< ciso
brief />
Tag Banner

All news with #remote code execution tag

778 articles · page 2 of 39

Adobe issues urgent patches for critical ColdFusion flaws

🔒 Adobe released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. Several flaws carry maximum or near-maximum CVSS scores and could enable arbitrary code execution or privilege escalation. Updates for ColdFusion and Campaign Classic are rated Priority 1, and on-premise Campaign Classic customers must patch promptly; Adobe-hosted instances are already remediated.
read more →

SAP Commerce Cloud flaw lets attackers run code

🔒 SAP released patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) tracked as CVE-2026-58231, rated 10.0, that could allow arbitrary code execution due to insufficient authorization checks and input validation. Onapsis urged customers to update to the fixed release and re-deploy; as a temporary mitigation, apply an IP Filter Set to restrict access to the vulnerable endpoint. SAP's August 2026 update also addressed three other critical flaws across Manufacturing Integration and Intelligence and ABAP platforms.
read more →

August 2026 Patch Tuesday: Zero‑Day Winsock and SAP CVE

🛡️ Microsoft’s August Patch Tuesday delivers 398 CVE fixes, highlighted by an actively exploited zero‑day in the Windows Ancillary Function Driver for WinSock (CVE‑2026‑68820). The release includes 42 critical and numerous remote code execution flaws that may be exploitable without authentication, plus two additional publicly disclosed zero‑days. SAP released 29 patches, led by a maximum‑severity improper authorization issue in Commerce Cloud’s Data Hub Adapter (CVE‑2026‑58231).
read more →

Zoom patches zero-click RCE and VDI disclosure flaws

🛡️ Zoom has patched four vulnerabilities across its applications, including two zero-click remote code execution issues that allow a meeting participant to execute malicious code on other attendees' systems without any interaction. Three client vulnerabilities affect Zoom versions before 7.1.5 and 7.0.6 and stem from memory corruption in the text annotation feature; a fourth path traversal flaw impacts Zoom Workplace VDI Client and plugins before 7.0.11 and 6.6.15. The annotation bugs were found by A Security using an AI agent, which built a working exploit in under 24 hours, and Zoom has provided mitigations including server-side filtering and guidance to restrict optional features and enforce client version minimums.
read more →

Microsoft Patch Tuesday — August 2026 Update Summary

🛡️ Microsoft released its August 2026 Patch Tuesday with 421 vulnerabilities across many products, including 62 rated critical. One flaw has known exploitation in the wild: CVE-2026-68820 affecting the Windows Ancillary Function Driver for WinSock. The bulletin highlights numerous RCEs in Windows, Office, SharePoint, Azure services and more, and flags several high-scoring elevation-of-privilege issues.
read more →

Microsoft patches 398 vulnerabilities, including active zero-day

🛡️ Microsoft released its August security updates closing 398 CVEs, including one actively exploited Windows kernel privilege-escalation bug in afd.sys (CVE-2026-68820). Four unauthenticated RCEs affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack each score 9.8 and require prioritization based on service exposure. The release also completes a two-part SharePoint remediation started in July by fixing the RCE component.
read more →

Zoom annotation flaws allowed zero-click takeover

🛡️ Researchers found that Zoom's annotation feature could enable zero-click remote code execution between meeting participants. The flaws affected multiple Zoom clients and SDKs and were patched in June and July, before public disclosure, with no reported exploitation at publication. The bugs involve improper parsing of structured drawing objects, leading to buffer overflows, over-reads, and a use-after-free. Patches and CVE references are included in Zoom advisories.
read more →

AI-assisted exploit lets attackers assume SharePoint users

🔒 Security researchers discovered an unauthenticated bypass in Microsoft SharePoint allowing an attacker to impersonate any user, including administrators. The flaw, CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, 2019, and 2016; SharePoint Online is not listed. Rapid7 chained the bypass to an RCE, CVE-2026-63520, to run code as the Windows service account, and published analysis and a proof-of-concept. Organizations should ensure the July update is applied and watch for August patches.
read more →

CISA: SharePoint RCE Flaw Now Used in Ransomware

🔒 CISA has confirmed that ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution flaw, tracked as CVE-2026-45659. The vulnerability arises from deserialization of untrusted data and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint servers. Agencies were ordered to patch quickly and monitor for exploitation, while Shadowserver reports thousands of exposed SharePoint instances, some still unpatched.
read more →

Researchers Weaponize Windows PnP Auto-Install Flaw

🔒 Security researchers demonstrated that Windows Plug and Play auto-install can be abused to fetch signed vendor software for an emulated USB device and escalate to SYSTEM on an updated Windows 11 machine. The technique also works over Remote Desktop when low-level USB or PnP redirection is enabled, though Microsoft notes this is not enabled by default. The researchers presented their findings at DEF CON 34 and provided tooling to emulate devices and chain co-installer behavior to privileged execution.
read more →

OpenAI warns Astra may reach critical cyber capability

🔒 OpenAI says its upcoming model Astra is showing cybersecurity abilities that might meet its highest risk category, capable of autonomously finding and exploiting vulnerabilities or executing end-to-end attacks. The company made the assessment after recent internal testing and expert reviews and said it cannot rule out a Critical designation under its Preparedness Framework. OpenAI is tightening development controls, expanding monitoring, and pausing activities that don’t meet new safeguards while coordinating with governments and safety groups.
read more →

N‑able Issues Hotfixes After Active N‑central Exploitation

🔒 N‑able has issued Hotfix 2 for N‑central after detecting active exploitation of a recently disclosed RMM server vulnerability (CVE-2026-18577) first observed on July 31, 2026. The company says Hotfix 2 supersedes Hotfix 1 and provides additional hardening; on-prem customers must update to 2026.3.1.10 immediately. A limited set of customers were affected, and N‑able published IoCs plus a custom service template to scan Windows endpoints, while cautioning that results are not a guarantee of full remediation.
read more →

CISA Flags TeamCity RCE CVE-2026-63077 Patch Urged

🔒 JetBrains TeamCity on-premises installs are affected by CVE-2026-63077, a deserialization flaw enabling unauthenticated remote code execution via the agent polling protocol. An attacker can bypass authentication and run OS-level commands with the TeamCity process privileges, risking exposure of data, credentials, and build integrity. CISA reports active exploitation and urges immediate patching; federal agencies must remediate by August 8, 2026 under BOD 26-04.
read more →

CISA warns of active exploits in three products

🚨 The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive requiring federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days. The most severe issue, tracked as CVE-2026-9198, impacts Langflow and permits unauthenticated remote code execution via chained API endpoints. Vendors have released patches and a hotfix, but incomplete fixes and public proof-of-concept exploits have enabled ongoing attacks. CISA added all three flaws to its Known Exploited Vulnerabilities catalog and urged immediate remediation.
read more →

Paperclip AI flaws let attackers execute arbitrary commands

🛡️ Two critical vulnerabilities in the open-source AI control plane Paperclip allow attackers to import a malicious agent and trigger command execution on either network-accessible servers or local developer machines; a third flaw exposes sensitive control-plane details via inadequately guarded API routes. Vendors have released fixes in the source tagged v2026.416.0, which enforces stricter import permissions and hostname validation, and operators are urged to upgrade and review deployment exposure.
read more →

Critical Paperclip flaws enable remote code execution

🔒 New research from Oasis Security disclosed three vulnerabilities in Paperclip, an open-source AI agent orchestration control plane, that exposed sensitive data and allowed unauthenticated command execution on servers and developer machines. Two issues were rated critical and one carried a CVSS score of 10.0. The flaws include self-registration and CLI authorization weaknesses, missing access checks, and a DNS rebinding risk in local development mode, all of which have been patched.
read more →

Critical patches issued for Veeam, HashiCorp, and Django

🔒 Vendors HashiCorp, Veeam, and the Django Software Foundation have released fixes for 11 vulnerabilities affecting Terraform MCP Server, Veeam Service Provider Console, and Django. The most severe include an unauthenticated credential-exposure bug in Veeam (9.5), a cross-tenant token-reuse issue in Terraform MCP (10.0), and a GeoDjango spatial lookup flaw that can write files or trigger code execution. Operators are advised to upgrade to Terraform MCP Server 1.1.0+, Veeam 9.3.0.35057, and Django 6.0.8 / 5.2.17; exposure depends on configuration and none of the flaws show public exploitation as of August 5, 2026.
read more →

Critical Paperclip flaws reveal AI agent trust limits

🛡️ Security researchers disclosed multiple vulnerabilities in the open-source AI agent platform Paperclip, including an authorization bypass, exposed APIs, and a DNS rebinding weakness that could lead to remote code execution and developer-machine compromise. Oasis Security detailed how default registration and import behaviors allowed attackers to escalate privileges and execute arbitrary commands by uploading malicious agent configurations. Patches were released in versions 2026.416.0 and 0.3.1 to harden authorization, validate hostnames, and restrict risky imports.
read more →

CISA Adds Langflow, Tomcat and N‑able Flaws to KEV

🛡️ CISA on August 5, 2026, added three actively exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a critical Langflow RCE (CVE-2026-9198) and an Apache Tomcat encryption bypass (CVE-2026-34486). The advisory also includes an N-able N-central authentication bypass (CVE-2026-18556) and a related incomplete fix tracked as CVE-2026-18577. Agencies must apply available patches and mitigations promptly to prevent ongoing exploitation.
read more →

Critical Ruby on Rails image-processing vulnerability

🛡️ A critical CVE-2026-66066 in Ruby on Rails’ Active Storage can let unauthenticated attackers read sensitive files or escalate to RCE by abusing image processing via libvips. Fixed in Active Storage versions 7.2.3.2, 8.0.5.1 and 8.1.3.1, the flaw affects apps that accept untrusted uploads and use libvips; admins should update Rails, ensure libvips ≥ 8.13, rotate secret_key_base, and audit uploads and logs.
read more →