< ciso
brief />
Tag Banner

All news with #remote code execution tag

778 articles

CISA orders federal patching for TrueConf flaws

πŸ”’ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently patch two actively exploited critical vulnerabilities in the self-hosted TrueConf Server communications platform. The flaws, tracked as CVE-2026-72529 and CVE-2026-72530, allow unauthenticated remote code execution through a missing authentication function and complex code-injection attacks. CISA added both issues to its KEV catalog and mandated fixes within two weeks due to significant risk to the federal enterprise.
read more β†’

Microsoft patches critical Entra ID deserialization flaw

πŸ” Microsoft patched a maximum-severity vulnerability in Entra ID that was exploited in attacks, tracked as CVE-2026-69836. Discovered by Microsoft engineer Robert Fitzpatrick, the flaw allowed unauthenticated actors to achieve code execution via deserialization of untrusted data. Microsoft states the issue is fully mitigated and no user action is required, and said exploit code is not publicly available. The company provided limited additional details on the incidents.
read more β†’

Critical sandbox escape patched in isolated-vm

πŸ”’ A critical sandbox escape was discovered and patched in isolated-vm, a library that runs JavaScript inside an isolated process. The flaw, a type confusion in the library's C++ binding code, could allow attackers to hijack the host's control flow and enable remote code execution. isolated-vm is widely used, including in AI agent frameworks, and patched versions 7.0.1 and 6.2.0 were released earlier this month.
read more β†’

ThreatsDay: Signed Drivers, AI Risks, and RCEs

πŸ›‘οΈ This week’s ThreatsDay highlights multiple vectors where trusted components and weak checks are repurposed for attack. Research shows Microsoft-signed drivers can be abused for kernel operations, and a critical Gogs RCE (CVSS 10.0) enables remote code execution via Git hooks. Other items include a large-scale Iran-linked academic espionage case, DLL sideloading campaigns, BYOVD abuse, guardrail-free AI services, and exposed refrigeration controllers.
read more β†’

Critical Elementor Pro flaw allows remote code execution

πŸ”’ A critical vulnerability in Elementor Pro allows attackers to upload executable files leading to remote code execution on affected WordPress sites. Identified as CVE-2026-32475, the bug stems from inconsistent handling of empty filename entries between the validation and processing loops in the File Upload module. Exploitation requires a published Elementor form with a File Upload field and multiple file upload enabled; administrators should update immediately and inspect uploads directories for rogue PHP files.
read more β†’

Active exploitation of Zimbra SNMP RCE disclosed

πŸ›‘οΈ A critical Zimbra Collaboration flaw (CVE-2026-73570, CVSS 8.9) allowing command injection and remote code execution is being actively exploited, CERT Polska warns. The issue affects ZCS versions prior to 10.1.20 when the optional zimbra-snmp package and SNMP notifications are enabled; it was patched in 10.1.20. Administrators are urged to inspect /var/log/zimbra.log for suspicious restarts and check recent files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
read more β†’

Citrix issues urgent NetScaler security update advisory

πŸ”’ Citrix warned customers to immediately patch two NetScaler vulnerabilities impacting NetScaler Gateway and NetScaler ADC appliances. The most severe, CVE-2026-19490, can allow remote attackers to bypass authentication when SAML action is configured on certain AAA, Auth, or VPN virtual servers. The other, CVE-2026-19489, is a high-severity memory overflow that can enable remote DoS when SIP ALG is enabled on large-scale NAT group configurations. Citrix published recommended firmware builds and urged immediate upgrades for affected deployments.
read more β†’

Critical Zimbra RCE Flaw Actively Exploited Now

πŸ›‘οΈ CERT Polska warns that attackers are actively exploiting a critical Zimbra Collaboration Suite vulnerability (CVE-2026-73570). The flaw, patched in Zimbra 10.1.20 on July 20, enables unauthenticated remote code execution via command injection in the SNMP notification processing when SNMP notifications are enabled. Shadowserver reports over 12,100 Zimbra servers exposed online, and administrators are urged to check logs and specific directories for signs of compromise. Zimbra has been a frequent target of APT groups in past campaigns.
read more β†’

Critical Elementor Pro file upload flaw allows RCE

πŸ›‘οΈ Cybersecurity researchers disclosed a critical vulnerability in the Elementor Pro WordPress plugin that permits unrestricted upload of dangerous file types, tracked as CVE-2026-32475 with a CVSS score of 9.0. The issue stems from the Forms module's File Upload field where extension checks and file-move operations run in separate loops, enabling unauthenticated attackers to bypass the extension blocklist by submitting duplicate file parts and write PHP files into wp-content/uploads/elementor/forms. The flaw affects versions up to 4.2.1 and was patched in 4.2.2 on August 19 after disclosure.
read more β†’

Critical Windows IKE Extension Flaw Actively Exploited

πŸ”’ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are exploiting a critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component, tracked as CVE-2026-33824. The vulnerability affects supported Windows 10, Windows 11, and Windows Server versions and can be triggered by unauthenticated attackers sending crafted packets to UDP ports 500 or 4500. Microsoft issued a Patch Tuesday advisory and recommended firewall mitigations for organizations that cannot immediately apply updates.
read more β†’

Critical AIT‑GUI Flaw Allows Remote Command Execution

πŸ”’ A critical vulnerability in NASA's open-source AIT-GUI ground control software could let unauthenticated actors issue spacecraft and instrument commands, execute server-side scripts, and run command sequences. Disclosed by Cycode researcher Yuval Elbar on August 18 and tracked as GHSA-p9r8-2q67-fp86 (CVSS 9.4), the flaw affects versions through 2.5.1 and was fixed in 2.5.2. The issue stems from an API that listens on all interfaces, lacks authentication/CSRF protection, and allows unsafe filesystem path construction on execution endpoints.
read more β†’

CISA Adds Actively Exploited Critical Ray Flaw

πŸ›‘οΈ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Ray vulnerability (CVE-2025-62593) to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The flaw enables remote code execution via DNS rebinding attacks through browsers like Firefox and Safari and primarily affects developers running Ray in development or testing environments. Ray fixed the issue in version 2.52.0, and agencies are urged to remediate by August 20, 2026.
read more β†’

Critical GitLab GraphQL Flaw Allows Remote Project Changes

πŸ”’ GitLab released out-of-cycle security updates on August 17, 2026, to fix a critical GraphQL vulnerability (CVE-2026-19478) that could let unauthenticated attackers remotely modify or delete public projects and user data. The patches apply to self-managed instances in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4; hosted GitLab.com and Dedicated are already patched. A second, High-severity issue (CVE-2026-19650) addresses a CSRF-related GraphQL multiplex handling flaw requiring user interaction.
read more β†’

Critical Forminator flaw lets attackers execute code

πŸ›‘οΈ A critical vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin β€” used on 600,000+ sites β€” allows unauthenticated attackers to upload arbitrary files, including executable PHP, and achieve remote code execution. The flaw, present in versions up to 1.56.1, stems from improper file type validation in the handle_file_upload() function and misuse of MIME key matching combined with a public submission handler. Patch 1.56.2, released on July 31, 2026, fixes the issue; site owners should update immediately.
read more β†’

UNISOC modem isolation flaw risks kernel RCE

πŸ”’ SSD Secure Disclosure researchers revealed a UNISOC modem firmware vulnerability that lets modem-level code execution reach Android kernel space by exploiting improper isolation between modem and kernel memory. The team demonstrated a full exploit chain, including a VoLTE-triggered final stage, and tested it on devices such as the Realme C33. No vendor firmware fix from UNISOC has been reported, leaving OEM updates as the primary mitigation.
read more β†’

Unisoc modem exploit chain risks Android kernel

πŸ”’ SSD Secure Disclosure detailed a two-stage exploit chain that yields full Android kernel access via Unisoc modem firmware when a victim answers a malicious VoLTE video call. The advisory, published August 17, 2026, follows an earlier March 2026 remote code execution disclosure and requires control of a private 4G network plus a modem foothold. Affected chipsets include Unisoc T606, T612, and T7250 in multiple device brands, and no vendor patch is yet available.
read more β†’

Critical SAP Commerce Cloud RCE Vulnerability Alert

πŸ”” SAP Commerce Cloud is affected by a maximum-severity vulnerability, CVE-2026-58231, rated 10.0 for insufficient authorization and input validation. An unauthenticated attacker can abuse a default authentication client to send crafted input and trigger arbitrary code execution, risking confidentiality, integrity, and availability. Vendors urge immediate patching and recommend IP filter sets as a temporary mitigation.
read more β†’

Critical SAP Commerce Cloud RCE Now Being Exploited

πŸ›‘οΈ A maximum-severity remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) patched three days ago is already being targeted in attacks, Defused reports. The flaw, in the core Data Hub Adapter extension, allows unauthenticated actors to exploit improper authorization to execute arbitrary code. SAP warned the issue arises from abuse of a default authentication client and insufficient input validation. Threat researchers observed initial exploitation attempts hitting honeypots despite no public PoC existing.
read more β†’

Critical GeoServer SQL Injection Now Patched

πŸ›‘οΈ A critical SQL injection zero-day in GeoServer was disclosed on August 12, 2026, and saw active exploitation attempts within hours, according to watchTowr. The flaw, tied to the jsonArrayContains function in PostGIS DataStore, could lead to remote code execution under certain configurations and remained initially unpatched. GeoServer has since released versions 3.0.1, 2.28.5, and 2.27.6 to remediate the issue, which carries a CVSS score of 9.8.
read more β†’

SCCM attack chain exploited with $58 certificate

πŸ›‘οΈ Researchers at XM Cyber demonstrated how a standard domain user can chain multiple flaws in Microsoft System Center Configuration Manager (SCCM) to achieve remote code execution on the primary site server. The attack combines a broken AdminService authorization, a path-traversal bug called CabSlip, weak signature validation exploitable with a low-cost commercial certificate, and an unsigned DLL load in the SMS Executive service. Microsoft patched the initial authorization flaw (CVE-2026-47301) in July, but additional fixes are expected in ConfigMgr 2609.
read more β†’