#remote code execution
71 stories taggedremote code execution · page 4 of 5.

GitLab Flaw Lets Any Logged-In User Run Commands on Self-Hosted Servers
Researcher Yuhang Wu published working exploit code against GitLab 18.11.3 that hijacks the server through two booby-trapped notebooks and a diff request.

A Weaponised SVG File Let Researchers Run Commands on Bing's Own Servers
Security testers at XBOW uploaded a booby-trapped image to Bing's image search and ended up with full control over Microsoft's image-processing machines. Two critical patches followed.

Redis Patches Four Code-Execution Bugs After AI Agent Finds Zero-Days
Seven security releases went out on July 23 after researchers used Moonshot AI's Kimi K3 agents to uncover authenticated remote code execution chains in stock Redis builds.

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild
CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

A Poisoned Web Page Was Enough to Hijack Amazon's AI Coding Assistant
Researchers showed that Kiro, Amazon's AI-powered coding tool, could be tricked into running attacker code just by reading a booby-trapped web page.

Hackers Chain Two WordPress Bugs to Hijack Sites Without a Password
The flaw pair, nicknamed wp2shell, lets attackers take over vulnerable WordPress sites remotely. Mass scanning is already underway.

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In
A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

Hackers Start Breaking Into ServiceNow AI Platform Through Critical Flaw CVE-2026-6875
Attackers are exploiting a pre-authentication bug in ServiceNow's flagship platform just days after patches shipped, researchers confirm.

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk
A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

7-Zip Ships Emergency Fix for Flaw That Lets Booby-Trapped Archives Run Code
Version 26.02 patches a heap buffer overflow in XZ decompression. There is no auto-update, so users have to grab it themselves.

A WordPress Bug Lets Strangers Run Code on Your Site. No Login Required.
Every WordPress 6.9 and 7.0 site was exposed until a Friday emergency patch. The fix is being force-installed.

Hackers Are Already Exploiting a Critical Microsoft SharePoint Flaw Patched Just Days Ago
CISA has added a newly patched SharePoint vulnerability to its active-exploitation watchlist, giving US federal agencies just three days to apply the fix.

F5 Fixes Serious Security Flaws in NGINX and BIG-IP
Patches are now available for multiple vulnerabilities in two widely used networking products that could have let attackers take control of systems, crash services, or steal data.

Four Security Firms Patch Serious Flaws in Their Own Products
Tenable, ESET, Tanium, and Trend Micro have all pushed out fixes this month for high- and critical-severity vulnerabilities in tools that businesses rely on to stay secure.

Fortinet, Ivanti, and ServiceNow patch 15 flaws, including a critical no-login attack on ServiceNow's AI platform
A flaw rated 9.5 out of 10 in severity lets criminals run malicious code on ServiceNow systems without needing a password. Twelve Fortinet products and two Ivanti tools also received fixes on the same day.