#remote code execution
53 stories taggedremote code execution · page 3 of 4.

Four Security Firms Patch Serious Flaws in Their Own Products
Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform
A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.

CISA Warns of Active Attacks on SharePoint Servers, Urges Immediate Patching
Three flaws are being exploited to break into on-premises SharePoint, steal cryptographic keys, and plant malware. Two more just disclosed could be next.

Seven Security Flaws Fixed in VMware Avi Load Balancer, One Rated Critical
Broadcom has patched a critical flaw that lets attackers break into a core networking component without a password, plus six more serious bugs found by two outside researchers.

Hackers Are Breaking Into Websites Through Two Popular Joomla Add-Ons
Two widely used plugins for the Joomla website-building platform have critical security flaws that let criminals take full control of a site without needing a password. Patches exist, but attacks started before most site owners knew there was a problem.

HalluSquatting: How AI Hallucinations Are Being Turned Into a Doorway for Malware
Security researchers have found a way to turn a known quirk of AI chatbots into a method for delivering malicious software directly to developers' computers, without hacking the AI itself.

AI Coding Assistants Fooled by Decades-Old File Trick to Attack Developer Machines
A technique as old as Unix itself let researchers plant hidden traps inside innocent-looking code projects, then watch AI tools quietly rewrite the wrong files while developers clicked 'approve'.

Adobe ColdFusion flaw now under attack, Canada's cyber agency warns
A critical bug in Adobe's web platform is being exploited days after patches shipped. Roughly 800 servers sit exposed online.

Popular AI Coding Tool Cursor Has Flaws That Could Let Attackers Run Code on Your Computer
Security researchers found two vulnerabilities in the Cursor AI code editor that could allow an attacker to silently take control of a developer's machine — no click required.

Adobe Rushes Out Fixes for a Dozen Flaws in ColdFusion and Campaign Classic — Six Are as Bad as It Gets
Twelve security holes, six of them rated the highest possible severity, were quietly sitting in two widely used Adobe products. Patches are out. The clock is ticking.

Cursor IDE's Sandbox Cracked by Prompt Injection — No User Interaction Required
Two logic flaws in Cursor's command execution sandbox let attackers escape the isolation layer and run code on the underlying OS. Patches landed in April. The researchers say Cursor isn't alone.

Pre-Auth Root RCE in Progress Kemp LoadMaster: Patch the API Now
CVE-2026-8037 lets an unauthenticated attacker run commands as root via a crafted API request. CVSS 9.8. The vendor has shipped a fix.

Active Exploitation Hits PTC Windchill as Attackers Drop Web Shells on PLM Systems
A critical deserialization flaw in software used by Boeing, Lockheed Martin, and BMW is drawing threat actors toward some of the most sensitive intellectual property in global manufacturing.

Two Critical NGINX Open Source Bugs Open the Door to Remote Code Execution
F5 patches a use-after-free in the HTTP/3 module and a second critical flaw. QUIC-enabled deployments are the immediate concern.

Bucket Squatting in Vertex AI SDK Opened Cross-Tenant RCE Window
A staging-bucket naming flaw in two versions of Google's Vertex AI Python SDK let attackers pre-register a victim's expected bucket and swap in a malicious pickle model before the platform could retrieve the original.