Threats Tagged 'code-execution'
View all threats tagged with 'code-execution'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'code-execution'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-39949 is an authenticated remote code execution vulnerability in Cacti versions up to and including 1.2.30. The flaw arises from unsanitized variable substitution in RRDtool command-line arguments, allowing users with graph management privileges to inject arbitrary OS commands via host metadata fields such as the device notes. Exploitation requires authenticated access with permissions to create devices and graph templates. An attacker can craft malicious input in the notes field and trigger code execution during graph rendering. Join the discussion | Reddit Cybersecurity | 06/16/2026, 21:06:50 UTC Added: 06/16/2026, 21:15:06 UTC |
A high-severity vulnerability (CVE-2026-5027) in the Langflow low-code AI development platform allows unauthenticated attackers to write files to arbitrary locations via a path traversal flaw in the 'POST /api/v2/files' endpoint. This flaw enables remote code execution (RCE) because the filename parameter is not sanitized, and Langflow's default unauthenticated auto-login allows attackers to reach the vulnerable endpoint without credentials. Exploitation attempts have been observed in the wild, with attackers dropping test files on victim systems. Approximately 7,000 Langflow instances are internet-accessible, mostly in North America. The vulnerability was publicly disclosed in March 2026, and no patch or official fix information is provided in the source content. Join the discussion | Reddit Cybersecurity | 06/11/2026, 12:17:00 UTC Added: 06/11/2026, 12:22:18 UTC |
A critical remote code execution vulnerability has been identified in SmarterMail, a widely used mail server software. The Cyber Security Agency (CSA) has issued an alert highlighting the severity of this bug, which could allow attackers to execute arbitrary code remotely without authentication. Although no known exploits are currently reported in the wild, the potential impact is significant due to the critical nature of the flaw. This vulnerability threatens the confidentiality, integrity, and availability of affected mail servers, potentially enabling full system compromise. European organizations relying on SmarterMail for email services are at risk, especially those in countries with higher adoption rates of this software. Immediate mitigation steps include monitoring official advisories for patches, restricting network access to SmarterMail servers, and enhancing intrusion detection capabilities. Given the lack of a CVSS score, the severity is assessed as critical due to the ease of exploitation and potential for widespread impact. Organizations should prioritize vulnerability management and incident response readiness to defend against potential exploitation attempts. Join the discussion | Reddit InfoSec News | 12/30/2025, 22:18:48 UTC Added: 12/30/2025, 22:28:49 UTC |
A high-severity remote code execution vulnerability has been identified in Digiever Network Video Recorder (NVR) systems, flagged by CISA as actively exploited. This vulnerability allows attackers to execute arbitrary code remotely, potentially compromising affected devices without requiring user interaction or authentication. Although no specific affected versions or patches have been disclosed yet, the threat is considered high priority due to its exploitation potential. European organizations using Digiever NVRs, especially in critical infrastructure and surveillance sectors, face risks of unauthorized access, data breaches, and operational disruption. Mitigation should focus on immediate network segmentation, monitoring for suspicious activity, and applying vendor updates as soon as they become available. Countries with higher adoption of Digiever products and strategic surveillance deployments, such as Germany, France, and the UK, are likely more impacted. Given the ease of exploitation and potential impact on confidentiality, integrity, and availability, the severity is assessed as high. Defenders must prioritize detection and containment measures while awaiting official patches. Join the discussion | Reddit InfoSec News | 12/25/2025, 13:00:15 UTC Added: 12/25/2025, 13:08:14 UTC |
A critical vulnerability in n8n, an open-source workflow automation tool, has been disclosed with a CVSS score of 9.9, enabling arbitrary code execution on thousands of instances. This flaw allows attackers to execute malicious code remotely, potentially compromising confidentiality, integrity, and availability of affected systems. Although no known exploits are currently in the wild, the severity and ease of exploitation make this a high-risk threat. European organizations using n8n for automation and integration tasks could face significant operational disruptions and data breaches. Immediate patching and mitigation are essential to prevent exploitation. The countries most likely affected are those with high adoption of n8n and significant digital transformation initiatives, including Germany, the UK, France, and the Netherlands. Mitigation requires applying vendor patches when available, restricting network access to n8n instances, and implementing strict input validation and monitoring. Given the critical impact and ease of exploitation without authentication, this threat is assessed as critical severity. Defenders must prioritize detection and response strategies to mitigate potential attacks leveraging this vulnerability. Join the discussion | Reddit InfoSec News | 12/23/2025, 11:01:57 UTC Added: 12/23/2025, 11:05:39 UTC |
A critical vulnerability in HPE OneView has been disclosed, allowing unauthenticated remote code execution with a CVSS score of 10.0. This flaw enables attackers to execute arbitrary code on affected systems without any authentication or user interaction, posing a severe risk to confidentiality, integrity, and availability. Although no known exploits are currently active in the wild, the vulnerability's critical nature demands immediate attention. European organizations using HPE OneView for infrastructure management are at significant risk, especially those in sectors reliant on HPE hardware and management tools. Mitigation requires prompt application of vendor patches once available, network segmentation, and strict access controls to limit exposure. Countries with high adoption of HPE enterprise solutions and critical infrastructure sectors, such as Germany, the UK, France, and the Netherlands, are likely to be most affected. Given the ease of exploitation and potential for widespread impact, the threat severity is assessed as critical. Defenders should prioritize detection and containment strategies while awaiting official patches. Join the discussion | Reddit InfoSec News | 12/18/2025, 19:13:02 UTC Added: 12/18/2025, 19:26:24 UTC |
Gladinet software contains hard-coded cryptographic keys that attackers actively exploit to gain unauthorized access and execute arbitrary code. This vulnerability allows adversaries to bypass authentication mechanisms, potentially leading to full system compromise. Although no known exploits are currently observed in the wild, the presence of hard-coded keys significantly lowers the barrier for exploitation. European organizations using Gladinet products are at risk, especially those relying on these tools for cloud storage and file sharing. The threat is rated high severity due to the potential impact on confidentiality, integrity, and availability without requiring user interaction. Mitigation is complicated by the lack of official patches, necessitating immediate compensating controls such as network segmentation, strict access controls, and monitoring for suspicious activity. Countries with high adoption of Gladinet or strategic cloud infrastructure are more likely to be targeted. Defenders should prioritize identifying affected systems, restricting network exposure, and preparing incident response plans to address potential exploitation attempts. Join the discussion | Reddit InfoSec News | 12/11/2025, 10:28:20 UTC Added: 12/11/2025, 10:39:14 UTC |
A critical code execution vulnerability has been identified in Ivanti Endpoint Manager, a widely used IT asset and endpoint management solution. Although specific affected versions and technical details are not disclosed, the flaw allows remote code execution, posing a severe risk to impacted environments. No known exploits have been reported in the wild yet, but the critical severity indicates potential for significant damage if exploited. European organizations using Ivanti Endpoint Manager could face risks including unauthorized access, data breaches, and disruption of endpoint management operations. Immediate attention to patching or mitigation is advised once official updates are available. The threat is particularly relevant to countries with high adoption of Ivanti products and critical infrastructure relying on endpoint management. Due to the lack of detailed technical information and patches, organizations should enhance monitoring and restrict access to management interfaces. The suggested severity is critical given the potential for full system compromise without user interaction or authentication. Defenders should prioritize threat intelligence monitoring and prepare incident response plans accordingly. Join the discussion | Reddit InfoSec News | 12/09/2025, 19:23:19 UTC Added: 12/09/2025, 19:30:19 UTC |
Critical vulnerabilities in React Server Components (RSC) within React and Next.js frameworks allow unauthenticated remote code execution (RCE). These bugs enable attackers to execute arbitrary code on vulnerable servers without requiring authentication or user interaction. The flaws stem from improper handling of server-side rendering components, exposing backend systems to direct compromise. No known exploits are currently in the wild, but the severity and potential impact are critical. European organizations using React and Next.js for server-side rendering are at significant risk, especially those with public-facing web applications. Immediate patching and code review are essential once fixes are available. Mitigation includes restricting server access, monitoring unusual activity, and applying strict input validation. Countries with high adoption of React/Next. Join the discussion | Reddit InfoSec News | 12/03/2025, 19:46:50 UTC Added: 12/03/2025, 19:59:42 UTC |
The unquoted path vulnerability is a longstanding Windows flaw that can allow hidden code execution when executable paths containing spaces are not properly quoted. This misconfiguration can enable attackers to execute malicious code by placing executables in specific directories that Windows interprets incorrectly. Although decades old, this vulnerability remains relevant due to legacy software and improper system configurations. Exploitation does not require user interaction or authentication but depends on the presence of unquoted service paths. The threat is rated medium severity due to moderate impact and exploitation complexity. European organizations using Windows systems with legacy or improperly configured services are at risk, especially in countries with high Windows market penetration and critical infrastructure reliance on such systems. Mitigation requires auditing service paths, applying proper quoting, and enforcing secure software deployment practices. Countries like Germany, France, the UK, and Italy are likely most affected given their extensive Windows usage and critical infrastructure. Defenders should prioritize detection of unquoted paths and remediation to prevent potential code execution attacks. Join the discussion | Reddit NetSec | 11/20/2025, 19:47:04 UTC Added: 11/20/2025, 19:59:14 UTC |
Showing 1 to 10 of 38 results