Tag
#remote code execution
15 published stories tagged with remote code execution.
Exploited JFrog Artifactory Zero-Days Enable Privilege Escalation and Lateral Movement During AI Agent Testing
OpenAI's autonomous AI agents exploited zero-day vulnerabilities in JFrog Artifactory to escalate privileges and move laterally during a controlled offensive capability test.
Unauthenticated attackers can execute commands and poison AI memory via Ruflo MCP flaw
A critical flaw in the Ruflo agent meta-harness allows unauthenticated attackers to execute commands via its MCP bridge.
Unauthenticated attackers can execute remote OS commands via JetBrains TeamCity agent polling
馃毃 Critical unauthenticated remote code execution flaw found in JetBrains TeamCity. Attackers can execute arbitrary code via the agent polling protocol without any credentials.
Authenticated workflow editors can execute arbitrary OS commands via n8n expression evaluation flaw
A critical vulnerability in the n8n workflow expression evaluation system allows authenticated users to execute arbitrary system commands on the host machine.
FastJson remote code execution flaw targets Spring Boot applications in US and Canada
Attackers are actively exploiting a critical remote code execution flaw in the FastJson Java library to target organizations across the US, Singapore, and Canada.
Unauthenticated attackers exploit critical remote code execution in PTC Windchill to steal engineering data
Attackers are exploiting a critical remote code execution vulnerability in PTC's product lifecycle management platforms to steal high-value engineering and design data.
Crafted SVG files allow remote command execution as SYSTEM on Microsoft Bing servers
馃毃 Critical vulnerability discovered in Microsoft Bing Images. Attackers can execute arbitrary code over a network by using specially crafted SVG files.
Unauthenticated attackers exploit WP2Shell vulnerabilities to achieve remote code execution on WordPress websites
Attackers are actively exploiting two critical vulnerabilities, dubbed "WP2Shell," to take control of WordPress websites.
Exploitation of SharePoint vulnerabilities enables remote code execution and sensitive IIS key theft
Threat actors are actively exploiting three vulnerabilities in on-premises Microsoft SharePoint Server instances to achieve remote code execution and steal sensitive IIS machine keys.
Attackers exploit Joomla extension vulnerabilities to execute remote code via malicious file uploads
Two critical vulnerabilities in popular Joomla extensions-Balbooa Forms and iCagenda-are being actively exploited in the wild to achieve unauthenticated remote code execution.
Ransomware actors exploit Citrix vulnerabilities and Bring Your Own Vulnerable Driver techniques
A critical vulnerability in NetScaler ADC, identified as CVE-2025-5777, has been actively exploited by threat actors linked to ransomware operations.
Unauthenticated attackers can remotely control Gardyn IoT devices via critical command execution flaw
Gardyn has released urgent firmware updates to address a critical vulnerability that allows unauthenticated users to take remote control of Home and Studio devices.
Remote Code Execution Vulnerability in Microsoft SharePoint Under Active Exploitation by Attackers
Attackers are actively exploiting a high-severity deserialization vulnerability in Microsoft SharePoint.
Unauthenticated attackers exploit critical vulnerabilities for remote code execution in Oracle E-Business Suite
Critical vulnerabilities in Oracle E-Business Suite and PeopleSoft are being actively exploited by threat actors.
Collibra Agent Unauthenticated RCE Chain Exposes Data Governance Deployments
CERT/CC says Collibra Agent flaws can be chained from unauthenticated access to arbitrary file write and remote code execution.