< ciso
brief />
Tag Banner

All news with #remote code execution tag

882 articles · page 8 of 45

Critical patches issued for Veeam, HashiCorp, and Django

🔒 Vendors HashiCorp, Veeam, and the Django Software Foundation have released fixes for 11 vulnerabilities affecting Terraform MCP Server, Veeam Service Provider Console, and Django. The most severe include an unauthenticated credential-exposure bug in Veeam (9.5), a cross-tenant token-reuse issue in Terraform MCP (10.0), and a GeoDjango spatial lookup flaw that can write files or trigger code execution. Operators are advised to upgrade to Terraform MCP Server 1.1.0+, Veeam 9.3.0.35057, and Django 6.0.8 / 5.2.17; exposure depends on configuration and none of the flaws show public exploitation as of August 5, 2026.
read more →

Critical Paperclip flaws reveal AI agent trust limits

🛡️ Security researchers disclosed multiple vulnerabilities in the open-source AI agent platform Paperclip, including an authorization bypass, exposed APIs, and a DNS rebinding weakness that could lead to remote code execution and developer-machine compromise. Oasis Security detailed how default registration and import behaviors allowed attackers to escalate privileges and execute arbitrary commands by uploading malicious agent configurations. Patches were released in versions 2026.416.0 and 0.3.1 to harden authorization, validate hostnames, and restrict risky imports.
read more →

CISA Adds Langflow, Tomcat and N‑able Flaws to KEV

🛡️ CISA on August 5, 2026, added three actively exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a critical Langflow RCE (CVE-2026-9198) and an Apache Tomcat encryption bypass (CVE-2026-34486). The advisory also includes an N-able N-central authentication bypass (CVE-2026-18556) and a related incomplete fix tracked as CVE-2026-18577. Agencies must apply available patches and mitigations promptly to prevent ongoing exploitation.
read more →

Critical Ruby on Rails image-processing vulnerability

🛡️ A critical CVE-2026-66066 in Ruby on Rails’ Active Storage can let unauthenticated attackers read sensitive files or escalate to RCE by abusing image processing via libvips. Fixed in Active Storage versions 7.2.3.2, 8.0.5.1 and 8.1.3.1, the flaw affects apps that accept untrusted uploads and use libvips; admins should update Rails, ensure libvips ≥ 8.13, rotate secret_key_base, and audit uploads and logs.
read more →

TP-Link patches Omada ZTP flaws enabling network breaches

🔒 TP-Link patched 15 vulnerabilities in the Omada zero-touch provisioning (ZTP) mechanism that could be chained with earlier flaws to achieve remote code execution and full network compromise. Forescout’s Vedere Labs disclosed the issues at Black Hat USA, noting impacts across Omada controllers, gateways, switches, access points, cloud services, mobile apps, and various TP-Link devices. The flaws include hard-coded keys, information disclosure, device hijacking, client-side code execution, and interception of encrypted communications. Administrators are urged to apply firmware updates, use strong unique credentials, enable MFA, rotate secrets if compromise is suspected, and monitor for suspicious activity.
read more →

High‑Severity FaceHugger Flaws in Hugging Face Diffusers

🛡️ Three high‑severity vulnerabilities in Hugging Face's Diffusers library, collectively named FaceHugger, can let crafted model repositories execute arbitrary code on machines that load them. Zafran Labs attributes the issues to TOCTOU race conditions that bypass the trust_remote_code safeguard during model loading. The flaws were fixed in Diffusers 0.38.0; users are advised to patch or follow recommended mitigation steps when loading custom pipelines.
read more →

Rails fixes critical Active Storage flaw with RCE risk

🛡️ The Rails project patched a critical Active Storage vulnerability (CVE-2026-66066) that can let unauthenticated attackers read arbitrary files and potentially achieve remote code execution when libvips is used. The flaw affects multiple Rails branches before specified patch releases and requires accepting uploads from untrusted users. Administrators should upgrade libvips to 8.13+, apply Rails updates, and rotate exposed secrets. ImageMagick users are not affected by this vector.
read more →

Broadcom issues patches for multiple VMware flaws

🔒 Broadcom has released patches addressing five vulnerabilities across multiple VMware products, with three rated as critical. Affected products include vCenter, ESX, Workstation, Fusion, and various cloud and telco platforms. Issues range from authentication bypass and out-of-bounds write enabling remote code execution to syslog-related arbitrary code execution. Administrators should apply fixes from Broadcom's advisory promptly.
read more →

Critical TeamCity RCE Patch Urged for On‑Prem Servers

🔒 JetBrains warned of a critical pre-authentication vulnerability in TeamCity On‑Premises that could allow unauthenticated HTTP(S) requests to bypass authentication and execute arbitrary OS commands. Tracked as CVE-2026-63077 and rated 9.8, the flaw affects all on‑prem deployments and has been fixed in versions 2025.11.7 and 2026.1.3. Customers unable to upgrade can apply a security patch plugin; TeamCity Cloud customers need take no action.
read more →

Critical TeamCity RCE Vulnerability Alert from JetBrains

🚨 JetBrains has disclosed a critical authentication bypass in TeamCity On-Premises tracked as CVE-2026-63077 that allows remote code execution via the agent polling protocol when an attacker has HTTPS access to the server. All on‑premises TeamCity versions are affected, while TeamCity Cloud customers are already protected. JetBrains released fixes in TeamCity 2025.11.7 and 2026.1.3 and provides a security patch plugin for 2017.1+ for those who cannot upgrade. Administrators are urged to apply patches immediately and follow recommended hardening practices such as limiting internet exposure and requiring VPN or other protective layers.
read more →

Critical Ruflo MCP flaw allows unauthenticated RCE

🛡️ Researchers disclosed a critical vulnerability (CVE-2026-59726) in Ruflo, an open-source agent orchestration harness for Anthropic Claude Code and OpenAI Codex, that permitted unauthenticated remote code execution. The flaw, present in versions before 3.16.3, exposed an unauthenticated Model Context Protocol (MCP) bridge on port 3001 by default due to docker-compose binding to 0.0.0.0. Exploitation allowed attackers to run shell commands, steal LLM API keys, read conversations, poison AI memory, and persist backdoors. The maintainer released fixes after disclosure, changing the MCP binding to loopback, gating execution controls, and enabling MongoDB authentication.
read more →

Patched Firefox JIT Bug Enabled Remote Code Execution

🛡️ Nebula Security disclosed a high-severity Firefox JIT vulnerability, tracked as CVE-2026-10702, that could be triggered simply by visiting a malicious webpage and was used to compromise Tor Browser builds embedding affected Firefox versions. Mozilla fixed the flaw in Firefox 151.0.3 and rated it High; the bug allows arbitrary code execution in the browser renderer process and was exploited by Nebula as the initial stage of their IonStack browser-to-kernel chain on an ARM64 Android 17 build. Users are urged to update to the latest Firefox release.
read more →

Critical Gitea RCE in diffpatch fixed in 1.27.1

🔒 Gitea patched a critical remote code execution (RCE) vulnerability tracked as CVE-2026-60004 affecting versions 1.17 through 1.27.0. A user with repository write access could craft a malicious patch that becomes an active Git hook and executes shell commands as the Gitea service account. The flaw requires authentication and write permission, but default open registration allows outsiders to create accounts and exploit unpatched instances. Upgrading to 1.27.1 addresses the issue; Gitea Cloud upgrades were scheduled automatically.
read more →

Arista fixes critical VeloCloud Orchestrator flaw

🔒 Arista has released patches for a critical vulnerability in VeloCloud Orchestrator (VCO) that is actively being exploited in the wild. The vendor warned the flaw may allow remote attackers to access privileged internal functionality and impact VCO hosts, affecting confidentiality, integrity, and availability. Customers are urged to upgrade to fixed releases (VCO 5.2.3.14+, 6.1.3.4+, 6.4.2.4+) and to consider incident response actions such as credential rotation and device validation. Advisors stressed the severity—an unauthenticated command‑injection in an orchestration platform—and warned that on‑premises users often receive fixes more slowly than cloud deployments.
read more →

vBulletin fixes pre-auth RCE; public exploit published

🛡️ A critical pre-authenticated remote code execution vulnerability (CVE-2026-61511) in vBulletin 5.x and 6.x up to 5.7.5 and 6.2.1 allowed attackers to execute arbitrary PHP via template rendering. Researcher Egidio Romano reported the flaw via SSD Secure Disclosure and published a technical analysis and PoC showing the issue stems from improper input sanitization in runMaths(), which forwards data to PHP's eval(). vBulletin released patched 6.2.2 and backported fixes as Patch Level 1; users on older 5.x builds are advised to upgrade.
read more →

OpenWrt critical DHCPv6 overflow and LuCI audit fixes

🛡️ OpenWrt released 24.10.8 (and 25.12.5 for 25.12 users) to fix a critical DHCPv6 stack overflow (CVE-2026-53921) and several remotely triggerable network-service flaws enabled by default. The DHCPv6 bug lets an unauthenticated attacker reachable to UDP/547 overwrite a stack buffer in odhcpd, potentially enabling code execution on devices lacking typical mitigations. The advisory includes public PoC code; other fixes include uhttpd request-smuggling, DHCPv6 hostname-injection XSS, and LuCI component hardening still under review.
read more →

Critical TeamCity RCE Patch Urged for On‑Premises

🛡️ JetBrains warns on-premises TeamCity users to update immediately after a critical RCE vulnerability, CVE-2026-63077 (CVSS 9.8), was disclosed on July 10, 2026. The flaw allows unauthenticated attackers via HTTP(S) to bypass authentication and execute OS commands through the agent polling protocol. Fixes are available in TeamCity 2025.11.7 and 2026.1.3, with a security patch plugin offered for older 2017.1+ releases; no evidence of active exploitation has been reported.
read more →

Arista VeloCloud Orchestrator Exploited in Wild

🔒 Arista has confirmed a maximum-severity OS command injection flaw, CVE-2026-16812 (CVSS 10.0), affecting on-premises VeloCloud Orchestrator (VCO) that is under active exploitation. The issue can enable remote attackers to execute arbitrary code and access privileged internal functionality, potentially compromising confidentiality, integrity, and availability. Affected on-prem VCO releases include versions prior to 5.2.3.14, 6.1.3.4, 6.4.2.4, and 7.0.0.1; hosted and dedicated deployments were already fixed. Arista shared three malicious IPs as IoCs and urged operators to preserve logs, restrict access, and update promptly.
read more →

FastJson zero-day RCE targeting US firms

📣 Researchers report active exploitation of a critical remote code execution flaw in the FastJson Java library (versions 1.2.68–1.2.83). Observed attacks primarily target US organizations across finance, healthcare, retail and other sectors, and exploit Spring Boot fat-JAR deployments. Alibaba confirmed the issue but no patch is available; users are urged to enable SafeMode or migrate to non-affected builds.
read more →

Public exploit targets vBulletin template engine

🔒 SSD Secure Disclosure published a proof-of-concept on July 27 showing an unauthenticated request can reach PHP's eval() in vBulletin templates and execute code on unpatched forums. vBulletin released fixes (6.2.2 and patches for branches) on July 1, and Cloud instances are reported patched, but self-hosted sites running affected versions remain at risk. The disclosed exploit contained a trivial one-character typo that prevents it running unchanged; the underlying vulnerability, identified as CVE-2026-61511 by SSD, enables pre-auth remote code execution via ajax/render/pagenav template rendering.
read more →