Articles tagged "RCE"

Found 141 articles

Researchers from Wordfence have discovered that hackers are taking advantage of two serious vulnerabilities in popular WordPress plugins: Super Forms and Elementor Pro. The first vulnerability, identified as CVE-2026-14894, has a CVSS score of 9.8 and allows unauthenticated attackers to upload files of any type due to a lack of file type validation in the Super Forms plugin. This flaw has led to over 440,000 exploit attempts. The Elementor Pro plugin is also affected, although specific details about its vulnerabilities were not provided. This situation is alarming for website owners using these plugins, as successful exploitation can lead to unauthorized access and potential data breaches. Website administrators should take immediate action to secure their sites against these threats.

Read Original
Actively Exploited

Recent reports indicate that SonicWall's SMA 1000 series devices are vulnerable to multiple zero-day exploits, allowing unauthorized remote code execution (RCE). This follows a series of attacks earlier this summer that targeted two other zero-day vulnerabilities in SonicWall's edge devices. The implications of this vulnerability are significant, as it could allow attackers to gain control over affected systems without any authentication. Organizations using these devices need to take immediate action to safeguard their networks, as the vulnerabilities are being actively exploited. Users are advised to monitor for updates from SonicWall and apply patches as soon as they are released to mitigate potential risks.

Read Original

GeoNetwork has addressed two vulnerabilities that could allow attackers to execute remote code without authentication on its geospatial metadata catalog, commonly used by government and agency geoportals. The vulnerabilities were discovered and fixed in versions 4.4.12 and 4.2.17, released on July 8, 2026. This is significant because it exposes systems that rely on GeoNetwork to potential exploitation, which could lead to unauthorized access or control over sensitive data. The details of these vulnerabilities were made public on August 31, 2026, prompting users to update their systems to safeguard against possible attacks. Government agencies and organizations using GeoNetwork should prioritize applying these updates to prevent any exploitation of the vulnerabilities.

Read Original

Forescout Research - Vedere Labs has successfully adapted a pre-authentication remote code execution (RCE) exploit from one model of WAGO programmable logic controller (PLC) to another, using Anthropic's Claude AI to assist in the process. This exploit targets CVE-2021-31886, which involves a stack-based buffer overflow in the Nucleus FTP server when processing the USER command. The researchers were able to execute attacker-supplied ARM shellcode on actual hardware, demonstrating the potential risks associated with this vulnerability. Companies using affected WAGO PLCs need to be aware of this exploit as it poses a significant risk of unauthorized access and control of their systems. This incident serves as a reminder of the vulnerabilities that can exist in industrial control systems and the need for robust security measures.

Read Original

Recent security research has revealed serious vulnerabilities in several popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could allow attackers to bypass authentication, take over accounts, and execute arbitrary code on affected sites. The most critical vulnerability, CVE-2026-76581, has a CVSS score of 9.8, indicating a high level of risk. Website owners using these plugins and themes are strongly advised to take immediate action to secure their sites, as the potential for exploitation is significant. Addressing these vulnerabilities is crucial to protect user data and maintain the integrity of web applications.

Read Original

In recent cybersecurity news, several incidents have emerged that may not have received significant attention. The Manchester Airports Group has suffered a cyberattack, although details about the extent of the breach are still unclear. Additionally, a data breach at Carhartt revealed that some of the leaked information was actually fabricated, raising concerns about the authenticity of compromised data. In the realm of ransomware, U.S. Bank has publicly addressed claims made by a ransomware gang, which suggests that the bank may be dealing with potential threats to its systems. These incidents highlight ongoing vulnerabilities in various sectors and the need for companies to remain vigilant against evolving cyber threats.

Read Original

Security researcher Olivier Laflamme has reported two serious vulnerabilities in the Unitree G1 EDU humanoid robot that allow for root remote code execution (RCE). The vulnerabilities, identified as CVE-2026-76639 and CVE-2026-76640, can be exploited through different paths, including a Bluetooth Low Energy (BLE) method that can give attackers root access to the robot’s Locomotion PC. The first vulnerability involves a network-adjacent route via components called chat_go and bashrunner. This is a significant concern for users of the Unitree G1 EDU, as it opens the door for unauthorized control of the robot, potentially leading to malicious activities. Addressing these flaws is crucial for ensuring the security and reliability of robotic systems, especially in educational and research environments where they are increasingly being used.

Read Original

Vercel has issued security patches for two serious vulnerabilities in the Next.js framework that could allow attackers to execute code remotely without authentication. The first vulnerability arises from the handling of AVIF image files, which can be manipulated to exploit the system. The second flaw is a path traversal issue that affects installations on Windows filesystems, enabling unauthorized access to files. These vulnerabilities are particularly concerning because they can be exploited without any user interaction, putting many applications at risk if they use Next.js. Developers using this framework should prioritize updating to the latest version to mitigate these risks.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies must address a serious remote code execution vulnerability affecting Citrix NetScaler appliances by this Saturday. This flaw is currently being exploited by attackers, which raises urgent concerns for the security of government networks. Citrix NetScaler is widely used for application delivery and load balancing, making it critical for agencies to implement the patch to prevent unauthorized access and potential data breaches. The deadline emphasizes the need for swift action to mitigate risks, as failure to patch could lead to significant security incidents. Agencies are strongly advised to prioritize this update to protect their systems and sensitive information.

Read Original
Critical
Zoneminder

All CISA Advisories

A serious vulnerability has been identified in Zoneminder, a popular surveillance software, affecting versions 1.37.48 and 1.38.3. This flaw allows authenticated users with permission to view events to execute arbitrary commands on the server through an OS command injection in the event export functionality. While no active exploitation has been reported, the potential for remote code execution poses significant risks to users. Zoneminder recommends that users upgrade to version 1.38.3 or later to mitigate this issue. Organizations utilizing this software should act promptly to protect their systems from possible attacks.

Read Original

A serious vulnerability has been discovered in the isolated-vm package, which is commonly used in Node.js applications. This type confusion bug allows attackers to escape the V8 sandbox, potentially leading to remote code execution (RCE) on the host machine. If exploited, the vulnerability could give attackers control over the host process, posing significant risks to any systems relying on this package. Developers using isolated-vm need to be vigilant and apply necessary updates to protect their applications. The situation underscores the importance of regular security audits and patch management in software development.

Read Original

CERT Polska has reported that a critical vulnerability in the Zimbra Collaboration Suite, known as CVE-2026-73570, is being actively exploited by attackers. This flaw allows for unauthenticated remote code execution, posing significant risks to users of the software. The vulnerability was patched on July 20, but the fact that it is now being exploited in the wild raises concerns for organizations that may not have yet applied the update. Affected users are urged to implement the patch immediately to protect their systems from potential breaches. The urgency of this situation highlights the need for timely software updates and vigilance against emerging threats.

Read Original

A serious vulnerability has been discovered in Elementor Pro, a popular WordPress page builder plugin. This flaw allows unauthorized users to upload files and execute remote code, potentially giving attackers control over compromised sites. The issue stems from a flaw in the File Upload module where validation and processing loops do not align correctly. As a result, websites using Elementor Pro could be at risk if they do not address this vulnerability. It's essential for site administrators to update their plugins and ensure proper security measures are in place to prevent unauthorized access.

Read Original

This week, several security vulnerabilities have emerged, highlighting significant risks in trusted software and systems. Notably, Gogs version 10.0 has a remote code execution (RCE) vulnerability that attackers can exploit, while n8n has a similar issue that allows workflows to trigger RCE. Additionally, researchers have noted that signed drivers can be misused to bypass security measures, and a weak header check in certain applications opens further avenues for code execution. These vulnerabilities affect a range of users and organizations that rely on these tools, and the ease of exploitation, especially with the aid of AI, raises alarms about the potential for widespread attacks. Companies should prioritize patching and monitoring their systems to mitigate these risks.

Read Original

A serious vulnerability has been identified in the Elementor Pro plugin for WordPress, which could allow attackers to upload harmful files and execute code remotely on affected servers. This flaw poses a significant risk to websites using this plugin, as it could lead to unauthorized access and control over the site. The issue affects versions of Elementor Pro prior to the fix, and website owners are urged to update their plugins immediately to protect against potential exploitation. Given the popularity of WordPress and Elementor Pro, many sites could be at risk, making timely action essential for security. Users should ensure they are using the latest version to mitigate this vulnerability and safeguard their online presence.

Read Original
Page 1 of 10Next