< ciso
brief />
Tag Banner

All news with #remote code execution tag

881 articles · page 2 of 45

Critical NetScaler zero-days demand immediate patch

🔒 Citrix has confirmed two critical unauthenticated remote code execution zero-day vulnerabilities in NetScaler ADC and NetScaler Gateway that are under active exploitation and must be patched immediately. Citrix released fixes in versions 14.1-73.37 and later and 13.1-64.23 and later, and urged customers to install updates as soon as possible. The US CISA added both to its KEV catalog while Citrix published additional mitigations, IOCs and fixes for six other related vulnerabilities.
read more →

Citrix issues urgent patches for critical NetScaler flaws

🔐 Citrix has released updates addressing eight vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, including two critical zero-days that were actively exploited. The most severe issues — CVE-2026-88771 and CVE-2026-88772 — enable unauthenticated remote code execution in default deployments and in DTLS-enabled configurations respectively. Agencies including CISA and the ACSC have issued emergency patching guidance, and Citrix urges customers to install updates immediately.
read more →

CISA Adds Two Critical Citrix NetScaler Flaws to KEV

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical Citrix NetScaler ADC and Gateway vulnerabilities to its Known Exploited Vulnerabilities (KEV) list after reports of active exploitation. Both issues carry CVSS scores of 9.5 and can lead to remote command execution or denial-of-service; one requires DTLS to be enabled. Citrix has released patched versions and provided IoCs through the NetScaler Console to help customers detect compromises.
read more →

Two Unpatched Citrix NetScaler Zero-Days Exploited

🔔 Security firm watchTowr reported on September 26 that two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway allow remote code execution and are being actively exploited. Citrix has not confirmed the flaws or released a fix, and some administrators have taken appliances offline as a precaution. The vulnerabilities are distinct from the earlier CVE-2026-19490 authentication bypass patched on August 19.
read more →

CISA Adds SharePoint and MikroTik Flaws to KEV List

🔐 CISA has added two actively exploited vulnerabilities—CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS—to its Known Exploited Vulnerabilities catalog. Microsoft updated its advisory to reflect that the SharePoint issue can be leveraged for remote code execution, while CERT Polska and researchers linked RouterOS flaws to a full administrative takeover exploit called MikroTrick. Federal agencies must patch these issues by September 28, 2026.
read more →

Critical WordPress RCE CVE-2026-87902 Patch Alert

⚠️ A critical Remote Code Execution vulnerability, CVE-2026-87902, affects WordPress versions 4.7.0 through 7.1.1 and allows arbitrary PHP file inclusion leading to potential code execution. WordPress released patches on September 22 (latest recommended version 7.1.2 or newer), but exploit attempts were observed within hours. Site owners should update immediately and follow recommended hardening measures to complement the patch.
read more →

CISA Adds Critical WSO2 and Adobe Flaws to KEV

🔒 CISA has added two critical vulnerabilities—affecting WSO2 and Adobe Commerce/Magento—to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaws include a path traversal and unrestricted file upload in WSO2 leading to remote code execution, and an authorization bypass in Adobe Commerce that allows customer account takeover. Federal agencies are advised to patch by September 27, 2026.
read more →

WordPress critical RCE flaw patched; rapid attacks follow

🔒 WordPress released a security update fixing a critical remote code execution vulnerability (CVE-2026-87902) that allows unauthenticated attackers to include and execute readable local PHP files outside active theme directories. The flaw, reported by researcher Robert Ressl, has been backported to versions as far back as 4.7 and has already seen exploitation in the wild. Security firms observed reconnaissance within hours and active payload delivery within a day, prompting urgent calls for fast, verified patch rollouts and increased visibility of forgotten WordPress instances.
read more →

Critical VeloCloud Orchestrator vulnerability impacts on-prem

🔒 Arista warned of a critical flaw in on-premises VeloCloud Orchestrator that allows remote attackers to access privileged internal functionality and potentially compromise the VSO host. The issue, tracked as CVE-2026-93952 with a CVSS score of 10.0, is actively exploited and affects multiple VCO release trains, though fixes are available only for some versions. Arista recommends immediate upgrades where patches exist and, for those that cannot upgrade, restricting web interface access and monitoring for suspicious indicators of compromise.
read more →

F5 patches critical BIG-IP APM zero‑day flaw

🔒 F5 released fixes for a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) that was actively exploited in the wild. The heap-based buffer overflow, tracked as CVE-2026-94127 and rated 9.8, affects deployments configured as OAuth authorization servers and can also impact appliance-mode systems when both APM and an OAuth authorization server profile are enabled. F5 published hotfixes for the 21.x, 17.5.x and 17.1.x branches and provided an iRule mitigation while patches are applied.
read more →

Check Point warns of Security Gateway VPN RCE exploit

🔒 Check Point confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution flaw in the VPN certificate-handling of its Security Gateway product, and warned of active abuse of CVE-2026-93616 affecting the Management web service. The company reported attacks beginning September 12, 2026, originating from anonymization services, and advised administrators to apply LivePatch Take 26 or specified Jumbo Hotfixes, update Spark firewalls, and follow temporary VPN rule restrictions if updates are not possible.
read more →

Critical WordPress flaw exploited for remote code execution

🔍 Threat actors have progressed from scanning for CVE-2026-87902 to actively exploiting the vulnerability to write files that execute shell commands when accessed. Patchstack observed initial reconnaissance less than five hours after WordPress 7.1.2 was released, with malicious activity increasing tenfold as attackers began delivering payloads. The flaw, discovered by Robert Ressl, is an unauthenticated path traversal that can lead to RCE under specific theme and server conditions. Administrators are urged to update to WordPress 7.1.2 and review logs for indicators of compromise.
read more →

MikroTrick RouterOS SSH Chain Grants Full Access

🔒 CERT Polska details a two-bug chain named MikroTrick that lets attackers gain full administrative control of Internet-exposed MikroTik RouterOS devices without a password. The chain combines an SSH state-machine flaw (CVE-2026-67279) and an argument-injection bug in the login process (CVE-2026-86060); exploitation traces predate vendor patches. Administrators are urged to apply updates and inspect devices for indicators such as a '-2' login, unexpected 'ops' accounts, and suspicious network activity.
read more →

Critical cPanel flaws enable root and cross-account access

🔒 cPanel disclosed three vulnerabilities affecting its CalDAV/CardDAV service and the WP Toolkit plugin on September 22. One flaw (CVE-2026-87899) allows any logged-in hosting account to execute code as root, while another (CVE-2026-87900) lets a cPanel user modify databases belonging to other accounts. A third issue (CVE-2026-68490) permits local users to read other accounts' calendars and contacts without altering them. Fixed versions for cPanel & WHM and WP Toolkit have been published, and cPanel provides update instructions but no temporary mitigations.
read more →

F5 BIG‑IP APM critical OAuth RCE patched

🛡️ F5 has disclosed and patched a critical heap‑based buffer overflow, CVE-2026-94127, in BIG‑IP Access Policy Manager when it is configured as an OAuth authorization server. The vulnerability allows unauthenticated remote code execution via specially crafted traffic to a virtual server hosting an APM access policy and an OAuth authorization server profile. F5 released engineering hotfixes for affected 21.1, 17.5 and 17.1 branches and provided an iRule mitigation for cases where immediate patching is not possible.
read more →

Chinese Hackers Exploit Chrome–Windows Zero‑Day Chain

🛡️ Volexity researchers observed UTA0565 exploiting a newly disclosed Google Chrome–Windows exploit chain on September 3–4, 2026, via fake websites. The actor chained two Chrome flaws (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC vulnerability (CVE-2026-85880) to escape the browser sandbox and achieve remote code execution. Phishing lures impersonated media and NGOs, delivering a BlueMoon-based loader that fetched a CLEANGULP executable named "chrome_cleanup.exe". CLEANGULP provides remote shell, process listing, file upload/download, and BOF execution, and uses a spoofed C2 domain mimicking a legitimate outlet.
read more →

F5 warns of BIG‑IP APM RCE zero‑day being exploited

🔒 F5 released updates to fix a critical BIG‑IP APM zero‑day that is being actively exploited for remote code execution. The flaw affects deployments with APM configured as an access policy and OAuth profile on virtual servers; pure OAuth Client/Resource Server setups without authorization server profiles are not impacted. F5 urged admins to search for indicators like multiple OAuth failures and TMM SIGABRT events and provided an iRule mitigation for those unable to patch immediately.
read more →

Critical Next.js ImageResponse remote code risk fixed

🛡️ Vercel disclosed a critical vulnerability in Next.js ImageResponse that could allow remote code execution when untrusted values are embedded in SVG content during image generation. The flaw affects Next.js 16.2.0 through 16.3.5 on the Node.js runtime and was patched in version 16.3.6 on September 22. The issue stems from Satori incorrectly allowing unescaped values into SVG output; users of Satori should update to 0.33.5. Workarounds include avoiding attacker-controlled values in SVG content.
read more →

WordPress issues urgent patch for critical flaw

🛡️ WordPress released updates on September 22 to fix a critical template-handling vulnerability (CVE-2026-87902) that lets unauthenticated attackers cause a site to load PHP files from outside theme folders. The flaw affects versions 4.7.0 through 7.1.1 and was rated CVSS 9.2. Site owners are urged to update to the listed patch for their branch immediately; automatic updates will apply for sites with that setting enabled.
read more →

Critical Bifrost AI gateway flaw allows remote code

🛡️ A critical vulnerability in Bifrost, an open-source AI gateway, lets unauthenticated attackers execute arbitrary commands on the gateway server via a single HTTP request when management authentication is disabled. Tracked as CVE-2026-90898 (CVSS 9.8), the flaw affects HTTP transports before transports/v2.1.0 and is exploitable by registering a stdio-type MCP client through the management API; a fix is available in v2.1.0. Operators should upgrade, enable management auth, and rotate exposed keys if the management API was reachable.
read more →