Two widely used plugins for the Joomla website-building platform have critical security flaws that let criminals take full control of a site without needing a password. Patches exist, but attacks started before most site owners knew there was a problem.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
AI Security

HalluSquatting: How AI Hallucinations Are Being Turned Into a Doorway for Malware

Security researchers have found a way to turn a known quirk of AI chatbots into a method for delivering malicious software directly to developers' computers, without hacking the AI itself.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
AI Security

AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines

A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

3 min read
Full-frame photoreal editorial image of a dimly lit server rack in a corporate data centre, one server bay glowing with a warning-red status LED while others sh
Vulnerabilities

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns

A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

3 min read
A close-up top-down view of a mechanical keyboard on a dark desk, its keys softly lit by the cool blue glow of a monitor displaying abstract cascading lines of
Vulnerabilities

Popular AI Coding Tool Cursor Has Flaws That Could Let Attackers Run Code on Your Computer

Security researchers found two vulnerabilities in the Cursor AI code editor that could allow an attacker to silently take control of a developer's machine — no click required.

3 min read
Extreme close-up of a glowing server rack in a dark data centre, amber and blue indicator lights reflecting off brushed metal chassis, shallow depth of field dr
Vulnerabilities

Adobe Rushes Out Fixes for a Dozen Flaws in ColdFusion and Campaign Classic — Six Are as Bad as It Gets

Twelve security holes, six of them rated the highest possible severity, were quietly sitting in two widely used Adobe products. Patches are out. The clock is ticking.

3 min read
AI Security

Cursor IDE's Sandbox Cracked by Prompt Injection — No User Interaction Required

Two logic flaws in Cursor's command execution sandbox let attackers escape the isolation layer and run code on the underlying OS. Patches landed in April. The researchers say Cursor isn't alone.

2 min read
Vulnerabilities

Pre-Auth Root RCE in Progress Kemp LoadMaster: Patch the API Now

CVE-2026-8037 lets an unauthenticated attacker run commands as root via a crafted API request. CVSS 9.8. The vendor has shipped a fix.

3 min read
Vulnerabilities

Active Exploitation Hits PTC Windchill as Attackers Drop Web Shells on PLM Systems

A critical deserialization flaw in software used by Boeing, Lockheed Martin, and BMW is drawing threat actors toward some of the most sensitive intellectual property in global manufacturing.

2 min read
Vulnerabilities

Two Critical NGINX Open Source Bugs Open the Door to Remote Code Execution

F5 patches a use-after-free in the HTTP/3 module and a second critical flaw. QUIC-enabled deployments are the immediate concern.

2 min read
AI Security

Bucket Squatting in Vertex AI SDK Opened Cross-Tenant RCE Window

A staging-bucket naming flaw in two versions of Google's Vertex AI Python SDK let attackers pre-register a victim's expected bucket and swap in a malicious pickle model before the platform could retrieve the original.

2 min read
© 2026 Threat Vectr