< ciso
brief />
Tag Banner

All news with #remote code execution tag

882 articles · page 10 of 45

Cloudflare deploys WAF rules for WordPress RCE and SQLi

🛡️ Cloudflare has deployed new Web Application Firewall protections to block two critical WordPress vulnerabilities: an unauthenticated RCE in the REST API and a related SQL injection. The rules, activated on July 17, 2026 at 17:03 UTC, protect all proxied customers including Free plans. Customers should still apply WordPress patches (7.0.2 and backports) and ensure Managed Rules remain set to Block while monitoring Security Events.
read more →

CISA orders urgent FortiSandbox patches for agencies

🔒 CISA has ordered U.S. federal agencies to urgently patch two actively exploited critical vulnerabilities in the Fortinet FortiSandbox platform. The flaws (CVE-2026-39808 and CVE-2026-25089) were fixed by Fortinet in April and June, and allow unauthenticated remote command injection with low complexity. Defused and CISA confirmed in-the-wild exploitation, and agencies must remediate by Sunday, July 19. Administrators are advised to upgrade affected deployments to the latest released versions to block attacks.
read more →

CISA Lists Exploited SharePoint RCE in KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Microsoft SharePoint Server vulnerability, CVE-2026-58644 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog, requiring Federal agencies to patch by July 19, 2026. Microsoft confirmed the flaw enables remote code execution via deserialization of untrusted data and has been exploited in the wild; fixes were issued on Patch Tuesday, July 14, 2026. Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA also warned of active exploitation of multiple SharePoint flaws and recommended hardening steps including applying updates, enabling AMSI, rotating IIS machine keys, limiting internet exposure, and tightening access controls.
read more →

CISA warns: patch actively exploited SharePoint flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are actively exploiting three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) in Internet-exposed on-premises instances. The flaws enable authentication bypass, remote code execution, and post-exploitation activity including theft of IIS machine keys and persistence to deploy malware. CISA urged administrators to apply Microsoft's patches, verify installation, shorten patch cycles, enable AMSI integration for SharePoint, use Microsoft Defender Antivirus detections, and implement hardening and monitoring measures.
read more →

SonicWall SMA 1000 Zero‑Days Prompt Urgent Patches

🛡️ SonicWall warned of active exploitation of two zero‑day vulnerabilities affecting Secure Mobile Access (SMA) 1000 series appliances, including an SSRF that scores 10.0 and a post‑auth code injection allowing command execution. Patches are available in platform hotfix builds 12.4.3‑03453, 12.5.0‑02835 and later; customers are urged to apply fixes and perform forensic checks for specific IoCs. CISA added both flaws to its KEV catalog and set a July 17, 2026 deadline for federal agencies.
read more →

SAP patches critical NetWeaver, Commerce Cloud flaws

🔒 SAP released July 2026 security updates addressing 16 vulnerabilities across multiple products, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The issues include a memory corruption bug in NetWeaver AS ABAP, an HTTP request smuggling flaw in Approuter, and default-credential exposure in Commerce Cloud. SAP also fixed several high- and medium-severity bugs such as RCE, XSS, SQLi, and DLL hijacking.
read more →

CISA warns of exploited RCE in Joomla extensions

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers are actively exploiting arbitrary file upload vulnerabilities in the iCagenda and Balbooa Forms Joomla extensions to achieve remote code execution. The agency designated these flaws as maximum priority and ordered federal agencies to apply updates or mitigations within three days. Vendors released fixes in iCagenda 4.0.8/3.9.15 and Balbooa Forms 2.4.1 after automated and zero-day exploitation was observed. Administrators should check installations and apply the available patches immediately.
read more →

Australia warns of widespread CMS exploitation

🛡️ The Australian Cyber Security Centre (ACSC) has warned of a large-scale campaign scanning and exploiting vulnerabilities in content management systems worldwide, impacting many SMBs in Australia. The actors deploy webshells via flaws allowing unauthenticated file upload, remote code execution, SSRF or deserialization, affecting products like WordPress, Joomla, Craft CMS and others. The ACSC advises inspecting servers for compromise, isolating and remediating infected hosts, patching vulnerable systems, and restoring from known-good backups.
read more →

Six new U-Boot flaws risk pre-OS code execution

🔒 Researchers at Binarly disclosed six vulnerabilities in U-Boot, the bootloader used across routers, cameras, and server management controllers. Two flaws allow code execution during image parsing before signature verification, while four cause crashes. The bugs trace to unchecked returns from fdt_get_name and other parsing errors; patches were merged but not yet broadly distributed.
read more →

OpenClaw flaws enable host escape and credential theft

🔒 Three critical vulnerabilities in the OpenClaw personal AI assistant could allow credential theft, privilege escalation, and arbitrary host code execution if exploited. The flaws include two command injection bugs (GHSA-hjr6-g723-hmfm and GHSA-9969-8g9h-rxwm) and a path traversal/link-following issue (GHSA-575v-8hfq-m3mc). OpenClaw 2026.6.6 patches these issues; operators are advised to harden configurations and limit tool/channel allowlists.
read more →

AI agents can enable silent remote code execution

🔒 A new AI Now Institute report demonstrates a proof-of-concept exploit that coerces Anthropic’s Claude Code and OpenAI’s Codex into executing attacker-supplied binaries during automated code review. The attack uses multi-stage prompt injection hidden in repository files (documentation, comments) to trick agents in auto-mode or auto-review into running a seemingly benign script that launches a malicious payload. Researchers warn the architectural risk — agents’ inability to reliably attribute text sources — makes such platforms potential attack vectors when granted shell access and autonomous execution.
read more →

Ubiquiti issues urgent UniFi security patches

🔒 Ubiquiti has released updates to remediate several critical vulnerabilities across UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS. The flaws include command injection, authenticated SQL injection, SSRF, and improper access control, with multiple CVSS scores at or near 10.0. Affected versions are identified for each product and updated builds are available that address the issues.
read more →

CISA directs federal patch for ColdFusion zero-day

🔒 The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch an actively exploited, maximum-severity vulnerability in Adobe ColdFusion (CVE-2026-48282) by Friday. Adobe published fixes for affected ColdFusion versions last week and urged administrators to install updates immediately. The flaw enables unauthenticated remote code execution in low-complexity attacks and has been observed in the wild soon after disclosure. CISA added the issue to its KEV catalog and invoked BOD 26-04 to enforce remediation timelines for FCEB agencies.
read more →

Critical Dialogflow CX 'Rogue Agent' code execution flaw

🛡️ A critical flaw in Google Dialogflow CX's Code Blocks could let an attacker with edit rights on one agent compromise other Code Block-enabled agents in the same Google Cloud project. Varonis named the issue Rogue Agent; it required the dialogflow.playbooks.update permission and thus implied a malicious insider or compromised developer account rather than an unauthenticated internet attacker. Google fixed the vulnerability after Varonis disclosed it via the VRP; there are no signs of exploitation.
read more →

Max-severity Adobe ColdFusion flaw being actively exploited

🔧 Adobe has issued emergency updates to fix a maximum-severity ColdFusion vulnerability (CVE-2026-48282) that is now being actively exploited, the Canadian Center for Cyber Security (CCCS) warned. The flaw affects ColdFusion 2025.9, 2023.20, and earlier, enabling unauthenticated remote code execution on unpatched systems. Adobe urges administrators to install the patch immediately, and Shadowserver reports nearly 800 exposed ColdFusion instances online.
read more →

Seven vulnerabilities disclosed in ubiquitous FatFs library

🔒 Security firm runZero disclosed seven vulnerabilities in the FatFs filesystem library used to read FAT/exFAT on many embedded devices. The bugs—rated Medium to High—can lead to memory corruption, crashes, data leaks, or code execution when a device mounts malformed media or firmware images. Only the GPT hang issue is fixed upstream; most fixes must come from downstream vendors who bundle FatFs. runZero published PoCs and urges vendors and integrators to audit wrappers and treat physical ports and update channels as attack surfaces.
read more →

Argo CD flaw highlights GitOps as tier-zero risk

🔒 A critical vulnerability in Argo CD repo-server exposes risks inherent to GitOps platforms. Synacktiv found the unauthenticated GenerateManifest gRPC endpoint can be abused via Kustomize/Helm options to execute commands if an attacker can reach both the repo-server and Redis ports. The issue affects typical Helm deployments where Kubernetes network policies are not enabled by default, enabling lateral movement from a compromised pod. Synacktiv disclosed details July 1, 2026 and recommends strict network segmentation until a patch is available.
read more →

CISA Adds SharePoint RCE CVE-2026-45659 to KEV Catalog

🔒 CISA has added a high-severity SharePoint Server vulnerability, CVE-2026-45659 (CVSS 8.8), to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. Microsoft patched the deserialization-based remote code execution flaw in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The issue can be triggered by any authenticated attacker with as little as Site Member permissions and does not require elevated privileges. Federal agencies are advised to apply updates by July 4, 2026, while Microsoft assesses public exploitation as "Exploitation Less Likely."
read more →

Cursor IDE sandbox bypasses enable RCE via prompt injection

🛡️ Researchers discovered two vulnerabilities in the Cursor AI-enabled IDE that enable prompt-injection-driven remote code execution by escaping the command execution sandbox. The flaws, CVE-2026-50548 and CVE-2026-50549, allow attackers to change the working directory and exploit symlink canonicalization fallbacks to write or overwrite files outside the project scope. Cursor patched the issues in version 3.0, and the findings underscore broader risks in agentic AI workflows and the difficulty of defending against prompt injection.
read more →

Unpatched Argo CD repo-server flaw risks code execution

🔒 Synacktiv disclosed an unpatched vulnerability in Argo CD's repo-server that allows unauthenticated attackers to execute arbitrary commands if they can reach the component's internal gRPC port. The flaw abuses kustomize's --helm-command option to run attacker-controlled scripts, demonstrated against Argo CD v2.13.3, and can lead to full cluster takeover by leveraging exposed Redis credentials. There is no fixed release or CVE; operators must enable Kubernetes network policies to isolate repo-server and Redis until a patch is available.
read more →