Tag

#remote code execution

53 stories taggedremote code execution · page 4 of 4.

AI Security

Langflow's Unauthenticated File-Write Flaw Is Being Exploited — Patch Dropped 73 Days Ago

CVE-2026-5027 lets attackers write files to arbitrary paths on exposed servers, and because Langflow ships with login disabled by default, exploitation requires exactly zero credentials.

3 min read
Vulnerabilities

Ivanti Sentry Carries Two Critical Bugs — One a Perfect 10 — Enabling Full Appliance Takeover

A pair of unauthenticated flaws in the mobile gateway give attackers a clear path to root. Exploit code is already public.

2 min read
Vulnerabilities

Six Flaws in protobuf.js Turn Serialized Schemas Into Execution Vectors

The JavaScript Protocol Buffers library — pulled 50 million times a week — ships patches for a cluster of CVEs that let attackers use schema metadata to run arbitrary code inside Node.js processes.

2 min read
Vulnerabilities

Schema as Weapon: Six Flaws in protobuf.js Open a Path to Remote Code Execution

Cyera researchers found that protobuf.js — pulled into apps 50 million times a week — will, under exploitable conditions, turn schema metadata into running code.

2 min read
AI Security

Silent RCE in Hugging Face Transformers Hides Behind a Single Config Field

CVE-2026-4372 lets an attacker own any machine that loads a poisoned model — no warnings, no prompts, no trace. The trust_remote_code flag didn't help.

2 min read
Vulnerabilities

Redis Patches Two-Year-Old Use-After-Free Surfaced by Autonomous AI Bug Hunter

CVE-2026-23479 sat in the blocking-client code from Redis 7.2.0 until the May 5 fixes. An authenticated user could parlay it into arbitrary OS command execution.

2 min read
Vulnerabilities

Exploit Code Goes Public for Critical Flowise One-Click RCE Flaw

A published proof-of-concept puts every self-hosted Flowise deployment at risk of full remote code execution — no authentication required from the attacker, just a malicious chatflow import.

2 min read
Vulnerabilities

Critical Argument Injection Zero-Day in Gogs Puts Self-Hosted Git Servers at Risk

A CVSS 9.4 flaw lets authenticated attackers execute arbitrary code through maliciously named pull-request branches — no patch is available.

2 min read
© 2026 Threat Vectr