< ciso
brief />
Tag Banner

All news with #remote code execution tag

881 articles · page 4 of 45

CISA: Critical VMware vCenter RCE Now Exploited

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that ransomware gangs are now exploiting a critical VMware vCenter vulnerability (CVE-2026-59310) patched by Broadcom on July 29. The flaw is a directory traversal issue in the vCenter Syslog server that allows unauthenticated attackers to execute arbitrary code; Broadcom urged emergency patching. Security firms reported widespread compromises and CISA added the CVE to its KEV Catalog, ordering rapid remediation across government systems.
read more →

Critical Cisco Secure Email Gateway zero-day exploited

📣 Cisco warned customers of an actively exploited zero-day in Secure Email Gateway that allows unauthenticated remote attackers to execute arbitrary commands as root. The flaw stems from insufficient validation in email parsing and malicious SQL in crafted messages. Cisco released patches and IOC guidance, while CISA added CVE-2026-76461 to its KEV Catalog, ordering federal fixes within three days.
read more →

Red Heron exploits Gitea RCE to target sectors

🔎 Acronis TRU attributes a rapid, multi-country campaign to suspected China-linked actor Red Heron that weaponized a disclosed Gitea RCE (CVE-2026-60004) to compromise internet-facing instances. The operator scanned and exploited hundreds of servers, stole source code and secrets, and escalated to persistent access and lateral movement, including root control of a Proxmox cluster. Analysts identified a C++ implant JITTERLY and an LD_PRELOAD rootkit SIXZUT used to hide activity and maintain persistence.
read more →

Smart TV and Set‑Top Box Proxyware Risks

🛡️ A recent analysis shows cheap smart TVs and TV boxes are increasingly recruited into proxyware and botnets, turning household devices into gateways for malicious traffic. Infected devices often run multiple proxy clients concurrently and can expose internal network resources, allowing remote attackers to reach router admin panels and other devices. The study of a popular SuperBox model revealed persistent malware, remote code execution via firmware flaws, and over 1,300 attacks in three weeks. Users are advised to monitor network traffic, avoid dubious apps and devices, disconnect compromised hardware, and protect routers with strong unique passwords and reputable security tools.
read more →

ConnectWise patches critical ScreenConnect flaw

🔒 ConnectWise issued an update for ScreenConnect five days after warning customers that active remote sessions could be used to transfer and execute files without authorization. Administrators were advised on Sept. 3 to remove the TransferFiles permission from any users with open sessions. The vulnerability, tracked as CVE-2026-84869, is fixed in ScreenConnect client version 26.6.5 and later. The update follows prior security incidents, including a 2025 nation-state attack and earlier 2024 exploitation reports.
read more →

Check Point patches two 9.8-rated VPN certificate flaws

🔒 Check Point released fixes on September 9 for two critical VPN certificate vulnerabilities affecting its Security Gateway appliances and Security Management Server. Both flaws — CVE-2026-85102 (certificate trust validation) and CVE-2026-85103 (ASN.1 heap overflow) — carry a CVSS score of 9.8 and could, under specific conditions, allow unauthenticated remote code execution. The company deployed fixes via Live Patch and Jumbo Hotfixes, but customers reported rollout delays, broken advisory links, and incomplete version clarity. Check Point says it discovered the issues internally and has no evidence of active exploitation.
read more →

WeChat zero-click worm hijacks accounts via calls

🛡️ A Palo Alto startup, Calif, developed a tool called WeWorm that exploits a remote code execution flaw in WeChat's VoIP stack to compromise Android and iOS devices via incoming calls. Researchers say the zero-click exploit required no user interaction and can hijack accounts to read/send messages and make calls. Tencent patched the vulnerability in Android 8.0.77 and iOS 8.0.76 after being notified, and Calif warns the worm could scale further when combined with other bugs.
read more →

Chrome V8 zero-day patched amid active exploitation

🛡️ Google released updates addressing 230 security vulnerabilities in Chrome, including an actively exploited medium-severity V8 out-of-bounds write (CVE-2026-87491). The flaw, reported by Jihyeon Jeong of Compsec Lab on August 6, 2026, allows remote code execution inside the sandbox via a crafted HTML page. Google confirmed an exploit exists in the wild and urges users to update to Chrome 153.0.8010.36/.37 on supported platforms. The patch also fixes multiple critical WebGL and Cast issues and CISA later added CVE-2026-87491 to its KEV catalog.
read more →

SAP issues emergency kernel patches for critical flaws

🛡️ Onapsis has disclosed a maximum severity memory corruption vulnerability in the SAP kernel, tracked as CVE-2026-44756, which may affect over 10,000 internet-facing SAP systems. The bug exists in SAP Extended Passport (EPP) Processing and can be triggered remotely without authentication via crafted network requests, potentially allowing attackers to execute arbitrary OS commands with SAP admin privileges. Onapsis also warned of several other critical issues, including S4GET (CVE-2026-58240) and additional high-severity flaws, and urged customers to apply SAP security notes immediately.
read more →

SAP issues emergency patches for critical kernel flaws

🔒 SAP released urgent security updates to fix multiple critical vulnerabilities, including a maximum-severity (CVSS 10.0) memory corruption bug in EPP Processing (CVE-2026-44756, "OVERPASS") discovered by Onapsis. The flaw is remotely exploitable without authentication and can lead to OS command execution with SAP administrative privileges, risking full compromise of business data and processes. SAP also patched CVE-2026-58240 ("S4GET") in NetWeaver Message Server and two other high-severity issues affecting CAP and SAP GUI for Java.
read more →

Microsoft Patch Tuesday: September 2026 Vulnerabilities

🔒 Microsoft released its September 2026 security update covering 973 vulnerabilities across many products, including 113 marked critical. Two vulnerabilities were reported exploited in the wild: one in the Windows Update Stack (CVE-2026-81963) and one in Windows ALPC (CVE-2026-85880). The bulletin highlights numerous remote code execution and elevation-of-privilege issues, with several high CVSS scores and multiple components prioritized for remediation.
read more →

Adobe issues emergency patch for Magento zero-day

🛡️ Adobe has released emergency patches addressing a maximum-severity zero-day, CVE-2026-75650, actively exploited in Adobe Commerce and Magento Open Source. Sansec dubbed the flaw "StyleSmuggler" after detecting exploitation beginning September 4, 2026. The vulnerability enables PHP code injection via Magento's template system to generate a malicious email and achieve remote code execution. A VULN-39341 hotfix and encryption key rotation are required to remediate affected versions.
read more →

N‑able issues hotfix for critical N-central RCE

🔒 N-able has released a hotfix addressing a critical pre-authentication remote code execution vulnerability, CVE-2026-86218, in its N-central monitoring and management platform. The flaw, given a maximum CVSS score of 10, impacts N-central versions before 2026.3.1.14 and could allow unauthenticated code execution on the server. N-able patched the issue in N-central 2026.3 Hotfix 4 (build 2026.3.1.14) and reports no evidence of in-the-wild exploitation. This follows several recent high-severity vulnerabilities and prior hotfixes.
read more →

Telerik RadAsyncUpload padding oracle leads to RCE

🔒 Security researcher TantoSec published a proof-of-concept that chains an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution against applications in a specific, non-default configuration. Progress shipped a patch in July (2026.2.708) and published CVEs, and there are no confirmed in-the-wild exploit reports as of September 7. The chain targets RadAsyncUpload versions through 2026.2.519 and relies on an explicit custom encryption key and a server-side handler that reads upload results.
read more →

N‑able issues fourth hotfix for N‑central RMM

🔒 N‑able released Hotfix 4 (build 2026.3.1.14) for its N‑central RMM to fix CVE-2026-86218, a pre-auth remote code execution vulnerability affecting all on‑premises builds prior to 2026.3.1.14. The company says hosted instances are patched and urges on‑premises customers to upgrade immediately; agents do not require updates. Communications diverge on whether the flaw has been observed exploited in the wild, and no indicators of compromise or interim mitigations were provided.
read more →

N‑able issues emergency hotfix for critical N-central RCE

🔒 N-able released an emergency hotfix addressing a maximum-severity remote code execution flaw in its N-central RMM platform. Tracked as CVE-2026-86218, the vulnerability allows unauthenticated attackers to execute code on internet-exposed instances. N-able issued N-central 2026.3 Hotfix 4 and urged immediate on-premises upgrades, while Shadowserver reports nearly 1,500 exposed servers. Security firms flagged related high-severity bugs and evidence suggesting active exploitation cannot be ruled out.
read more →

Google patches active Chrome zero-day in V8 engine

🔒 Google released an urgent Chrome update to fix an actively exploited high-severity zero-day (CVE-2026-85046) in the V8 JavaScript engine along with 11 other vulnerabilities across Windows, macOS, and Linux. The type confusion bug, reported by researcher Salvatore Gulizia (“Serotav”), can be triggered by crafted web content and may lead to remote code execution within Chrome’s sandboxed renderer. Google withheld technical exploit details while rolling out Chrome 152.0.7977.82/.83 to give users time to update; a restart is required once the update downloads.
read more →

Mass exploit attempts target WordPress plugins

🛡️ Wordfence reports that threat actors have been actively exploiting critical vulnerabilities in the WordPress plugins Super Forms and Elementor Pro, enabling unauthenticated file uploads that lead to remote code execution. Both flaws permit attackers to upload PHP web shells, which can be used to create admin accounts, exfiltrate data, or seize control of sites. Over 440,000 exploit attempts have been blocked, and site owners are urged to apply patches and scan for compromises.
read more →

Critical Cisco Nexus 9000 Flaw and IOS XR Hardening

🔒 Cisco released patches for a critical Nexus 9000 vulnerability (CVE-2026-20212) that allows unauthenticated remote root code execution via TCP ports 43210 and 43211. The advisory affects 10 Silicon One-based Nexus 9000 PIDs and lists mitigations including iACLs and a Live Protect shield while customers use the Software Checker to pick fixed releases. Cisco also published an IOS XR hardening release bundling seven umbrella CVEs, two rated 9.8, and provided SMUs and upgrade guidance for affected XR trains.
read more →

Critical Elementor Pro flaw exploited to hijack sites

⚠️ A critical vulnerability (CVE-2026-32475) in Elementor Pro was patched on August 19 after active exploitation that uploads webshells and enables remote command execution. The flaw affects versions 4.2.1 and earlier and abuses faulty file-upload array validation in forms with a File Upload field. Wordfence blocked nearly 200,000 attempts and advises immediate upgrade to 4.2.2 and checks for rogue PHP files in uploads.
read more →