< ciso
brief />
Tag Banner

All news with #command injection tag

42 articles

Citrix NetScaler exploitation drops web shells, steals configs

πŸ›‘οΈ LevelBlue observed threat actors exploiting a critical pre-auth command injection in Citrix NetScaler ADC and NetScaler Gateway to deploy web shells and exfiltrate configuration data. The activity weaponizes CVE-2026-88771 and included attacker-supplied authentication strings, payload retrieval via curl/wget, and second-stage scripts that establish reverse shells, create privileged accounts, and upload archived configs. The incidents follow recent disclosures of CVE-2026-88771 and CVE-2026-88772 amid active exploitation reports.
read more β†’

Unauthenticated command injection in Zimbra SNMP path

πŸ”’ Microsoft Threat Intelligence tracked exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path. Exploitation occurs via specially crafted SMTP requests against internet-facing Zimbra servers with the optional zimbra-snmp package installed and SNMP notifications enabled. Observed impacts included JSP web shells, reverse shells, privilege escalation, persistent tooling, and exfiltration of email and authentication data. Activity spanned multiple regions and industries and combined automated probes with hands-on-keyboard operations.
read more β†’

Ubiquiti fixes three maximum-severity vulnerabilities

πŸ”’ Ubiquiti released patches for three maximum-severity vulnerabilities affecting UniFi applications and OS. The flaws include a remote exploit in the UniFi Protect Application, a CRLF injection (CVE-2026-77550) that can bypass authentication on UniFi OS devices, and a command injection in the UniFi Talk VoIP system (CVE-2026-77554). Patches are available in UniFi Protect 7.2.105+, UniFi Talk 5.3.2+, and UniFi OS Server 5.1.21+.
read more β†’

CISA orders urgent Zimbra patching for active exploit

πŸ”” The Cybersecurity and Infrastructure Security Agency (CISA) directed U.S. federal civilian agencies to patch an actively exploited Zimbra Collaboration Suite flaw (CVE-2026-73570) within three days after CERT Polska reported in-the-wild attacks. The flaw, fixed in Zimbra 10.1.20 released July 20, permits unauthenticated remote code execution via a command injection in the SNMP notification component when enabled. Administrators are urged to review recent logs for indicators such as unexpected service restarts and newly created files under zimbra-owned webapps and /tmp directories.
read more β†’

CISA flags critical Progress Kemp LoadMaster flaw

πŸ”’ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are actively exploiting a critical command injection vulnerability in Progress Kemp LoadMaster. The flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands on unpatched appliances via unsanitized API inputs. Progress released patches in June for affected GA and LTSF versions, and CISA has directed federal agencies to remediate within three days.
read more β†’

Critical LoadMaster Command Injection Added to CISA KEV

πŸ”’ CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The flaw, rooted in improper input handling in an escape_quotes() function, allows unauthenticated attackers to execute arbitrary commands on affected appliances. Agencies are urged to apply patches immediately under BOD 26-04 to mitigate ongoing attacks.
read more β†’

Arista patches VeloCloud Orchestrator zero-day exploit

πŸ”’ Arista released fixes for a maximum-severity unauthenticated command injection in on-premises VeloCloud Orchestrator (CVE-2026-16812) that is being actively exploited. The flaw allows remote attackers network access to the VCO web interface to execute privileged commands without credentials, potentially impacting confidentiality, integrity, and availability. Affected on-premises versions include 5.2.x, 6.1.x, 6.4.x and early 7.0.x releases; hosted and dedicated deployments are already patched. Administrators are urged to apply the provided updates, restrict VCO web access, block listed malicious IPs, and review logs for signs of compromise.
read more β†’

Zimbra issues patch for critical SNMP command flaw

πŸ”§ Zimbra released version 10.1.20 to address nine vulnerabilities, led by a command injection flaw in the SNMP monitoring component when SNMP notifications are enabled. The update also fixes four cross-site scripting (XSS) issues in the Classic Web Client and a mail forwarding restriction bypass (CVE-2026-50055) reported by Jonah Burgess. The vendor limited details per industry best practices and urged customers to apply the fixes promptly.
read more β†’

CISA urges immediate patching of Fortinet FortiSandbox

πŸ›‘οΈ The US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply patches by July 19. Both flaws are OS command injection bugs with CVSS scores of 9.1 and have documented in-the-wild exploitation. Fortinet released fixes in FortiSandbox versions 4.4.9 and 5.0.6; CISA advised discontinuing cloud services where mitigations are unavailable.
read more β†’

Ubiquiti patches max-severity UniFi OS flaws

πŸ”’ Ubiquiti released updates addressing seven critical UniFi OS vulnerabilities, including a maximum-severity command injection flaw (CVE-2026-50746) in the UniFi Connect Application. The flaw affects versions 3.4.16 and earlier and could allow a network-based attacker to execute commands on the host. Users are advised to upgrade UniFi Connect to version 3.4.20 or later. Six additional critical issues across UniFi Talk, Access, Protect, UniFi OS Server, and multiple devices were also patched.
read more β†’

CISA orders three-day patch for Ivanti Sentry flaw

πŸ”’ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch an actively exploited Ivanti Sentry flaw (CVE-2026-10520) within three days under Binding Operational Directive BOD 26-04. The vulnerability, an OS command injection in Ivanti's security gateway appliance, has been confirmed exploited and added to CISA's Known Exploited Vulnerabilities Catalog. Shadowserver reports multiple Sentry gateways have already been backdoored and warns unpatched systems are likely compromised.
read more β†’

Maximum-severity Ivanti Sentry flaw now exploited

πŸ”’ Attackers are exploiting a recently patched maximum-severity OS command injection in Ivanti Sentry (formerly MobileIron Sentry), tracked as CVE-2026-10520, to achieve root code execution on Internet-exposed gateways. Ivanti released patches in Sentry R10.5.2, R10.6.2, and R10.7.1, but Shadowserver reports many publicly reachable appliances have already been backdoored. Shadowserver warned that their scans undercount exposures due to blocklisting and urged immediate patching, while Ivanti has not revised its advisory and maintains no evidence of customer exploitation at disclosure.
read more β†’

Universal Robots Polyscope 5 Command Injection Fix

⚠️ A critical OS command injection in the Dashboard Server of Universal Robots Polyscope 5 (CVSS 9.8) allows unauthenticated attackers to execute commands on the robot's operating system. Affected releases are versions prior to 5.25.1; the vendor has issued Polyscope 5 v5.25.1 as a corrective update. CISA advises immediate patching and network defenses including segmentation, firewalling, and limiting internet exposure.
read more β†’

Siemens Ruggedcom Rox OS Command Injection Fix Released

⚠ An input validation vulnerability in the feature key installation process of Siemens Ruggedcom Rox allows an authenticated remote attacker to inject OS commands and achieve arbitrary code execution with root privileges. Siemens has released updates and advises customers to upgrade affected devices to V2.17.1 or later without delay. CISA and Siemens recommend isolating control networks, restricting access, and following Siemens' operational guidelines to reduce exposure.
read more β†’

Siemens Ruggedcom Rox OS Command Injection Advisory

⚠️An input validation vulnerability in the Scheduler feature of Siemens Ruggedcom Rox devices allows an authenticated remote attacker to inject OS commands via the device's Web UI. Successful exploitation can execute arbitrary commands with root privileges on the underlying operating system. Siemens has released updates and recommends upgrading to V2.17.1 or later; CISA urges operators to apply the patch and implement network protections such as firewalls, isolation, and secure remote access.
read more β†’

Nexcorium Mirai Variant Exploits DVR Command Injection

⚠️Fortinet researchers observed a campaign exploiting a command injection flaw (CVE-2024-3721) in TBK DVR systems to deploy a Mirai-based, multi-architecture botnet called Nexcorium. Attackers deliver a downloader via crafted HTTP requests that retrieves ARM, MIPS and x86-64 payloads and executes them with elevated privileges. The malware leverages an XOR-encoded configuration, embedded credential lists for brute-force access and multiple persistence mechanisms, and network traffic includes a custom HTTP header referencing Nexus Team that may indicate the actor.
read more β†’

Chained Cisco Catalyst 9300 Flaws Could Cause DoS Outage

πŸ”’ Cisco's Catalyst 9300 switches contain four vulnerabilities β€” two of which can be chained to escalate privileges and induce a denial-of-service by forcing the device into maintenance mode. Opswat's Unit 515 CIP Lab reported CVE-2026-20114 (command injection) and CVE-2026-20110 (insufficient sanitization), which together allow a low-privileged Lobby Ambassador account to gain higher privileges. Cisco released fixes in its March 25, 2026 IOS and IOS XE advisory; administrators should run the Software Checker, enable MFA for Lobby Ambassador accounts, and, where possible, set the privilege level for the 'start maintenance' command from the CLI.
read more β†’

Low-cost KVM-over-IP Flaws Risk Remote Network Takeover

πŸ”’ Researchers discovered nine critical vulnerabilities across several low-cost KVM-over-IP units, including Angeet/Yeeso, GL-iNet, Sipeed, and JetKVM. Flaws range from unauthenticated file uploads and command injection to weak firmware verification and exposed debugging interfaces, enabling pre-authentication root takeover on some devices. Eclypsium warns these inexpensive, Linux-based single-port KVMs are increasingly common in business and pose outsized risks if exposed directly to networks.
read more β†’

CISA Adds Two Known-Exploited Vulnerabilities to KEV Catalog

⚠️ CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on March 3, 2026, after observing evidence of active exploitation. The entries include CVE-2026-21385, a memory corruption issue impacting multiple Qualcomm chipsets, and CVE-2026-22719, a command injection vulnerability affecting Broadcom VMware Aria Operations. Under BOD 22-01, Federal Civilian Executive Branch agencies must remediate cataloged flaws by the required due dates; CISA also strongly urges all organizations to prioritize timely remediation. CISA will continue to add vulnerabilities that meet its KEV criteria.
read more β†’

CISA Confirms Active Exploitation of FileZen Flaw Now

🚨 CISA has added a recently disclosed FileZen vulnerability, CVE-2026-25108 (CVSS v4 8.7), to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The issue is an OS command injection that allows an authenticated user to execute arbitrary commands via specially crafted HTTP requests. Affected versions include 4.2.1–4.2.8 and 5.0.0–5.0.10; Soliton advises updating to 5.0.11 or later and changing passwords if exploitation is suspected. Federal agencies must remediate by March 17, 2026.
read more β†’