#remote code execution
71 stories taggedremote code execution · page 3 of 5.

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer
A newly public security hole in popular mapping software drew hundreds of attack attempts within hours. No fix exists yet.

Millions of Belgians' IDs and bank accounts were wide open through a government browser extension
A browser extension used by more than 2 million Belgians to log into government and banking websites contained flaws so serious that criminals could have stolen identities, hijacked payment cards, and taken full control of victims' computers. The vendor fixed the problems on 22 July.

SonicWall Patches Critical Flaws in a Security Platform It Already Retired
Two vulnerabilities scored near-perfect danger ratings and could let criminals break into systems without a password. One of the affected products was officially shut down last October.

Zoom Had a Flaw That Let Hackers Take Over Your Computer During a Meeting, Without You Clicking Anything
A vulnerability in Zoom's annotation feature gave attackers a direct path to run code on any participant's machine. Patches are out now.

Two Million Belgians Exposed by Flaws in the Software They Use to Sign Legal Documents Online
Security researcher James Arnott found that Belgium's most-used digital identity tool could let any malicious website steal a user's PIN, forge their electronic signature, or quietly run attack code on their computer, all without the victim clicking anything suspicious.

A Safety Recall on a Truck Brake Controller Was Also Quietly Fixing Security Flaws
NMFTA researchers found that a Bendix EC-80 recall patched serious software vulnerabilities, including one that could let an attacker run their own code on a commercial truck's braking system, with no cybersecurity advisory ever issued.

Hackers Are Actively Exploiting a Critical Flaw in JetBrains TeamCity
A software tool used by thousands of development teams has a severe security hole that attackers are already using. The US government is giving federal agencies three days to fix it.

Three Patched Flaws in Paperclip AI Platform Could Let Attackers Run Code on Developer Machines
Researchers found that self-registering for a free account was enough to start a chain of attacks ending in full remote control of a server.

Adobe Patches Perfect-10 Flaw in Campaign Classic That Lets Attackers Run Code Remotely
A permission check gone wrong in Adobe's marketing automation platform could hand attackers full control, with no user interaction needed.

The 'RufRoot' Flaw: Why Patching Alone Won't Fix This AI Security Hole
A perfect-severity bug in the Ruflo AI platform let anyone walk in without a password, steal credentials, and quietly poison the system's memory. The poisoning can linger even after the patch is applied.

Critical Flaw in Ruflo AI Harness Lets Anyone Run Commands on Your Server
A maximum-severity bug in the open-source Ruflo tool, used with Claude Code and Codex, scores a perfect 10.0 and requires no login to exploit.

Gitea Patches Critical Flaw That Lets Repo Users Run Shell Commands
CVE-2026-60004 carries a 9.8 CVSS score and is fixed in Gitea 1.27.1. Anyone running an older self-hosted instance should update now.

Every AI Browser on the Market Can Be Hacked, Researchers Warn
Security firm Zenity says agentic browsers have stripped out decades-old web protections to work across multiple sites, and every product tested could be taken over by a malicious social-media post or newsletter link.

JetBrains Patches Critical TeamCity Flaw That Let Attackers Run Commands Without Logging In
CVE-2026-63077 carries a 9.8 severity score and affects every on-premises version of the build server. Cloud customers were patched automatically.

Anyone Can Now Attack Unpatched vBulletin Forums Thanks to Public Exploit Code
Working exploit code for a critical vBulletin flaw is out in the open, and it lets a stranger run commands on the server without logging in.