< ciso
brief />
Tag Banner

All news with #remote code execution tag

881 articles

Critical LMCache flaw allows remote code execution

πŸ›‘οΈ A critical vulnerability in LMCache lets unauthenticated attackers execute code on the cache server when it is configured to listen on a routable address. The flaw resides in multiprocess mode where ZeroMQ messages are unpickled before type checks, enabling crafted messages to run with the LMCache process's privileges. JFrog disclosed the issue (CVE-2026-105192) on October 7 and rated it 9.8/10; no patched release is available, and operators are advised to keep the server bound to localhost or restrict network access.
read more β†’

LibreOffice and OpenOffice permit silent Java code execution

πŸ›‘οΈ A malicious spreadsheet can trigger remote Java code execution in LibreOffice and Apache OpenOffice via database ranges that auto-refresh from an external ODB source. The issue requires Java support to be enabled and bypasses the usual macro trust prompt, enabling execution without user consent. LibreOffice patched the flaw as CVE-2026-63277 in updates released October 5 (move to 26.2.5 or 26.8.0), while Apache OpenOffice's matching CVE-2026-59265 remains unpatched in releases up to 4.1.16. Users can mitigate the risk by disabling Java or avoiding untrusted spreadsheets until OpenOffice issues its fix.
read more β†’

Active scans target Rejetto HFS critical RCE flaw

πŸ”Ž Researchers report active probes targeting CVE-2026-61500 in Rejetto HFS, a session-cookie signing weakness that can enable account takeover and remote code execution. Horizon3 linked discovery to Anthropic's Mythos model and released a PoC, prompting small-scale scans from a China Telecom IP. Administrators are urged to upgrade to Rejetto HFS 3.2.1 or preferably 3.3.4 to mitigate exploitation.
read more β†’

Critical Dell DSU Flaw Lets Attackers Gain Root

πŸ›‘οΈ Dell warned customers to update the System Update (DSU) CLI after a critical path traversal vulnerability (CVE-2026-86360) was disclosed that can allow unauthenticated attackers to execute code with root privileges. The company released DSU 2.3.0.0 to patch this and four other high-severity issues, and urged immediate upgrades. U.S. agencies previously warned vendors to eliminate path traversal weaknesses, and organizations should patch promptly to reduce risk.
read more β†’

Cling botnet leverages STUN to hide C2 activity

πŸ” Nozomi Networks observed attackers exploiting a patched critical Realtek Jungle SDK RCE (CVE-2021-35394) starting around September 5, 2026, to deploy a botnet named Cling. The malware repurposes ordinary STUN traffic as a covert command-and-control channel, enabling propagation, proxying, tunneling and denial-of-service actions while resembling legitimate NAT-traversal activity. Samples embed multiple exploit payloads targeting routers and DVRs from various vendors and use persistence techniques like replacing wget and modifying init scripts.
read more β†’

Active Exploitation of Rejetto HFS CVE-2026-61500

πŸ”’ A critical vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, is being actively targeted in the wild. The flaw stems from use of a weak PRNG for session-cookie signing, allowing attackers to reconstruct the key, forge admin sessions, and trigger remote code execution via the server_code feature. A patch (v3.2.1) was released in July 2026, but exploitation attempts were observed in October after a public PoC was released.
read more β†’

GitLab patches critical AI Gateway remote command flaw

πŸ”’ GitLab disclosed a critical vulnerability (CVE-2026-90970) in its AI Gateway that could let a logged-in user with Duo Agent Platform access escape a prompt template sandbox and run commands on self-hosted gateways. The flaw, rated 9.9 CVSS, affects gateway releases from 18.1.6 through the 19.1 line and is fixed in 19.2.4, 19.3.2, and 19.4.1. GitLab has already remediated gateways it hosts; self-managed customers are urged to update immediately.
read more β†’

GitLab warns of critical RCE in AI Gateway

πŸ”” GitLab warned customers to immediately patch a critical AI Gateway vulnerability that could allow attackers to execute arbitrary commands on vulnerable instances. The flaw, tracked as CVE-2026-90970, affects self-hosted AI Gateway deployments and stems from improper neutralization allowing sandbox escape by authenticated users with Duo Agent Platform access. GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to address the issue and said hosted AI Gateway users are already protected.
read more β†’

DIVD Breached via Agentic AI Exploiting Zammad Zero-days

πŸ”’ The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed it was compromised after attackers used two zero-day flaws in Zammad. Detected on September 24, the chained RCE (CVE-2026-102489) and privilege escalation (CVE-2026-102490) enabled rapid session hijack and root takeover, with a combined CVSS of 9.4. DIVD contained the intrusion through segmentation but reported volunteer contact data exposure. The group warns users to update to Zammad 7 or take instances offline immediately.
read more β†’

Critical FortiMail Zero-Day Allows Remote Code Execution

🚨 Fortinet warns of a critical FortiMail vulnerability (CVE-2026-104286) actively exploited in zero-day attacks that can allow unauthenticated attackers to write arbitrary files and execute code via crafted HTTP/HTTPS requests. The flaw affects multiple FortiMail 7.x and 8.0 releases; Fortinet identified the issue internally and provided temporary workarounds while patches are prepared. Admins are urged to disable IBE support or block management access from the Internet and to check published IOCs and logs for signs of compromise.
read more β†’

Kiteworks fixes max-severity EPG code-injection flaw

πŸ”’ Kiteworks released security updates addressing 126 vulnerabilities across its platform, including a max-severity code-injection flaw in the Email Protection Gateway (EPG). The issue, tracked as CVE-2026-54154, was reported via the YesWeHack bug bounty program and allowed unauthenticated remote code execution through a chain of path traversal, code injection, and missing authentication. The EPG flaw affects versions prior to 9.4.1 and is patched in 9.4.1 or later, while additional critical issues in Core and EPG were also fixed.
read more β†’

DIVD: Zammad zero-days enabled AI-driven breach

πŸ”’ The Dutch Institute for Vulnerability Disclosure (DIVD) reports its network was compromised via a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. The attacker used an autonomous AI agent to perform session hijacking, remote code execution, and privilege escalation to root in seconds. DIVD, working with Merlon Security, advised users to upgrade to version 7 or take instances offline while investigations continue.
read more β†’

Zimbra RCE Exploited to Deploy Web Shells and Steal Mail

πŸ›‘οΈ Microsoft found threat actors exploiting CVE-2026-73570 in Zimbra Collaboration Suite to deploy JSP web shells, establish reverse shells, escalate privileges, and exfiltrate mailbox data. The unauthenticated command injection flaw affected systems with SNMP notifications enabled and the optional zimbra-snmp package installed, and was patched in Zimbra 10.1.20 in July 2026. Attackers used varied persistence and lateral-movement techniques, including systemd services, cron jobs, SSH identity reuse, and custom Go-based tooling to harvest credentials and export mailbox databases. Organizations are urged to patch, remove the zimbra-snmp package if necessary, restrict SNMP/SMTP access, rotate secrets, and hunt for web shells and other artifacts.
read more β†’

AI-discovered Vulnerabilities More Likely to Enable RCE

πŸ” Google Threat Intelligence Group (GTIG) reports that vulnerabilities identified as likely discovered by AI are disproportionately associated with remote code execution (RCE). Between January and August 2026, GTIG found 50% of likely AI-discovered flaws led to RCE versus 26% of other CVEs, while overall disclosures and exploit activity accelerated. The research highlights concentrations in agent orchestration frameworks and edge/security appliances, noting rapid weaponization of n-days and localized zero-day spikes.
read more β†’

Unsloth Studio model loader allowed remote code execution

πŸ›‘οΈ Pillar Security found that selecting a model in Unsloth Studio caused the application to download and execute Python code from model repositories. The issue arose because Unsloth enabled Hugging Face's trust_remote_code automatically during routine model checks, running code just by reading a model's config.json. Unsloth patched the behavior in version 2026.6.9 and users are urged to upgrade and audit uses of trust_remote_code.
read more β†’

TeamViewer urges immediate patch for severe flaws

πŸ”’ TeamViewer has issued an urgent advisory urging customers to update immediately after disclosing multiple high-severity vulnerabilities in its Full Client and Host software for Windows, macOS, and Linux. The most critical issue is a remote session access control bypass (CVE-2026-92370) that could allow unauthorized remote actions leading to remote code execution. Four other flaws include path traversal, heap overflow, TOCTOU race condition, and improper path validation, which can enable local or remote code execution and privilege escalation. TeamViewer recommends upgrading to version 15.82, noting no evidence of public exploits or active in-the-wild abuse so far.
read more β†’

Apple issues CoreGraphics zero-day patch

πŸ”’ Apple has released a security update addressing CVE-2026-86950, a zero-day in the CoreGraphics rendering framework that Meta Product Security reported. The company said processing a maliciously crafted file could allow arbitrary code execution and that the flaw may have been exploited in an β€œextremely sophisticated” attack targeting specific individuals. Affected devices include recent iPhones, various iPad models and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1. Apple fixed the issue in iOS 26.7.1, iPadOS 26.7.1 and the noted macOS builds.
read more β†’

Critical Citrix NetScaler DTLS Overflow Under Active Exploitation

πŸ”’ Researchers disclosed details of a critical memory overflow in Citrix NetScaler ADC and Gateway, tracked as CVE-2026-88772 (CVSS 9.5). The flaw stems from improper DTLS fragment parsing in the NetScaler Packet Processing Engine, allowing crafted records to overflow a scratch buffer and enable remote code execution or denial-of-service. Vendor and researchers show how reassembly of many small fragments can produce a large NSB chain, enabling shellcode execution by bypassing NX protections with mprotect().
read more β†’

AgentCore SDK flaws allowed sandbox command execution

πŸ”’ Two vulnerabilities in Amazon Bedrock AgentCore's Python SDK could let attackers execute commands inside Code Interpreter sandboxes and access AWS credentials. BeyondTrust detailed that crafted package names and pip extras syntax could bypass validation, tracked as CVE-2026-12530 and CVE-2026-16796. AWS patched the issues in versions 1.6.1 and 1.18.1, and urged upgrades and stricter handling of untrusted package names.
read more β†’

NetScaler zero-days exploited: urgent patch guidance

πŸ”’ Unit 42 alerts that Citrix has reported active exploitation of two critical NetScaler vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated 9.5 on CVSS v4.0. The flaws enable unauthenticated remote code execution and a DTLS memory overflow that may cause RCE or DoS on NetScaler ADC and Gateway devices. Unit 42 urges immediate patching, system isolation, evidence preservation, and threat hunting while offering Incident Response assistance.
read more β†’