Home/ Blog/ Topics/ Remote code execution
Topic

Remote code execution

The most dangerous class of bug: flaws that let an attacker run their own code on your systems, often with no login required.

Security news

Unitree G1 robot flaws give root over Bluetooth, and one hacked robot can reach the next

Two Unitree G1 humanoid robot flaws (CVE-2026-76639, CVE-2026-76640) give an attacker root over Bluetooth or the network, and one hacked robot can reach the

Security news

Five WordPress plugin and theme flaws let attackers take the site or the whole server

Wordfence and Patchstack disclosed five unauthenticated WordPress flaws rated 9.8 to 10.0. GiveWP and Avada run code on the host. Patch all five now.

Security news

Three ServiceNow AI Platform flaws (CVSS 10.0) let an unauthenticated attacker run code. Patch now.

ServiceNow patched three CVSS 10.0 AI Platform flaws an unauthenticated attacker can chain for code execution, SQL injection, and privilege escalation.

Security news

Two critical Next.js flaws let attackers run code on self-hosted servers

Next.js patched two critical flaws that let unauthenticated attackers run code on self-hosted servers. Vercel apps are covered. Update to 15.5.24 or 16.3.3 now.

Security news

PaperCut print servers are under active attack through a login-free code-execution flaw

Attackers are exploiting an unauthenticated flaw in PaperCut NG and MF print servers to run code as the host account. Restrict access and patch now.

Security news

Gitea flaw CVE-2026-60004 lets any user run code on your server, now exploited. Patch 1.27.1.

CISA added Gitea's CVE-2026-60004 to its exploited list on Aug 25. A public exploit lets any user run code via the diffpatch API. Patch to 1.27.1 and hunt.

Security news

isolated-vm's sandbox flaw lets untrusted code take over the host running your AI workflows

A critical type-confusion flaw in isolated-vm lets sandboxed JavaScript escape and run code on the host. Patch to 7.0.1 or 6.2.0, and watch the Node process.

Security news

Elementor Pro flaw (CVE-2026-32475) lets an unauthenticated attacker upload PHP and run code. Patch to 4.2.2.

Elementor Pro before 4.2.2 has a critical file upload flaw (CVE-2026-32475, CVSS 9.0) letting an unauthenticated attacker plant a PHP webshell. Patch now.

Security news

Zimbra RCE (CVE-2026-73570) lets an unauthenticated attacker run commands over SMTP. Patch to 10.1.20.

CVE-2026-73570 is an unauthenticated command injection in Zimbra Collaboration Suite, now in CISA KEV and exploited in the wild.

Security news

A single web request can hijack SPIP websites with no login, and the first patch missed it (CVE-2026-77806)

SPIP before 4.4.21 has a critical unauthenticated code-execution flaw (CVE-2026-77806, CVSS 9.8) exploited in the wild. The 4.4.20 patch fell short; update now.

Security news

Forminator WordPress plugin flaw lets attackers run code with no login (CVE-2026-15748)

CVE-2026-15748 is a CVSS 9.8 unauthenticated file-upload RCE in the Forminator WordPress plugin. Affects versions up to 1.56.1. Update to 1.56.2 now.

Deep dive

Command execution was the week's most common bug. Self-hosted software is why.

Command injection and RCE led our threat desk's triage this week at 370, more than any other class.

Security news

A malicious web page can run code on developers' Ray AI servers, and CISA confirms active exploitation

CISA flagged CVE-2025-62593 in Ray as actively exploited. A malicious web page can reach a developer's local Ray dashboard and run code. Patch to Ray 2.52.0.

Security news

GeoServer zero-day: unauthenticated SQL injection can reach remote code execution, and there is no patch yet

A GeoServer zero-day lets unauthenticated attackers run SQL injection that can reach remote code execution. No CVE, no patch, and probing has already started.

Security news

Langflow's auto-login default gives any stranger admin, then RCE

CVE-2026-9198 lets an unauthenticated attacker mint a Langflow superuser token via auto-login, then run code as admin. KEV-listed, patch past 1.10.0 now.

Security news

Unauthenticated attacker can read any file on a Ruby on Rails server via a crafted image (CVE-2026-66066)

CVE-2026-66066 lets an unauthenticated attacker upload a crafted image to a Rails app and read any server file, including its signing key. Patch now.

Security news

Adminer flaw lets a logged-in user run code on the web server (CVE-2026-15686), fixed in 5.4.3

CVE-2026-15686 lets a logged-in Adminer user slip a blocked SQLite command past a filter and run code on the server. Fixed in Adminer 5.4.3; update now.

Security news

Fastjson RCE (CVE-2026-16723) now exploited on Spring Boot apps

CVE-2026-16723, a fastjson 1.x remote code execution flaw, is now exploited against US firms. Only Spring Boot fat-JAR apps are hit, and no 1.x patch is coming.

Security news

A max-severity flaw in Dassault's 3DEXPERIENCE platform lets an attacker run code with no login. Patch now.

CVE-2026-11756 is a CVSS 10 deserialization flaw in Dassault's 3DEXPERIENCE Launcher that allows unauthenticated remote code execution.

Security news

n8n flaw lets any workflow editor run OS commands on your server (GHSA-gv7g-jm28-cr3m)

n8n patched a CVSS 8.7 expression sandbox escape (GHSA-gv7g-jm28-cr3m) that lets any workflow editor run OS commands on the host. Update to 2.32.1 now.

Security news

WPForms Pro flaw lets a stranger upload a file and run code on your WordPress site. Patch now.

A flaw in WPForms Pro (CVE-2026-10818) lets unauthenticated attackers upload executable files to WordPress sites on versions up to 1.10.1.1 and run code.

Security news

Langflow's code-validation endpoint just produced its second unauthenticated RCE

CVE-2026-0770 (CVSS 9.8) is an unauthenticated root RCE in Langflow's validate endpoint, actively exploited and added to CISA's KEV catalog.

Security news

Oracle's July update fixes unauthenticated 10.0 code-execution flaws in WebLogic, HTTP Server, and Coherence

Oracle's July 2026 update ships 1,449 fixes, including unauthenticated CVSS 10.0 remote code execution in WebLogic, Oracle HTTP Server, and Coherence.

Security news

ServiceNow is under active attack through a route the public exploit does not show. Patch, don't block.

ServiceNow's pre-auth sandbox-escape flaw CVE-2026-6875 (CVSS 9.5) is under active exploitation.

Security news

In Apache Camel, a manipulated AI reply can quietly redirect what the server does next

CVE-2026-49042 lets a prompt-injected AI model set hidden Apache Camel headers via tool-call arguments, reaching code execution or SSRF on exposed routes.

Security news

wp2shell went from patch to public exploit in a day. Patching is no longer enough.

Public proof-of-concept exploits for the wp2shell WordPress Core RCE (CVE-2026-63030) are live and the mechanism is disclosed.

Security news

A stranger with no login can take over WordPress sites on 6.9 and 7.0. Patch now.

WordPress Core 6.9 and 7.0 carry wp2shell (CVE-2026-63030), an unauthenticated remote code execution flaw. Update to 6.9.5 or 7.0.2 right away, then hunt.

Security news

SharePoint's new RCE is live, and patching alone won't clean it

CVE-2026-58644, a SharePoint deserialization RCE, is in CISA's KEV catalog and exploited as a zero-day. Patching alone won't evict an attacker who stole keys.

Security news

A WatchGuard firewall can be taken over through its single sign-on agent, no login required

CVE-2026-8247 lets a network-adjacent attacker run code as root on WatchGuard Firebox firewalls with no login.

Security news

Super Forms flaw lets anyone take over a WordPress site, and a working exploit is now public

A critical flaw (CVSS 9.8) in the Super Forms WordPress plugin lets unauthenticated attackers run code on the server.

Security news

Adobe ColdFusion is under active attack, but the max-severity rating overstates who is exposed

Adobe ColdFusion flaw CVE-2026-48282 (CVSS 10.0) is now exploited in the wild and in CISA KEV. Who is actually exposed, how to detect it, and what to patch.

Security news

Formie's second hidden-field flaw in five weeks lets a stranger run code on your Craft CMS site

Formie for Craft CMS has a critical flaw (CVE-2026-52889) that lets an unauthenticated visitor inject Twig template code through a hidden field.

Security news

No password needed: a public exploit now hijacks unpatched Control Web Panel servers

A public exploit for a critical Control Web Panel flaw (CVE-2026-57517) lets unauthenticated attackers seize hosting servers. Patch to 0.9.8.1225 and hunt now.

Security news

Kemp LoadMaster's quote sanitizer became a pre-auth root RCE, exploited hours after the writeup dropped

Kemp LoadMaster's CVE-2026-8037 gives unauthenticated root through its API and is under active exploitation. Affected versions, the fix, and how to detect it.

Security news

Cursor's AI agent trusted the content it read, and that content could switch off its sandbox

Two critical Cursor flaws, DuneSlide (CVE-2026-50548/50549, CVSS 9.8), let a poisoned MCP server or web result overwrite the sandbox binary and run code.

Security news

Argo CD can be taken over from inside your cluster, and there is no patch to wait for

Argo CD's repo-server runs code for unauthenticated callers and can take over your Kubernetes cluster. No patch or CVE exists yet, so isolate and watch it now.

Security news

Microsoft said this SharePoint bug was unlikely to be exploited. CISA just proved it wrong.

Microsoft rated SharePoint's CVE-2026-45659 unlikely to be exploited. CISA added it to the KEV catalog on July 1 after active exploitation. Patch and hunt now.

Security news

Adobe's six max-severity ColdFusion flaws have no exploit yet, and that is the countdown

Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).

Security news

Windchill holds your product blueprints. A web shell on its login page hands them over.

CISA added PTC Windchill RCE CVE-2026-12569 to its KEV catalog after web shells hit exposed PLM servers. Patch to 11.0 M030 before the June 28 deadline.

Security news

Two flaws in Unraid's control panel let a logged-in user seize the whole server

Two command injection flaws in Unraid's web panel, CVE-2026-9772 and CVE-2026-9773, let any logged-in user run code as www-data.

Security news

Crawl4AI shipped its server unlocked by default. It took three patches to close the door.

Crawl4AI's Docker API shipped unauthenticated by default, exposing 51,000+ deployments to remote code execution and cloud-metadata SSRF. Upgrade to 0.9.0 now.

Security news

Java's most-used JSON library has a guardrail attackers can slip dangerous objects past

CVE-2026-54513 lets attackers bypass jackson-databind's polymorphic type validator by wrapping a banned class in an array. Patch to 2.18.8, 2.21.4 or 3.1.4.

Security news

Attackers can take over your self-hosted UniFi controller with no password. CISA says it is happening now.

Three chained UniFi OS Server flaws give unauthenticated root. CISA added all three to its exploited list on June 23. Patch to 5.0.8 and check who can reach it.

Security news

PixelSmash: a video your server opens by itself can run an attacker's code

PixelSmash (CVE-2026-8461) lets a crafted video run code on FFmpeg-based media servers like Jellyfin and Nextcloud. Update to FFmpeg 8.1.2, then hunt.

Security news

Your AI agent trusts your own computer. One web page turns that into a takeover.

Microsoft's AutoJack shows how one web page an AI browsing agent visits can run code on the host. The bug is a near miss. The architecture lesson is not.

Security news

A WordPress form plugin lets a stranger delete your site, the moment an admin looks

CVE-2026-9843 lets an unauthenticated visitor plant a form entry that deletes WordPress files when an admin opens it.

Security news

A single rigged document can turn Langflow's file reader into full server takeover

A crafted document in a Langflow RAG pipeline (CVE-2026-55447, CVSS 9.6) reads any file, forges a login token, then runs code. Upgrade to 1.9.2 or later.

Security news

Your Splunk box runs a database sidecar you never configured. Attackers use it for root.

CVE-2026-20253 is an unauthenticated RCE in Splunk Enterprise 10.x via a bundled PostgreSQL sidecar. On CISA KEV, exploited now. Patch to 10.0.7 or 10.2.4.

Security news

FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In

Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.

Security news

Three requests, no password, a webshell: the JCE flaw hitting Joomla hosts now

Unauthenticated RCE (CVSS 10, CVE-2026-48907) in JCE, the most-installed Joomla editor. KEV-listed and exploited. Patch to 2.9.99.6 and hunt for webshells.

Security news

Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach

Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.