home.social

#remotecodeexecution — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remotecodeexecution, aggregated by home.social.

fetched live
  1. CVE-2026-49481 | UpSnap (<5.4.0) has a CRITICAL OS command injection flaw (CVSS 9.6). Authenticated low-priv users can execute arbitrary commands on the server. Patch: upgrade to 5.4.0. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202649481 #remotecodeexecution

  2. Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core

    Pulse ID: 6a698ece10f40a7a5f6c66d4
    Pulse Link: otx.alienvault.com/pulse/6a698
    Pulse Author: Tr1sa111
    Created: 2026-07-29 05:25:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #RemoteCodeExecution #Word #Wordpress #bot #Tr1sa111

  3. Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core

    Pulse ID: 6a698ece10f40a7a5f6c66d4
    Pulse Link: otx.alienvault.com/pulse/6a698
    Pulse Author: Tr1sa111
    Created: 2026-07-29 05:25:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #RemoteCodeExecution #Word #Wordpress #bot #Tr1sa111

  4. Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core

    Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.

    Pulse ID: 6a6823754b2a6d2295eb3330
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #SQL #Word #Wordpress #bot #AlienVault

  5. Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core

    Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.

    Pulse ID: 6a6823754b2a6d2295eb3330
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #SQL #Word #Wordpress #bot #AlienVault

  6. How a Crafted SVG File Could Have Handed Attackers SYSTEM Access on Microsoft’s Bing Servers

    Three critical, now-patched vulnerabilities in Microsoft's infrastructure show how an everyday image upload feature in Bing Images became a path to remote code execution as NT AUTHORITY\SYSTEM. Researchers traced the bug to a decades-old class of image-parser command injection.

    securebulletin.com/how-a-craft

  7. Exploitation in the Wild of wp2shell

    A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.

    Pulse ID: 6a61c32bf83a8841dbf45852
    Pulse Link: otx.alienvault.com/pulse/6a61c
    Pulse Author: AlienVault
    Created: 2026-07-23 07:30:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #PHP #RAT #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #AlienVault

  8. Exploitation in the Wild of wp2shell

    A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.

    Pulse ID: 6a61c32bf83a8841dbf45852
    Pulse Link: otx.alienvault.com/pulse/6a61c
    Pulse Author: AlienVault
    Created: 2026-07-23 07:30:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #PHP #RAT #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #AlienVault

  9. CVE-2026-16723: CRITICAL RCE in Alibaba Fastjson 1.2.68. Exploitable under default config — no patch yet. Avoid 1.2.68 & monitor vendor updates for mitigation. CVSS 9.0. radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE202616723 #remotecodeexecution

  10. tinyparrot npm v0.4.1 flagged as CRITICAL: Malicious postinstall script executes attacker-supplied shell commands via obfuscated HTTPS POST. Remove & avoid use! No patch available. radar.offseq.com/threat/mal-20 #OffSeq #npm #remotecodeexecution #malware

  11. notify-utilities v1.3.5 (npm) is a CRITICAL threat: malicious code spawns a detached process to fetch & execute attacker JS, enabling stealthy RCE. Remove immediately. No CVE or fix yet. Details: radar.offseq.com/threat/mal-20 #OffSeq #npm #remotecodeexecution #malware

  12. CRITICAL: libssh2 contains 2 vulnerabilities allowing remote code execution without authentication or user action. No CVE, patch, or vendor advisory yet. Widely embedded — monitor for updates, limit exposure. radar.offseq.com/threat/massiv #OffSeq #libssh2 #vuln #remotecodeexecution

  13. Veeam Patches Backup Flaw That Enables Remote Code Execution

    Veeam has urgently patched a critical backup flaw, CVE-2026-44963, that allowed remote code execution with just domain user credentials, scoring a severe 9.4 out of 10 in severity. The update to version 12.3.2.4854 fixes this vulnerability, preventing attackers from running malicious code on the Backup Server.

    osintsights.com/veeam-patches-

    #RemoteCodeExecution #Veeam #Cve202644963 #BackupServer #SupplyChain

  14. Veeam Vulnerability Enables RCE Attacks on Backup Servers

    A newly discovered vulnerability in Veeam Backup &amp; Replication could allow an authenticated domain user to launch a remote code execution attack on your backup server - a critical target for hackers. Patch now to protect your data: update to version 12.3.2.4854 or later to fix the flaw.

    osintsights.com/veeam-vulnerab

    #Veeam #Ransomware #RemoteCodeExecution #Cve202644963 #BackupServers

  15. Gogs Fixes Zero-Day Flaw Enabling Remote Code Execution

    A critical vulnerability in Gogs allows attackers to execute remote code, putting Internet-facing instances at risk of full compromise - and it's easily exploitable by anyone who can create an account. This flaw enables attackers to wreak havoc without needing admin privileges, making swift action a must.

    osintsights.com/gogs-fixes-zer

    #ZeroDay #RemoteCodeExecution #Gogs #ArgumentInjection #EmergingThreats

  16. Hackers Exploit Everest Forms Pro Flaw to Compromise WordPress Sites

    A critical vulnerability in Everest Forms Pro, affecting over 4,000 active WordPress installations, has been exploited by hackers to gain remote code execution, allowing them to take control of sites without authorization. A patch has been released, but sites remain at risk if not updated to version 1.9.13 or later.

    osintsights.com/hackers-exploi

    #RemoteCodeExecution #Cve20263300 #EverestFormsPro #Wordpress #PluginVulnerability

  17. Everest Forms Pro Flaw Exploited for Remote Code Execution

    A critical flaw in the Everest Forms Pro WordPress plugin, CVE-2026-3300, has been exploited over 29,300 times, allowing attackers to execute remote code on vulnerable sites. This vulnerability was caused by a simple calculation feature that was not properly sanitized, leaving sites open to unauthenticated attacks.

    osintsights.com/everest-forms-

    #RemoteCodeExecution #Cve20263300 #Wordpress #EverestFormsPro #PluginVulnerability

  18. CISA Warns of Exploited Magento Extension Flaw

    A critical flaw in the Mirasvit Full Page Cache Warmer Magento extension, tracked as CVE-2026-45247, has been exploited by hackers, allowing them to execute remote code without authentication. This vulnerability, rated 9.8 on the CVSS scale, enables attackers to wreak havoc by supplying a malicious PHP object in the CacheWarmer…

    osintsights.com/cisa-warns-of-

    #MagentoExtensionFlaw #Cve202645247 #DeserializationVulnerability #RemoteCodeExecution #Cisa

  19. Faster Vulnerability Alerts Disrupt Cyberattack Window

    The time it takes for attackers to exploit a newly disclosed vulnerability has dramatically shrunk to just 1.6 days - leaving organizations scrambling to respond. In today's lightning-fast threat landscape, staying ahead of vulnerability alerts is crucial to preventing devastating cyberattacks.

    osintsights.com/faster-vulnera

    #VulnerabilityManagement #ExploitWindow #RemoteCodeExecution #Rce #EmergingThreats

  20. Windows Netlogon flaw exploited in attacks after patch release

    A critical Windows Netlogon flaw, patched just last month, is now being actively exploited in attacks, putting vulnerable systems at risk of remote code execution. This severe vulnerability, rated 9.8 out of 10 in severity, allows attackers to gain control of targeted domain controllers with just a specially crafted network…

    osintsights.com/windows-netlog

    #Windows #Netlogon #Cve202641089 #RemoteCodeExecution #StackbasedBufferOverflow

  21. Gogs Vulnerability Exposes Open-Source Git Service to RCE Attacks

    A critical vulnerability in Gogs, an open-source Git service, has been exposed, leaving users open to remote code execution (RCE) attacks - and an exploit module is already available. The flaw was reported as early as March, but shockingly, the project's maintainers have failed to respond to the researcher ever since.

    osintsights.com/gogs-vulnerabi

    #Gogs #RemoteCodeExecution #Rce #Opensource #Git

  22. LLM Agent Enables Rapid Post-Exploitation in Marimo Networks

    On May 10, 2026, a savvy attacker used a large language model agent to rapidly exploit a vulnerable Marimo instance, leveraging CVE-2026-39987 to spark a swift and damaging breach. This critical vulnerability allowed the attacker to execute arbitrary system commands, paving the way for cloud credential…

    osintsights.com/llm-agent-enab

    #MarimoNetworkExploitation #LargeLanguageModelAgent #Cve202639987 #Postexploitation #RemoteCodeExecution

  23. Gogs Vulnerability Exposes Remote Code Execution Risk

    A newly discovered vulnerability in Gogs puts servers at risk of remote code execution, allowing any authenticated user to inject malicious code through a simple pull request. By crafting a malicious branch name, attackers can exploit the --exec flag in git rebase to run unauthorized shell commands.

    osintsights.com/gogs-vulnerabi

    #RemoteCodeExecution #Gogs #Vulnerability #Git #SupplyChain

  24. Gogs Zero-Day Flaw Enables Remote Code Execution on Exposed Servers

    A zero-day flaw in Gogs, a self-hosted Git service, leaves exposed servers vulnerable to remote code execution - and it's surprisingly easy for attackers to exploit, as they can create an account and repository on default-configured instances. This critical-severity vulnerability affects the latest release versions and…

    osintsights.com/gogs-zero-day-

    #Gogs #ZeroDay #RemoteCodeExecution #ArgumentinjectionFlaw #SelfhostedGitService

  25. Microsoft Fixes SharePoint Flaw That Exposes Servers to Remote Code Execution

    Microsoft just patched a high-severity flaw in SharePoint that could let hackers execute malicious code remotely - and it's crucial you update your servers ASAP to stay safe. The vulnerability, tracked as CVE-2026-45659, has a CVSS score of 8.8, making it a prime target for attackers.

    osintsights.com/microsoft-fixe

    #RemoteCodeExecution #Sharepoint #Cve202645659 #Microsoft #DeserializationVulnerability

  26. KnowledgeDeliver LMS Flaw Exploited to Deploy Malware

    A security flaw in the KnowledgeDeliver LMS, known as CVE-2026-5426, was exploited by a threat actor to inject malicious code and infect users visiting the site. This vulnerability was caused by a predictable secret in the system's web.config file, allowing attackers to execute remote code.

    osintsights.com/knowledgedeliv

    #RemoteCodeExecution #LmsSecurity #Cve20265426 #MalwareOperations #EmergingThreats

  27. #Google has accidentally leaked details about an unfixed issue in #Chromium that keeps #JavaScript running in the background even when the browser is closed, allowing #remotecodeexecution on the device.
    An attacker could #exploit the problem to create a malicious webpage with a Service Worker, such as a download task, that never terminates. Rebane says that this could allow an attacker to execute JavaScript code on the visitors' devices.
    bleepingcomputer.com/news/secu #RCE

  28. NGINX Flaw CVE-2026-42945 Actively Exploited, Threatens Worker Crashes and RCE

    A newly discovered NGINX flaw, CVE-2026-42945, is being actively exploited, posing a significant threat of worker crashes and remote code execution (RCE) through specially crafted HTTP requests. This high-severity vulnerability, with a CVSS score of 9.2, has been lurking in NGINX versions since 2008,…

    osintsights.com/nginx-flaw-cve

    #Nginx #Cve202642945 #RemoteCodeExecution #HeapBufferOverflow #VulnerabilityExploitation

  29. A single git push command was enough to exploit a flaw in #GitHub's internal protocol and achieve code execution on backend infrastructure.

    #RemoteCodeExecution

    CVE-2026-3854

    wiz.io/blog/github-rce-vulnera

  30. Windows ZeroDay "RedSun"
    Nur Stunden nachdem Microsoft den ersten „BlueHammer"-Zeroday gepatcht hatte, veröffentlichte der enttäuschte und offenbar tief frustrierte Forscher „Nightmare-Eclipse" seinen zweiten Angriff: „RedSun".

    Mehr: maniabel.work/archiv/1453

    #Exploit #Microsoft #PatchDay #RedSun #RemoteCodeExecution #Windows #ZeroDay #infosec #up2date

  31. Anthropic says the newly disclosed zero‑click RCE bug in Claude Desktop Extensions isn’t a design flaw to fix, citing the Model Context Protocol’s architecture. The debate raises big questions for AI agents and cybersecurity. What does this mean for developers and users? Dive into the details. #AIagents #ClaudeDesktop #RemoteCodeExecution #Cybersecurity

    🔗 aidailypost.com/news/anthropic

  32. 🚨 ALERT: FreeBSD's "security" geniuses have discovered that their router advertisements can execute code remotely! 😱💻 But don't worry, they patched it in record time—by repeating the same date and time for every version. 🕒🔧 Bravo, truly groundbreaking work! 👏
    freebsd.org/security/advisorie #FreeBSD #Security #RemoteCodeExecution #Patch #Genius #Hackers #News #HackerNews #ngated

  33. Kritische Befehls‑Injection‑Lücke im WordPress‑Plugin W3 Total Cache

    Eine schwerwiegende Sicherheitslücke (CVE‑2025‑9501, CVSS‑Score 9.0) wurde im beliebten WordPress‑Caching‑Plugin W3 Total Cache entdeckt. Sie ermöglicht Remote‑Code‑Execution – das heißt, Angreifer können beliebige Befehle auf dem Server ausführen, ohne sich vorher authentifizieren zu müssen.

    #wordpress #plugin #w3totalcache #infosec #infosecnews #RemoteCodeExecution

    beyondmachines.net/event_detai