A serious vulnerability has been discovered in vBulletin, a popular forum software, which allows attackers to execute arbitrary PHP code without needing authentication. This flaw arises from how the software handles template rendering, making it particularly dangerous. Users of vBulletin should be on high alert, as the vulnerability could potentially allow unauthorized access to sensitive data or lead to further exploitation of their systems. The vBulletin team has released a fix to address this issue, and it is crucial for all users to apply the patch promptly to secure their forums. Given the nature of this vulnerability, it is essential for site administrators to regularly monitor their systems for any signs of exploitation and ensure they are running the latest software versions.
Articles tagged "RCE"
Found 121 articles
Help Net Security
JetBrains has addressed a significant security vulnerability (CVE-2026-63077) in its TeamCity On-Premises software that could allow attackers to execute code without authentication. This flaw affects users who host TeamCity servers themselves, making it crucial for administrators to act swiftly. JetBrains is urging these users to upgrade their installations immediately to protect against potential exploitation. For those unable to upgrade right away, the company has provided a security patch plugin as a temporary fix. Given TeamCity's popularity as a continuous integration and delivery tool, the urgency of this update is clear, as unpatched systems could become prime targets for cyberattacks.
Hackers are exploiting a serious vulnerability in the FastJson open-source Java library that allows for remote code execution without needing user interaction or elevated permissions. This puts numerous U.S. companies at risk, as they may be using FastJson in their applications. Researchers have confirmed that the vulnerability is actively being targeted, making it urgent for affected organizations to address the issue. The ability for attackers to execute code remotely without any user action raises significant security concerns, as it could lead to data breaches or system compromises. Companies using this library should take immediate steps to secure their systems and stay updated on any patches or fixes released to mitigate this threat.
Researchers have identified a serious security vulnerability in GitLab that allows remote code execution (RCE) through a combination of two bugs in the Oj JSON parser, which is used in Ruby. This issue affects authenticated users on unpatched versions of GitLab and can be exploited via Jupyter notebook diffs. The exploit, published by Depthfirst researchers on July 24, demonstrates how attackers could potentially execute arbitrary commands on the affected systems. Users of GitLab should prioritize applying the necessary patches to protect their installations from this vulnerability, as it poses a significant risk to data integrity and security.
Help Net Security
Last week, it was reported that a pre-authentication remote code execution (RCE) vulnerability in ServiceNow was actively exploited in the wild. This vulnerability allows attackers to execute arbitrary code on affected systems without needing to authenticate, posing significant risks to organizations using the platform. In a separate incident, Hugging Face, a popular AI community, experienced a data breach, although details about the extent of the breach and the data compromised have not been fully disclosed. These incidents highlight ongoing security challenges for companies leveraging AI and cloud services, as they must remain vigilant against potential exploits that can have serious consequences for their operations and data integrity.
Attackers are exploiting a serious vulnerability in Fastjson, a JSON library developed by Alibaba for Java applications, particularly those using Spring Boot. This flaw, identified as CVE-2026-16723, allows unauthorized code execution with the privileges of the Java process, posing significant risks to affected systems. The vulnerability has a high severity rating of 9.0, indicating it could lead to severe consequences if not addressed. Currently, there are no patches available to fix this issue, which increases the urgency for developers and organizations using Fastjson to take immediate protective measures. Security firms have reported that this vulnerability is being actively exploited, making it critical for users to assess their systems and implement necessary safeguards.
The Hacker News
Security researchers have released exploit code for a vulnerability in GitLab that allows authenticated users to execute commands as the 'git' user on certain self-managed servers. This flaw affects GitLab version 18.11.3 and earlier, which had a patch issued on June 10, 2023. If a user can push to a project, they can exploit the vulnerability by committing a specially crafted Jupyter notebook. This action reveals sensitive heap memory data, enabling unauthorized command execution. Organizations using vulnerable versions of GitLab should prioritize applying the patch to prevent potential abuse of this exploit, especially in environments where multiple users have access to project repositories.
Researchers have discovered multiple remote code execution (RCE) vulnerabilities in several versions of Redis, a widely used in-memory data structure store. The vulnerabilities affect Redis versions 6.2.22, 7.4.9, 8.6.4, and 8.8.0, with specific exploitation chains requiring commands like RESTORE, EVAL, and XGROUP. Redis confirmed that these memory flaws could allow attackers to execute arbitrary code remotely. In response, Redis released seven security updates on July 23 to address these issues, including versions 6.2.23, 7.2.15, and 7.4.10. Users of these affected versions need to update their systems promptly to protect against potential exploitation.
Help Net Security
Attackers are actively exploiting a serious remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-50522. This vulnerability allows them to extract the IIS machine keys from on-premise SharePoint servers, enabling long-term access to the compromised systems. Following the release of public exploit code, researchers from WatchTowr reported successful attacks occurring just hours later. Companies using on-premise SharePoint installations need to be particularly vigilant, as the stolen machine keys can facilitate ongoing unauthorized access. It's crucial for organizations to patch this vulnerability promptly and take additional measures to secure their machine keys to prevent future exploitation.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive for U.S. government agencies to urgently address a vulnerability in the Langflow visual framework, which is used for creating AI agents. This flaw is currently being actively exploited, meaning attackers are taking advantage of it to potentially compromise systems. Agencies are being urged to prioritize applying patches to safeguard their operations from these threats. The situation is critical as the exploitation of this vulnerability could lead to unauthorized access and control over sensitive systems. Timely action is essential to prevent significant security breaches and protect government data.
Security Affairs
A serious remote code execution (RCE) vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, is currently being exploited by attackers. This vulnerability has a CVSS score of 9.8, indicating its severity. It was patched during Microsoft's July 2026 Patch Tuesday, but following the release of public proof-of-concept (PoC) exploit code, researchers from watchTowr have observed active exploitation in the wild. Organizations using SharePoint need to ensure they have applied the latest updates to protect against potential breaches. The situation underscores the urgency for companies to stay current on security patches to mitigate risks associated with known vulnerabilities.
Hackers are taking advantage of a serious vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, which allows them to steal machine keys. This means that even if the affected servers are patched, attackers can still maintain access to these systems. The flaw is critical, and its exploitation poses a significant risk to organizations using SharePoint, potentially leading to unauthorized access to sensitive information. Companies using SharePoint should take immediate action to secure their systems and monitor for any suspicious activity. The ongoing exploitation of this vulnerability highlights the need for vigilance in securing enterprise software against such threats.
The Hacker News
A serious vulnerability in Microsoft SharePoint Server, identified as CVE-2026-50522, is currently being exploited in the wild. This flaw, which has a CVSS score of 9.8, allows attackers to execute arbitrary code on affected systems through deserialization of untrusted data. The vulnerability was patched by Microsoft during its July 2026 Patch Tuesday update but has since been targeted by malicious actors. Organizations using SharePoint need to prioritize applying the latest security updates to protect against potential unauthorized access and exploitation. It's crucial for administrators to stay vigilant and monitor their systems for any signs of compromise.
A serious vulnerability in ServiceNow's AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This flaw allows for unauthenticated remote code execution on self-hosted instances of the platform. Researchers from Searchlight Cyber disclosed the vulnerability on July 14, 2023, and ServiceNow promptly released patches for affected systems on the same day. However, reports indicate that attacks exploiting this flaw began shortly after, on July 17. Organizations using self-hosted ServiceNow instances need to apply the patches immediately to protect against potential breaches, as the vulnerability poses a significant risk to their data and operations.
A critical vulnerability in the ServiceNow AI Platform, identified as CVE-2026-6875, is being actively exploited by attackers. This pre-authentication code injection flaw allows unauthenticated users to escape the platform's script sandbox and execute arbitrary code on targeted instances. Researchers from Searchlight Cyber discovered this vulnerability and reported it to ServiceNow in early April 2026. The exploitation of this vulnerability poses significant risks to organizations using the ServiceNow AI Platform, as it could lead to unauthorized access and control over sensitive workflows and data. Companies are urged to take immediate action to safeguard their systems against potential attacks.