< ciso
brief />
Tag Banner

All news with #remote code execution tag

882 articles · page 6 of 45

Ubiquiti fixes three maximum-severity vulnerabilities

🔒 Ubiquiti released patches for three maximum-severity vulnerabilities affecting UniFi applications and OS. The flaws include a remote exploit in the UniFi Protect Application, a CRLF injection (CVE-2026-77550) that can bypass authentication on UniFi OS devices, and a command injection in the UniFi Talk VoIP system (CVE-2026-77554). Patches are available in UniFi Protect 7.2.105+, UniFi Talk 5.3.2+, and UniFi OS Server 5.1.21+.
read more →

Unpatched Kaltura mwEmbed flaws enable file read and RCE

🛡️ CERT/CC disclosed two unpatched vulnerabilities in Kaltura's mwEmbed/html5lib player that allow unauthenticated remote file reads and remote code execution via unsafe PHP deserialization. The flaws (CVE-2026-19913 & CVE-2026-19912) stem from mwEmbedLoader.php accepting an attacker-controlled ServiceUrl and using PHP's unserialize() without validation. No patch is available and CERT/CC was unable to reach Kaltura; administrators are advised to restrict endpoint access, allow-list ServiceUrl, and take mitigation steps including rotating credentials in local.ini.
read more →

Marimo notebook MCP command injection patched

🛡️ Marimo fixed a high-severity code injection that let a crafted notebook supply a malicious Model Context Protocol (MCP) command executed as a local subprocess when opened in edit mode. Tracked as CVE-2026-75149 and scored ~8.7–8.8, the flaw affected versions prior to 0.23.15 and required user interaction but no attacker authentication. Marimo released version 0.23.15 and later versions to remediate the issue.
read more →

CISA orders urgent Zimbra patching for active exploit

🔔 The Cybersecurity and Infrastructure Security Agency (CISA) directed U.S. federal civilian agencies to patch an actively exploited Zimbra Collaboration Suite flaw (CVE-2026-73570) within three days after CERT Polska reported in-the-wild attacks. The flaw, fixed in Zimbra 10.1.20 released July 20, permits unauthenticated remote code execution via a command injection in the SNMP notification component when enabled. Administrators are urged to review recent logs for indicators such as unexpected service restarts and newly created files under zimbra-owned webapps and /tmp directories.
read more →

CISA orders federal patching for TrueConf flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently patch two actively exploited critical vulnerabilities in the self-hosted TrueConf Server communications platform. The flaws, tracked as CVE-2026-72529 and CVE-2026-72530, allow unauthenticated remote code execution through a missing authentication function and complex code-injection attacks. CISA added both issues to its KEV catalog and mandated fixes within two weeks due to significant risk to the federal enterprise.
read more →

Microsoft patches critical Entra ID deserialization flaw

🔐 Microsoft patched a maximum-severity vulnerability in Entra ID that was exploited in attacks, tracked as CVE-2026-69836. Discovered by Microsoft engineer Robert Fitzpatrick, the flaw allowed unauthenticated actors to achieve code execution via deserialization of untrusted data. Microsoft states the issue is fully mitigated and no user action is required, and said exploit code is not publicly available. The company provided limited additional details on the incidents.
read more →

Critical sandbox escape patched in isolated-vm

🔒 A critical sandbox escape was discovered and patched in isolated-vm, a library that runs JavaScript inside an isolated process. The flaw, a type confusion in the library's C++ binding code, could allow attackers to hijack the host's control flow and enable remote code execution. isolated-vm is widely used, including in AI agent frameworks, and patched versions 7.0.1 and 6.2.0 were released earlier this month.
read more →

ThreatsDay: Signed Drivers, AI Risks, and RCEs

🛡️ This week’s ThreatsDay highlights multiple vectors where trusted components and weak checks are repurposed for attack. Research shows Microsoft-signed drivers can be abused for kernel operations, and a critical Gogs RCE (CVSS 10.0) enables remote code execution via Git hooks. Other items include a large-scale Iran-linked academic espionage case, DLL sideloading campaigns, BYOVD abuse, guardrail-free AI services, and exposed refrigeration controllers.
read more →

Critical Elementor Pro flaw allows remote code execution

🔒 A critical vulnerability in Elementor Pro allows attackers to upload executable files leading to remote code execution on affected WordPress sites. Identified as CVE-2026-32475, the bug stems from inconsistent handling of empty filename entries between the validation and processing loops in the File Upload module. Exploitation requires a published Elementor form with a File Upload field and multiple file upload enabled; administrators should update immediately and inspect uploads directories for rogue PHP files.
read more →

Active exploitation of Zimbra SNMP RCE disclosed

🛡️ A critical Zimbra Collaboration flaw (CVE-2026-73570, CVSS 8.9) allowing command injection and remote code execution is being actively exploited, CERT Polska warns. The issue affects ZCS versions prior to 10.1.20 when the optional zimbra-snmp package and SNMP notifications are enabled; it was patched in 10.1.20. Administrators are urged to inspect /var/log/zimbra.log for suspicious restarts and check recent files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/.
read more →

Citrix issues urgent NetScaler security update advisory

🔒 Citrix warned customers to immediately patch two NetScaler vulnerabilities impacting NetScaler Gateway and NetScaler ADC appliances. The most severe, CVE-2026-19490, can allow remote attackers to bypass authentication when SAML action is configured on certain AAA, Auth, or VPN virtual servers. The other, CVE-2026-19489, is a high-severity memory overflow that can enable remote DoS when SIP ALG is enabled on large-scale NAT group configurations. Citrix published recommended firmware builds and urged immediate upgrades for affected deployments.
read more →

Critical Zimbra RCE Flaw Actively Exploited Now

🛡️ CERT Polska warns that attackers are actively exploiting a critical Zimbra Collaboration Suite vulnerability (CVE-2026-73570). The flaw, patched in Zimbra 10.1.20 on July 20, enables unauthenticated remote code execution via command injection in the SNMP notification processing when SNMP notifications are enabled. Shadowserver reports over 12,100 Zimbra servers exposed online, and administrators are urged to check logs and specific directories for signs of compromise. Zimbra has been a frequent target of APT groups in past campaigns.
read more →

Critical Elementor Pro file upload flaw allows RCE

🛡️ Cybersecurity researchers disclosed a critical vulnerability in the Elementor Pro WordPress plugin that permits unrestricted upload of dangerous file types, tracked as CVE-2026-32475 with a CVSS score of 9.0. The issue stems from the Forms module's File Upload field where extension checks and file-move operations run in separate loops, enabling unauthenticated attackers to bypass the extension blocklist by submitting duplicate file parts and write PHP files into wp-content/uploads/elementor/forms. The flaw affects versions up to 4.2.1 and was patched in 4.2.2 on August 19 after disclosure.
read more →

Critical Windows IKE Extension Flaw Actively Exploited

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are exploiting a critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component, tracked as CVE-2026-33824. The vulnerability affects supported Windows 10, Windows 11, and Windows Server versions and can be triggered by unauthenticated attackers sending crafted packets to UDP ports 500 or 4500. Microsoft issued a Patch Tuesday advisory and recommended firewall mitigations for organizations that cannot immediately apply updates.
read more →

Critical AIT‑GUI Flaw Allows Remote Command Execution

🔒 A critical vulnerability in NASA's open-source AIT-GUI ground control software could let unauthenticated actors issue spacecraft and instrument commands, execute server-side scripts, and run command sequences. Disclosed by Cycode researcher Yuval Elbar on August 18 and tracked as GHSA-p9r8-2q67-fp86 (CVSS 9.4), the flaw affects versions through 2.5.1 and was fixed in 2.5.2. The issue stems from an API that listens on all interfaces, lacks authentication/CSRF protection, and allows unsafe filesystem path construction on execution endpoints.
read more →

CISA Adds Actively Exploited Critical Ray Flaw

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Ray vulnerability (CVE-2025-62593) to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The flaw enables remote code execution via DNS rebinding attacks through browsers like Firefox and Safari and primarily affects developers running Ray in development or testing environments. Ray fixed the issue in version 2.52.0, and agencies are urged to remediate by August 20, 2026.
read more →

Critical GitLab GraphQL Flaw Allows Remote Project Changes

🔒 GitLab released out-of-cycle security updates on August 17, 2026, to fix a critical GraphQL vulnerability (CVE-2026-19478) that could let unauthenticated attackers remotely modify or delete public projects and user data. The patches apply to self-managed instances in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4; hosted GitLab.com and Dedicated are already patched. A second, High-severity issue (CVE-2026-19650) addresses a CSRF-related GraphQL multiplex handling flaw requiring user interaction.
read more →

Critical Forminator flaw lets attackers execute code

🛡️ A critical vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin — used on 600,000+ sites — allows unauthenticated attackers to upload arbitrary files, including executable PHP, and achieve remote code execution. The flaw, present in versions up to 1.56.1, stems from improper file type validation in the handle_file_upload() function and misuse of MIME key matching combined with a public submission handler. Patch 1.56.2, released on July 31, 2026, fixes the issue; site owners should update immediately.
read more →

UNISOC modem isolation flaw risks kernel RCE

🔒 SSD Secure Disclosure researchers revealed a UNISOC modem firmware vulnerability that lets modem-level code execution reach Android kernel space by exploiting improper isolation between modem and kernel memory. The team demonstrated a full exploit chain, including a VoLTE-triggered final stage, and tested it on devices such as the Realme C33. No vendor firmware fix from UNISOC has been reported, leaving OEM updates as the primary mitigation.
read more →

Unisoc modem exploit chain risks Android kernel

🔒 SSD Secure Disclosure detailed a two-stage exploit chain that yields full Android kernel access via Unisoc modem firmware when a victim answers a malicious VoLTE video call. The advisory, published August 17, 2026, follows an earlier March 2026 remote code execution disclosure and requires control of a private 4G network plus a modem foothold. Affected chipsets include Unisoc T606, T612, and T7250 in multiple device brands, and no vendor patch is yet available.
read more →