#remotecodeexecution — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #remotecodeexecution, aggregated by home.social.
-
CVE-2026-49481 | UpSnap (<5.4.0) has a CRITICAL OS command injection flaw (CVSS 9.6). Authenticated low-priv users can execute arbitrary commands on the server. Patch: upgrade to 5.4.0. Details: https://radar.offseq.com/threat/cve-2026-49481-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-772a6e1ae64fad76 #OffSeq #infosec #CVE202649481 #remotecodeexecution
-
A high-severity Django vulnerability, CVE-2026-15307, can enable remote code execution through spatial lookups. Update to Django 6.0.8 or 5.2.17 now.
#Django #DjangoSecurity #CVE202615307 #RCE #RemoteCodeExecution #Vulnerability #Python #WebSecurity #InfoSec #CyberSecurity
-
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
Pulse ID: 6a698ece10f40a7a5f6c66d4
Pulse Link: https://otx.alienvault.com/pulse/6a698ece10f40a7a5f6c66d4
Pulse Author: Tr1sa111
Created: 2026-07-29 05:25:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #RemoteCodeExecution #Word #Wordpress #bot #Tr1sa111
-
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
Pulse ID: 6a698ece10f40a7a5f6c66d4
Pulse Link: https://otx.alienvault.com/pulse/6a698ece10f40a7a5f6c66d4
Pulse Author: Tr1sa111
Created: 2026-07-29 05:25:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #RemoteCodeExecution #Word #Wordpress #bot #Tr1sa111
-
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.
Pulse ID: 6a6823754b2a6d2295eb3330
Pulse Link: https://otx.alienvault.com/pulse/6a6823754b2a6d2295eb3330
Pulse Author: AlienVault
Created: 2026-07-28 03:35:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #SQL #Word #Wordpress #bot #AlienVault
-
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.
Pulse ID: 6a6823754b2a6d2295eb3330
Pulse Link: https://otx.alienvault.com/pulse/6a6823754b2a6d2295eb3330
Pulse Author: AlienVault
Created: 2026-07-28 03:35:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #SQL #Word #Wordpress #bot #AlienVault
-
How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers
Three critical, now-patched vulnerabilities in Microsoft's infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Researchers traced the bug to a decades-old class of image-parser command injection. -
Exploitation in the Wild of wp2shell
A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.
Pulse ID: 6a61c32bf83a8841dbf45852
Pulse Link: https://otx.alienvault.com/pulse/6a61c32bf83a8841dbf45852
Pulse Author: AlienVault
Created: 2026-07-23 07:30:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #PHP #RAT #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #AlienVault
-
Exploitation in the Wild of wp2shell
A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.
Pulse ID: 6a61c32bf83a8841dbf45852
Pulse Link: https://otx.alienvault.com/pulse/6a61c32bf83a8841dbf45852
Pulse Author: AlienVault
Created: 2026-07-23 07:30:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #PHP #RAT #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #AlienVault
-
CVE-2026-16723: CRITICAL RCE in Alibaba Fastjson 1.2.68. Exploitable under default config — no patch yet. Avoid 1.2.68 & monitor vendor updates for mitigation. CVSS 9.0. https://radar.offseq.com/threat/cve-2026-16723-cwe-20-improper-input-validation-in-alibaba-fastjson-939ed165aac7ce81 #OffSeq #infosec #CVE202616723 #remotecodeexecution
-
CVE-2026-6875 (CVSS 9.5) is a ServiceNow sandbox escape in the AI Platform that allows unauthenticated remote code execution. Patch now.
#ServiceNow #CVE20266875 #RemoteCodeExecution #SandboxEscape #CyberSecurity
-
tinyparrot npm v0.4.1 flagged as CRITICAL: Malicious postinstall script executes attacker-supplied shell commands via obfuscated HTTPS POST. Remove & avoid use! No patch available. https://radar.offseq.com/threat/mal-2026-10190-malicious-code-in-tinyparrot-npm-8e0728bab742b27e #OffSeq #npm #remotecodeexecution #malware
-
notify-utilities v1.3.5 (npm) is a CRITICAL threat: malicious code spawns a detached process to fetch & execute attacker JS, enabling stealthy RCE. Remove immediately. No CVE or fix yet. Details: https://radar.offseq.com/threat/mal-2026-10158-malicious-code-in-notify-utilities--b49cbdabbd7b0388 #OffSeq #npm #remotecodeexecution #malware
-
CRITICAL: libssh2 contains 2 vulnerabilities allowing remote code execution without authentication or user action. No CVE, patch, or vendor advisory yet. Widely embedded — monitor for updates, limit exposure. https://radar.offseq.com/threat/massive-security-flaw-discovered-in-popular-ssh-li-1a973c1519977003 #OffSeq #libssh2 #vuln #remotecodeexecution
-
Veeam Patches Backup Flaw That Enables Remote Code Execution
Veeam has urgently patched a critical backup flaw, CVE-2026-44963, that allowed remote code execution with just domain user credentials, scoring a severe 9.4 out of 10 in severity. The update to version 12.3.2.4854 fixes this vulnerability, preventing attackers from running malicious code on the Backup Server.
#RemoteCodeExecution #Veeam #Cve202644963 #BackupServer #SupplyChain
-
Veeam Vulnerability Enables RCE Attacks on Backup Servers
A newly discovered vulnerability in Veeam Backup & Replication could allow an authenticated domain user to launch a remote code execution attack on your backup server - a critical target for hackers. Patch now to protect your data: update to version 12.3.2.4854 or later to fix the flaw.
#Veeam #Ransomware #RemoteCodeExecution #Cve202644963 #BackupServers
-
Gogs Fixes Zero-Day Flaw Enabling Remote Code Execution
A critical vulnerability in Gogs allows attackers to execute remote code, putting Internet-facing instances at risk of full compromise - and it's easily exploitable by anyone who can create an account. This flaw enables attackers to wreak havoc without needing admin privileges, making swift action a must.
#ZeroDay #RemoteCodeExecution #Gogs #ArgumentInjection #EmergingThreats
-
Hackers Exploit Everest Forms Pro Flaw to Compromise WordPress Sites
A critical vulnerability in Everest Forms Pro, affecting over 4,000 active WordPress installations, has been exploited by hackers to gain remote code execution, allowing them to take control of sites without authorization. A patch has been released, but sites remain at risk if not updated to version 1.9.13 or later.
#RemoteCodeExecution #Cve20263300 #EverestFormsPro #Wordpress #PluginVulnerability
-
Everest Forms Pro Flaw Exploited for Remote Code Execution
A critical flaw in the Everest Forms Pro WordPress plugin, CVE-2026-3300, has been exploited over 29,300 times, allowing attackers to execute remote code on vulnerable sites. This vulnerability was caused by a simple calculation feature that was not properly sanitized, leaving sites open to unauthenticated attacks.
#RemoteCodeExecution #Cve20263300 #Wordpress #EverestFormsPro #PluginVulnerability
-
CISA Warns of Exploited Magento Extension Flaw
A critical flaw in the Mirasvit Full Page Cache Warmer Magento extension, tracked as CVE-2026-45247, has been exploited by hackers, allowing them to execute remote code without authentication. This vulnerability, rated 9.8 on the CVSS scale, enables attackers to wreak havoc by supplying a malicious PHP object in the CacheWarmer…
#MagentoExtensionFlaw #Cve202645247 #DeserializationVulnerability #RemoteCodeExecution #Cisa
-
Faster Vulnerability Alerts Disrupt Cyberattack Window
The time it takes for attackers to exploit a newly disclosed vulnerability has dramatically shrunk to just 1.6 days - leaving organizations scrambling to respond. In today's lightning-fast threat landscape, staying ahead of vulnerability alerts is crucial to preventing devastating cyberattacks.
#VulnerabilityManagement #ExploitWindow #RemoteCodeExecution #Rce #EmergingThreats
-
Windows Netlogon flaw exploited in attacks after patch release
A critical Windows Netlogon flaw, patched just last month, is now being actively exploited in attacks, putting vulnerable systems at risk of remote code execution. This severe vulnerability, rated 9.8 out of 10 in severity, allows attackers to gain control of targeted domain controllers with just a specially crafted network…
#Windows #Netlogon #Cve202641089 #RemoteCodeExecution #StackbasedBufferOverflow
-
Gogs Vulnerability Exposes Open-Source Git Service to RCE Attacks
A critical vulnerability in Gogs, an open-source Git service, has been exposed, leaving users open to remote code execution (RCE) attacks - and an exploit module is already available. The flaw was reported as early as March, but shockingly, the project's maintainers have failed to respond to the researcher ever since.
-
LLM Agent Enables Rapid Post-Exploitation in Marimo Networks
On May 10, 2026, a savvy attacker used a large language model agent to rapidly exploit a vulnerable Marimo instance, leveraging CVE-2026-39987 to spark a swift and damaging breach. This critical vulnerability allowed the attacker to execute arbitrary system commands, paving the way for cloud credential…
#MarimoNetworkExploitation #LargeLanguageModelAgent #Cve202639987 #Postexploitation #RemoteCodeExecution
-
Gogs Vulnerability Exposes Remote Code Execution Risk
A newly discovered vulnerability in Gogs puts servers at risk of remote code execution, allowing any authenticated user to inject malicious code through a simple pull request. By crafting a malicious branch name, attackers can exploit the --exec flag in git rebase to run unauthorized shell commands.
-
Gogs Zero-Day Flaw Enables Remote Code Execution on Exposed Servers
A zero-day flaw in Gogs, a self-hosted Git service, leaves exposed servers vulnerable to remote code execution - and it's surprisingly easy for attackers to exploit, as they can create an account and repository on default-configured instances. This critical-severity vulnerability affects the latest release versions and…
#Gogs #ZeroDay #RemoteCodeExecution #ArgumentinjectionFlaw #SelfhostedGitService
-
Microsoft Fixes SharePoint Flaw That Exposes Servers to Remote Code Execution
Microsoft just patched a high-severity flaw in SharePoint that could let hackers execute malicious code remotely - and it's crucial you update your servers ASAP to stay safe. The vulnerability, tracked as CVE-2026-45659, has a CVSS score of 8.8, making it a prime target for attackers.
#RemoteCodeExecution #Sharepoint #Cve202645659 #Microsoft #DeserializationVulnerability
-
KnowledgeDeliver LMS Flaw Exploited to Deploy Malware
A security flaw in the KnowledgeDeliver LMS, known as CVE-2026-5426, was exploited by a threat actor to inject malicious code and infect users visiting the site. This vulnerability was caused by a predictable secret in the system's web.config file, allowing attackers to execute remote code.
#RemoteCodeExecution #LmsSecurity #Cve20265426 #MalwareOperations #EmergingThreats
-
🚨 A compromise affecting the community-maintained Laravel Lang project introduced remote code execution backdoors across multiple packages, including:
- Laravel-Lang/lang
- Laravel-Lang/http-statuses
- Laravel-Lang/actions
- Laravel-Lang/attributesAll tags were rewritten pointing to malicious commits
https://github.com/Laravel-Lang/lang/issues/8295
https://github.com/Laravel-Lang/common/issues/257
https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack
https://socket.dev/blog/laravel-lang-compromise
#PHP #Laravel #SupplyChainAttack #RemoteCodeExecution #RCE #Packagist
-
#Google has accidentally leaked details about an unfixed issue in #Chromium that keeps #JavaScript running in the background even when the browser is closed, allowing #remotecodeexecution on the device.
An attacker could #exploit the problem to create a malicious webpage with a Service Worker, such as a download task, that never terminates. Rebane says that this could allow an attacker to execute JavaScript code on the visitors' devices.
https://www.bleepingcomputer.com/news/security/google-accidentally-exposed-details-of-unfixed-chromium-flaw/ #RCE -
NGINX Flaw CVE-2026-42945 Actively Exploited, Threatens Worker Crashes and RCE
A newly discovered NGINX flaw, CVE-2026-42945, is being actively exploited, posing a significant threat of worker crashes and remote code execution (RCE) through specially crafted HTTP requests. This high-severity vulnerability, with a CVSS score of 9.2, has been lurking in NGINX versions since 2008,…
#Nginx #Cve202642945 #RemoteCodeExecution #HeapBufferOverflow #VulnerabilityExploitation
-
Android-Patchday Kritische Schadcode-Lücke bedroht Android
Mehr: https://maniabel.work/archiv/1556
#Android, #AndroidPatchDay, #Exploit, #RemoteCodeExecution #up2date #BeDiS
-
A single git push command was enough to exploit a flaw in #GitHub's internal protocol and achieve code execution on backend infrastructure.
CVE-2026-3854
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
-
Windows ZeroDay "RedSun"
Nur Stunden nachdem Microsoft den ersten „BlueHammer"-Zeroday gepatcht hatte, veröffentlichte der enttäuschte und offenbar tief frustrierte Forscher „Nightmare-Eclipse" seinen zweiten Angriff: „RedSun".Mehr: https://maniabel.work/archiv/1453
#Exploit #Microsoft #PatchDay #RedSun #RemoteCodeExecution #Windows #ZeroDay #infosec #up2date
-
https://winbuzzer.com/2026/04/15/microsoft-april-2026-patch-tuesday-fixes-167-flaws-xcxwbn/
Microsoft April 2026 Patch Tuesday Fixes 167 Flaws, 2 Zero-Days
#PatchTuesday #Microsoft #Security #Cybersecurity #ZeroDayVulnerabilities #MicrosoftSharePoint #MicrosoftDefender #Windows #Windows11 #MicrosoftWindows #WindowsUpdate #RemoteCodeExecution
-
https://winbuzzer.com/2026/03/26/chrome-update-fixes-8-high-risk-browser-vulnerabilities-xcxwbn/
Chrome Update Fixes 8 High-Risk Browser Vulnerabilities
#GoogleChrome #Google #WebBrowsers #Cybersecurity #ZeroDayVulnerabilities #BigTech #MicrosoftEdge #Opera #RemoteCodeExecution #DataSecurity #Exploits #Chrome146 #Alphabet
-
Microsoft Issues Emergency KB5084597 Hotpatch for RRAS Flaws
#Microsoft #Windows1124H2 #Windows11 #Cybersecurity #SecurityVulnerabilities #SecurityFlaws #RemoteCodeExecution #SoftwareUpdates #WindowsUpdate ##WindowsServer #Windows1125H2 #RRAS #Kb5084597
-
Anthropic says the newly disclosed zero‑click RCE bug in Claude Desktop Extensions isn’t a design flaw to fix, citing the Model Context Protocol’s architecture. The debate raises big questions for AI agents and cybersecurity. What does this mean for developers and users? Dive into the details. #AIagents #ClaudeDesktop #RemoteCodeExecution #Cybersecurity
🔗 https://aidailypost.com/news/anthropic-declines-patch-reported-ai-agent-vulnerability-cites-design
-
https://winbuzzer.com/2026/02/11/claude-desktop-zero-click-vulnerability-10000-users-xcxwbn/
10,000+ Claude Desktop Users Exposed by Zero-Click Flaw
#Claude #Anthropic #RemoteCodeExecution #Security #Cybersecurity #Vulnerability #MCP #GoogleCalendar #Google #LLMs
-
https://winbuzzer.com/2026/02/06/amd-refuses-fix-critical-autoupdate-rce-vulnerability-xcxwbn/
AMD Won't Fix Critical RCE Vulnerability in its AutoUpdate Software
#AMD #RemoteCodeExecution #Cybersecurity #Security #Vulnerability #WindowsSecurity #Gaming #Hardware #Semiconductors
-
Hackers Breach Fortune 500 Companies Exploiting Security Testing Apps
#Cybersecurity #DataBreaches #Malware #Hackers #AWS #GCP #Azure #CloudSecurity #ThreatActors #CyberThreats #RemoteCodeExecution #DataSecurity
-
Oops, apocalypse ...
Critical n8n bug allows unauthenticated server takeover • The Register
https://www.theregister.com/2026/01/08/n8n_rce_bug/ -
🚨 ALERT: FreeBSD's "security" geniuses have discovered that their router advertisements can execute code remotely! 😱💻 But don't worry, they patched it in record time—by repeating the same date and time for every version. 🕒🔧 Bravo, truly groundbreaking work! 👏
https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc #FreeBSD #Security #RemoteCodeExecution #Patch #Genius #Hackers #News #HackerNews #ngated -
Security Flaw in Google Antigravity AI IDE Allows Data Exfiltration via Prompt Injection
#Security #AI #AICoding #Google #Cybersecurity #GoogleGemini #AIAgents #AgenticAI #Antigravity #DataPrivacy #RemoteCodeExecution #PromptInjection #DataExfiltration
-
Kritische Befehls‑Injection‑Lücke im WordPress‑Plugin W3 Total Cache
Eine schwerwiegende Sicherheitslücke (CVE‑2025‑9501, CVSS‑Score 9.0) wurde im beliebten WordPress‑Caching‑Plugin W3 Total Cache entdeckt. Sie ermöglicht Remote‑Code‑Execution – das heißt, Angreifer können beliebige Befehle auf dem Server ausführen, ohne sich vorher authentifizieren zu müssen.
#wordpress #plugin #w3totalcache #infosec #infosecnews #RemoteCodeExecution
-
GoSign Desktop RCE flaws affecting users in Italy
https://www.ush.it/2025/11/14/multiple-vulnerabilities-gosign-desktop-remote-code-execution/
#HackerNews #GoSignDesktop #RCE #Italy #vulnerabilities #cybersecurity #remoteCodeExecution