< ciso
brief />
Tag Banner

All news with #remote code execution tag

881 articles · page 5 of 45

Active SQL injection in Sangoma Switchvox exploited

🔒 Horizon3 researchers report active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Switchvox’s /pa endpoint that can lead to remote code execution. The issue was one of 12 flaws disclosed to Sangoma and patched in Switchvox 8.4.0.2 on July 14. Attackers have attempted to establish reverse shells and exfiltrate process data from internet-exposed systems, prompting urgent upgrade and compromise checks.
read more →

SQL Injection Flaw in WP Backup Plugin Risks Site Takeover

🛡️ A high-severity SQL injection in the All-in-One WP Migration and Backup plugin (CVE-2026-19949) can let unauthenticated attackers achieve remote code execution and site takeover. Discovered by Jack Taylor and reported via Wordfence, the flaw stems from incorrect parsing of escaped backslashes and quotes during archive restoration. Exploitation requires an admin to perform an export/import action, and despite a patch in version 7.110, roughly 3.25 million sites remain vulnerable.
read more →

Malicious Git configs enable code execution in agents

🔒 Manifold Security disclosed eight vulnerabilities across seven CLI AI coding agents where a repository's .git config can name commands the agent runs locally as the user, bypassing sandboxes and prompts. Some vendors have released fixes (goose, Claude Code core.fsmonitor path, Cursor), while Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained unpatched at Manifold's retest on September 1. OpenAI published related CVEs for Codex the same day.
read more →

SonicWall SMA zero-day flaws exploited in attacks

🔒 SonicWall released hotfixes for two critical vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances after confirming active exploitation. The flaws — a pre-authentication SSRF (CVE-2026-83548) and a post-authentication command injection (CVE-2026-83549) — affect SMA 6210, 7210, and 8200v on older platform-hotfix builds. SonicWall recommends upgrading to the latest fixes, searching for IoCs, and re-imaging or resetting credentials if compromises are detected.
read more →

GeoNetwork fixes chained unauthenticated RCE vulnerabilities

🛡️ GeoNetwork patched two chained vulnerabilities that allow unauthenticated remote code execution by combining a missing authorization check on the formatter upload endpoint with an unsafe Saxon XSLT configuration. The fixes were released in versions 4.4.12 and 4.2.17 on July 8, 2026, with advisory details published August 31. Vendor-sourced scans found 121 internet-exposed instances across 39 countries, many tied to government or national agencies, and administrators are urged to upgrade or block write methods to the formatter endpoint as an interim mitigation.
read more →

Critical SonicWall SMA1000 Zero-Day Flaws Exposed

🛡️ SonicWall has disclosed two zero-day vulnerabilities affecting SMA1000 appliances (models 6210, 7210 and 8200v), with impacted firmware versions 12.4.3-03453 and 12.5.0-02835 (platform-hotfix) and older. The more severe issue, CVE-2026-83548, is a pre-authentication SSRF in the Appliance Work Place interface with a CVSS score of 10.0, while CVE-2026-83549 is a post-authentication RCE in the Management Console (CVSS 7.8). SonicWall advises upgrading to the latest hotfix, contacting Technical Support to hunt for IoCs, and re-imaging or redeploying appliances and resetting credentials if compromises are found.
read more →

Researchers Use AI to Port Pre‑Auth PLC Exploit

🔎 Forescout Research - Vedere Labs used Anthropic's Claude to port a working pre‑authentication RCE exploit for CVE-2021-31886 between WAGO PLC models, achieving ARM shellcode execution on live hardware. The effort required sustained researcher steering and consumed $535.74 in API usage over an 8.5-hour session; a subsequent session accidentally bricked a PLC. CERT@VDE advises disabling FTP, enforcing network segmentation, and monitoring traffic, while noting no available firmware updates for affected devices.
read more →

SonicWall warns of exploited SMA1000 zero-days

🛡️ SonicWall warned customers that attackers are chaining two newly discovered SMA1000 zero-day vulnerabilities to achieve remote code execution. The first is a critical command injection flaw (CVE-2026-83548) tied to an SSRF issue in the Appliance WorkPlace, while the second (CVE-2026-83549) affects the Management Console and requires admin privileges. Affected models include SMA1000 6210, 7210, and 8200v; SonicWall urges immediate hotfix upgrades and recommends re-imaging and credential resets if compromise is suspected.
read more →

Five critical WordPress plugin and theme flaws

🔒 Multiple critical vulnerabilities have been disclosed in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. Reports from Wordfence and Patchstack describe issues ranging from authentication bypass and privilege escalation to arbitrary file writes and remote code execution. Affected versions span multiple releases and require immediate patching or mitigation to prevent complete site takeover.
read more →

PaperCut issues second emergency patch for exploited flaws

🛡️ PaperCut released a second emergency security update after researchers found multiple bypasses of the initial fix for actively exploited vulnerabilities in PaperCut NG/MF. The company disclosed two CVEs—CVE-2026-81578 (auth bypass, 8.8) and CVE-2026-82078 (unsafe dynamic class-loading, 9.4)—that can be chained for remote code execution. The updated Emergency Patch Release 2 provides additional hardening and is available for versions 24–26 on Windows, Linux, and macOS; administrators are urged to install it and restrict web interface access.
read more →

GiveWP plugin flaw allows remote command execution

🛡️ GiveWP, a WordPress donation plugin with over 100,000 installs, contained a critical vulnerability (CVE-2026-82222) that allowed attackers to execute arbitrary server commands. Patchstack researchers reported the issue on July 28, showing exploitation required chaining unsafe unserialization, attacker-controlled serialized donations, and a bundled gadget chain. The vendor released a patch in version 4.16.7.2 on August 27 that blocks serialized payloads and cleans affected databases.
read more →

Attackers Chain Two PaperCut Flaws to Achieve RCE

🛡️ Huntress and watchTowr reported attackers chaining two recently patched PaperCut vulnerabilities to bypass authentication and achieve remote code execution. PaperCut released a second emergency patch with additional hardening after disclosure of CVE-2026-81578 and CVE-2026-82078. Observed activity includes execution of Base64-encoded commands and deployment of a cross-platform Java .class file used for reconnaissance and cleanup.
read more →

Thousands of Gitea Servers Remain Vulnerable to RCE

🔒 Shadowserver reports over 8,300 Internet-exposed Gitea instances remain unpatched against a critical code injection flaw (CVE-2026-60004) exploited in active remote code execution attacks. The vulnerability, disclosed by a Salesforce researcher, lets authenticated users execute shell commands via the diffpatch API, and default open registration enables easy exploitation. Gitea issued version 1.27.1 on July 27 to fix the issue and urged immediate upgrades, while CISA added the flaw to its actively exploited catalog and ordered federal agencies to patch swiftly.
read more →

Two root RCE chains found in Unitree G1 EDU

🔒 Security researcher Olivier Laflamme disclosed two independent root remote code execution (RCE) chains impacting the Unitree G1 EDU, tracked as CVE-2026-76639 and CVE-2026-76640. One path is network-adjacent via chat_go and bashrunner, the other begins from an unauthenticated BLE bootstrap write leading to Wi‑Fi provisioning and a buffer overflow. Unitree's cloud account-to-robot ownership check was reportedly patched in July 2026, but no fixed firmware release has been publicly confirmed for the G1 EDU.
read more →

Critical cPanel flaw allows root code execution

🛡️ cPanel released patches for a critical vulnerability (CVE-2026-65643) affecting domain parking and addon domain handling in cPanel & WHM that could let authenticated users create arbitrary files and achieve root code execution. The company published fixed builds across multiple release branches on August 27, 2026, and advised administrators to update immediately or enable automatic updates. The advisory names patched builds including a WP Squared release, omits DNSOnly, and provides no interim mitigation or CVSS score. Servers on end-of-life versions must upgrade to receive the fix.
read more →

Next.js fixes critical RCE via AVIF and Windows path

🔒 Vercel released urgent patches for two critical remote code execution flaws in Next.js: one triggered by specially crafted AVIF images and another by a Windows-specific path traversal. Fixes are available in Next.js 15.5.24 and 16.3.3 published August 25, 2026; Vercel-hosted apps are already protected. Users on affected versions should upgrade immediately, especially Windows-hosted servers which have no workaround.
read more →

CISA directs urgent patching for Citrix NetScaler RCE

🔒 CISA has ordered federal agencies to patch Citrix NetScaler appliances by Saturday due to an actively exploited vulnerability, CVE-2026-8452. The flaw is a memory overflow affecting NetScaler ADC and Gateway appliances configured with Gateway VPN or AAA virtual servers and can lead to unpredictable behavior, DoS, or remote code execution. Researchers have observed active exploitation in attacks deploying web shells, and Citrix's advisory has not yet acknowledged in-the-wild targeting. Shadowserver currently tracks thousands of exposed NetScaler instances online.
read more →

Critical Avada WordPress Theme Zero-Click RCE

🛡️A chain of six vulnerabilities in the Avada WordPress theme and Fusion Builder plugin allows an unauthenticated attacker to execute arbitrary PHP code via a zero-click exploit. Tracked as CVE-2026-18431 with a 9.8 score, the attack requires a precise sequence of authorization, input-validation, trust-boundary, and file-handling failures. ThemeFusion released patches in Avada 7.16.1 and Fusion Builder 3.16.1 after disclosure by Wordfence, which withheld full details to allow administrators time to update.
read more →

Attackers Target SharePoint RCE Chain and PoC Exploits

🛡️ Defused warns attackers are chaining two Microsoft SharePoint flaws — CVE-2026-55040 and CVE-2026-63520 — to achieve remote code execution on unpatched servers. Public proof-of-concept exploits were published in August and were quickly weaponized, with probes observed against honeypots and large-scale internet-exposed SharePoint instances. CISA has issued directives to secure SharePoint servers while Microsoft monitors exploitation activity.
read more →

Ubiquiti fixes three maximum-severity vulnerabilities

🔒 Ubiquiti released patches for three maximum-severity vulnerabilities affecting UniFi applications and OS. The flaws include a remote exploit in the UniFi Protect Application, a CRLF injection (CVE-2026-77550) that can bypass authentication on UniFi OS devices, and a command injection in the UniFi Talk VoIP system (CVE-2026-77554). Patches are available in UniFi Protect 7.2.105+, UniFi Talk 5.3.2+, and UniFi OS Server 5.1.21+.
read more →