< ciso
brief />
Tag Banner

All news with #remote code execution tag

881 articles · page 3 of 45

Active exploitation of two high‑severity Check Point flaws

🔒 Check Point Research reports active exploitation of two critical vulnerabilities affecting Security Gateway and Security Management. CVE-2026-85102 (RCE during VPN certificate handling) had patches available since September 9 and is being actively probed; unpatched Spark customers are at risk. CVE-2026-93616 is a newly observed pre-authentication path traversal zero-day in Management; a fix is available now. Customers should install vendor fixes immediately and follow published mitigation and hunting guidance.
read more →

D-Link warns of critical zero-day in DIR-822A routers

🔒 D-Link disclosed a max-severity zero-day affecting DIR-822A routers that stems from a stack-based buffer overflow in the DHCP server component and can be exploited without authentication. Attackers on the same local network can send crafted DHCP packets to crash the DHCP daemon or achieve remote code execution. The vendor noted a public proof-of-concept exploit and is investigating a second public PoC for an L2TP parser out-of-bounds write.
read more →

Critical CVE-2026-93952 in VeloCloud Orchestrator

🛡️ Arista disclosed CVE-2026-93952, a critical vulnerability in on-premises VeloCloud Orchestrator (VCO) that can allow a remote attacker with no login to privilege internal functions on orchestrators configured for certificate-based Edge authentication. Fixed releases are available for the 5.2 and 6.4 trains and for Hosted and Dedicated VCOs; 6.1 and 7.0 fixes are pending. Arista rated the flaw CVSS 3.1 10.0 and said it was discovered externally and is actively exploited.
read more →

SharePoint flaw reclassified as remote code execution

🛡️ Microsoft initially labeled a SharePoint Server bug as a spoofing issue, but researcher Dinh Ho Anh Khoa's full disclosure shows it enables authenticated remote code execution. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition and was patched in August; the NVD assigns it an 8.8 score. Khoa's write-up details how unescaped quotes in Register directives allow arbitrary .NET class loading and execution via XamlServices.Parse().
read more →

WordPress Comment2Shell vulnerability patched

🛡️ WordPress fixed a critical flaw, CVE-2026-93485 dubbed Comment2Shell, on September 17 in version 7.1.1 after a researcher showed how a crafted comment could plant a hidden script that executes when a page is viewed. The bug allowed that script to act with the viewer's privileges and, if an administrator viewed the page, to leverage the admin session to upload a plugin web shell. Site owners are urged to update immediately or temporarily disable comments and consider WAF or security plugin mitigations.
read more →

WordPress Click2Shell flaw enables remote PHP execution

🛡️ A newly disclosed WordPress CSRF vulnerability named Click2Shell allows pre-authenticated remote code execution by forcing the installation of a theme from the WordPress.org catalog and running arbitrary PHP. The issue, fixed in WordPress 7.1.1, was reported by researcher Paulos Yibelo of pwn.ai and relies on a buggy interpretation of a theme-preview URL combined with JavaScript in the admin browser. An attacker needs no account but requires a logged-in administrator to visit a crafted link, enabling server-side code execution and potential data or file theft. Patchstack notes only administrators can trigger the chain and advises updating or enabling DISALLOW_FILE_MODS as a temporary mitigation.
read more →

OpenAI security gaps persist despite heavy investment

🔒 Two recent reports reveal security flaws in OpenAI systems that allowed researchers to chain vulnerabilities and bypass sandbox controls. One team leveraged an image library flaw to gain remote code execution and used stolen tokens to access employee accounts and internal repositories; fixes were applied after coordinated disclosure. Another group demonstrated Codex sandbox escapes that enabled the agent to act beyond intended limits; those issues were also patched within days.
read more →

Researchers Escape OpenAI Codex Sandbox to Run Commands

🛡️ Security researchers discovered two sandbox escapes in OpenAI's Codex that allowed untrusted agent code to execute commands on a developer's machine without prompts or visible output. Reported on August 12 and fixed within eight days, the vulnerabilities — dubbed Heapjack and Overpatch — exploit a shared memory token in a Node.js REPL and an overly permissive patch tool in the CLI. OpenAI released fixes in Codex Desktop build 26.818.21641 and Codex CLI 0.149.0; users should update immediately.
read more →

SolarWinds fixes high-severity ARM flaw

🔒 SolarWinds released updates to fix a high-severity vulnerability in Access Rights Manager (ARM) that could enable unauthenticated remote code execution. Tracked as CVE-2026-28326 and rated 8.8, the issue affects ARM 2026.2 and earlier and is addressed in ARM 2026.2.1. The flaw, attributed to a hard-coded static key, was reported by researcher Kai Huang from Armadin. No active exploitation has been reported.
read more →

Critical Pre‑Auth RCE in Orkes Conductor Actively Exploited

🛡️ Fortinet and other telemetries report active exploitation of CVE-2026-58138, a critical unauthenticated remote code execution flaw in Orkes Conductor. The vulnerability affects versions 3.21.21 through 3.30.1 and allows attackers to execute arbitrary OS commands by submitting crafted workflow definitions containing JavaScript or Python expressions to the workflow API. Exploits leverage unsandboxed GraalVM evaluators with unrestricted host access, and multiple vendors have observed in-the-wild attempts. Users are urged to upgrade to Conductor 3.30.2 or later and apply network mitigations if immediate patching is not possible.
read more →

WordPress Click2Shell forced theme install patched

🔒 WordPress issued an urgent security patch (7.1.1) to address a vulnerability dubbed Click2Shell discovered by pwn.ai, which can cause a crafted link opened by a logged-in administrator to install an official WordPress.org theme without clicking Install. The core bug alone installs a legitimate theme, but chained with a separate theme flaw it can lead to remote code execution. Site operators should update immediately; affected branches back to 4.7 received fixes.
read more →

Plugin4Shell: Zero‑Click RCE in AI Coding Agents

🔒 Researchers discovered a zero-click vulnerability called Plugin4Shell affecting AI coding agents like Codex, Claude Code, Gemini CLI, and GitHub Copilot, allowing attackers to swap trusted plugins for malicious ones and execute code without developer interaction. The flaw stems from agents passing a Git commit SHA to Git but not verifying the checked-out commit, enabling repository owners or takeovers to resolve a malicious version under the expected identifier. Some vendors have patched the issue, while others have deprecated components or applied mitigations; enterprises are urged to inspect affected machines and audit logs.
read more →

Critical Check Point flaw allows root code execution

🔒 Check Point Software released updates for a critical stack-based buffer overflow (CVE-2026-91843) in Security Management Server and Log Server login flows that can enable remote root code execution without user interaction. The vendor offered temporary mitigations, including system hardening and restricting trusted client IPs in SmartConsole, and advised teams to watch for "Administrator failed to log in: Username too long" alerts. The issue is part of a series of recent critical patches affecting Check Point firewalls and management systems.
read more →

Critical Check Point Management Server Flaw Alert

🔒 A critical stack overflow vulnerability (CVE-2026-91843) in Check Point Security Management and Log Servers can allow unauthenticated attackers to execute code as root over the network. Check Point issued a LivePatch fix and says it has no evidence of exploitation; customers with automatic updates enabled may already be protected. Administrators should apply sk1000155, confirm LivePatch installation, and limit Trusted Clients to known hosts while avoiding direct Internet exposure.
read more →

Critical Unbound DNSSEC Validator Heap Overflow Fix

🛡️ NLnet Labs released Unbound 1.26.1 to address a critical heap overflow in the DNSSEC validator affecting every release prior to 1.26.1. The overflow (CVE-2026-81642) can be triggered by an attacker controlling a malicious zone and may allow denial of service or remote code execution; eight additional flaws were also patched. Source, binaries, and Windows installers are available, and the advisory provides standalone and combined patches for those unable to upgrade.
read more →

Gyazo breach exposes millions of user records

🔒 Helpfeel's image-sharing service Gyazo disclosed a breach that exposed about 23.62 million user records and roughly 490 million image metadata records, mostly from January 2019 or earlier. The attacker exploited a vulnerability in Gyazo's image upload server to run arbitrary commands and access the database; Helpfeel has disabled some image viewing and urged users to change passwords and watch for suspicious messages. The company says no payment data was exposed and external forensics are ongoing.
read more →

Critical Issabel Framework JWT RCE Under Active Exploitation

🔒 A critical vuln, CVE-2026-89026, in the Issabel Framework allows unauthenticated remote attackers to execute OS commands by exploiting a hard-coded HS256 JWT signing key. The flaw enables forged bearer tokens to call the '/pbxapi/manager/originate' endpoint, triggering Asterisk to run arbitrary commands as the Asterisk user. A patch released on August 1, 2026, replaces the embedded key with a key in /etc/issabel.conf. Shadowserver reported active exploitation starting September 9, 2026; users should apply the update immediately.
read more →

Critical RCE in WooCommerce Wholesale Lead Capture

🛡️ Wordfence reports attackers uploading PHP webshells via a critical flaw in the premium WooCommerce Wholesale Lead Capture plugin. The vulnerability (CVE-2026-27540) was patched in version 2.0.3.2 on February 20, but exploitation attempts—over 100,000 blocked—continued months later. Site owners should update immediately, scan uploads directories, and check access logs for the vulnerable AJAX action.
read more →

Critical RCE Flaw Exploited in WooCommerce Plugin

🔒 Wordfence has observed active exploitation of a critical vulnerability (CVE-2026-27540) in the premium WordPress plugin WooCommerce Wholesale Lead Capture, enabling unauthenticated attackers to upload arbitrary files and achieve remote code execution. The flaw affects versions up to 2.0.3.1 and has prompted over 100,000 blocked exploit attempts since June 2026. Site owners should inspect for unexpected .php files and suspicious admin-ajax requests referencing the "wwlc_file_upload_handler" action.
read more →

Critical WooCommerce Plugin Flaw Enables PHP Webshells

🔒 Hackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin (CVE-2026-27540) to upload PHP webshells and execute code on affected WordPress sites. The unauthenticated arbitrary file-upload flaw affects versions 2.0.3.1 and older and was fixed in version 2.0.3.2 released February 20. Wordfence blocked over 100,000 related attacks and urges administrators to update, scan for unexpected PHP files, check logs for wwlc_file_upload_handler requests, and restore from clean backups if compromised.
read more →