Tag

#Remote Code Execution

15 published stories tagged with Remote Code Execution.

highExploited VulnerabilitiesJul 29, 20263 min read

Exploited JFrog Artifactory Zero-Days Enable Privilege Escalation and Lateral Movement During AI Agent Testing

OpenAI's autonomous AI agents exploited zero-day vulnerabilities in JFrog Artifactory to escalate privileges and move laterally during a controlled offensive capability test.

criticalExploited VulnerabilitiesJul 29, 20263 min read

Unauthenticated attackers can execute commands and poison AI memory via Ruflo MCP flaw

A critical flaw in the Ruflo agent meta-harness allows unauthenticated attackers to execute commands via its MCP bridge.

criticalExploited VulnerabilitiesJul 28, 20262 min read

Unauthenticated attackers can execute remote OS commands via JetBrains TeamCity agent polling

馃毃 Critical unauthenticated remote code execution flaw found in JetBrains TeamCity. Attackers can execute arbitrary code via the agent polling protocol without any credentials.

criticalExploited VulnerabilitiesJul 27, 20262 min read

Authenticated workflow editors can execute arbitrary OS commands via n8n expression evaluation flaw

A critical vulnerability in the n8n workflow expression evaluation system allows authenticated users to execute arbitrary system commands on the host machine.

highExploited VulnerabilitiesJul 27, 20263 min read

FastJson remote code execution flaw targets Spring Boot applications in US and Canada

Attackers are actively exploiting a critical remote code execution flaw in the FastJson Java library to target organizations across the US, Singapore, and Canada.

highRansomwareJul 27, 20262 min read

Unauthenticated attackers exploit critical remote code execution in PTC Windchill to steal engineering data

Attackers are exploiting a critical remote code execution vulnerability in PTC's product lifecycle management platforms to steal high-value engineering and design data.

criticalExploited VulnerabilitiesJul 24, 20262 min read

Crafted SVG files allow remote command execution as SYSTEM on Microsoft Bing servers

馃毃 Critical vulnerability discovered in Microsoft Bing Images. Attackers can execute arbitrary code over a network by using specially crafted SVG files.

criticalExploited VulnerabilitiesJul 19, 20263 min read

Unauthenticated attackers exploit WP2Shell vulnerabilities to achieve remote code execution on WordPress websites

Attackers are actively exploiting two critical vulnerabilities, dubbed "WP2Shell," to take control of WordPress websites.

highData BreachesJul 15, 20263 min read

Exploitation of SharePoint vulnerabilities enables remote code execution and sensitive IIS key theft

Threat actors are actively exploiting three vulnerabilities in on-premises Microsoft SharePoint Server instances to achieve remote code execution and steal sensitive IIS machine keys.

criticalAPT / Nation-StateJul 10, 20263 min read

Attackers exploit Joomla extension vulnerabilities to execute remote code via malicious file uploads

Two critical vulnerabilities in popular Joomla extensions-Balbooa Forms and iCagenda-are being actively exploited in the wild to achieve unauthenticated remote code execution.

criticalRansomwareJul 2, 20262 min read

Ransomware actors exploit Citrix vulnerabilities and Bring Your Own Vulnerable Driver techniques

A critical vulnerability in NetScaler ADC, identified as CVE-2025-5777, has been actively exploited by threat actors linked to ransomware operations.

criticalExploited VulnerabilitiesJul 2, 20263 min read

Unauthenticated attackers can remotely control Gardyn IoT devices via critical command execution flaw

Gardyn has released urgent firmware updates to address a critical vulnerability that allows unauthenticated users to take remote control of Home and Studio devices.

highAPT / Nation-StateJul 1, 20262 min read

Remote Code Execution Vulnerability in Microsoft SharePoint Under Active Exploitation by Attackers

Attackers are actively exploiting a high-severity deserialization vulnerability in Microsoft SharePoint.

highData BreachesJul 1, 20264 min read

Unauthenticated attackers exploit critical vulnerabilities for remote code execution in Oracle E-Business Suite

Critical vulnerabilities in Oracle E-Business Suite and PeopleSoft are being actively exploited by threat actors.

criticalCloud & SaaS SecurityJun 4, 20265 min read

Collibra Agent Unauthenticated RCE Chain Exposes Data Governance Deployments

CERT/CC says Collibra Agent flaws can be chained from unauthenticated access to arbitrary file write and remote code execution.