Threats Tagged 'rce'
View all threats tagged with 'rce'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'rce'
Click on any threat for detailed analysis and mitigation recommendations
New WordPress Pre-Auth XSS (CVE-2026-64638) Could Lead to RCE: Have you patched your instances yet?CVE-2026-64638 0 CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress login pages that can lead to remote code execution (RCE) under specific conditions. The flaw allows attacker-controlled JavaScript to execute in the browser of a visitor after a failed login attempt. Exploitation requires a logged-in administrator to interact with an attacker-controlled page, potentially enabling PHP code execution on the server. The vulnerability affects default WordPress installations and was patched in WordPress 7.0.3 and backported to versions back through 4.7. Versions older than 4.7 remain vulnerable. WordPress recommends immediate updating, and automatic background updates should apply the patch automatically. No in-the-wild exploitation has been reported as of the advisory date. Join the discussion | Reddit Cybersecurity | 08/07/2026, 14:20:01 UTC Added: 08/07/2026, 14:26:03 UTC |
Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix 0 NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities. The post Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/07/2026, 10:00:00 UTC Added: 08/07/2026, 10:11:13 UTC |
ZDI-26-525: (0Day) PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability 0 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. Join the discussion | Zero Day Initiative | 08/05/2026, 05:00:00 UTC Added: 08/05/2026, 18:45:38 UTC |
ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability 0 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. Join the discussion | Zero Day Initiative | 08/05/2026, 05:00:00 UTC Added: 08/05/2026, 18:45:38 UTC |
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities 0 The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/05/2026, 09:44:50 UTC Added: 08/05/2026, 09:56:11 UTC |
40%+ of AI-Generated Code Has Security Issues; We Open-Sourced a Way to Help 0 Research indicates that over 40% of AI-generated code contains security issues, often due to missing framework- and version-specific security details. To address this, an open-source project called AI Code Security Cards provides library-specific security guidance for developers and AI coding agents. The project covers more than 60 libraries and frameworks across multiple programming languages, offering practical instructions to mitigate common security pitfalls. This initiative aims to improve the security posture of AI-generated code by guiding coding agents on unsafe defaults, validation, authentication patterns, and security changes between library versions. Join the discussion | Reddit Cybersecurity | 08/05/2026, 09:34:58 UTC Added: 08/05/2026, 09:56:02 UTC |
TP-Link patches Omada ZTP flaws allowing hackers to breach networks 0 TP-Link has released patches for 15 vulnerabilities in the zero-touch provisioning (ZTP) feature of its Omada network devices. These vulnerabilities could be chained with previously disclosed flaws to enable remote code execution (RCE) by attackers. The vulnerabilities affect the ZTP mechanism, which is used to simplify device deployment and configuration. No known exploits are reported in the wild at this time. Join the discussion | Bleeping Computer | 08/04/2026, 22:18:20 UTC Added: 08/04/2026, 22:26:14 UTC |
VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystemCVE-2026-14890 0 A pickle deserialization vulnerability (CVE-2026-14890) exists in the SGLang open-source framework's expert-parallel backup subsystem. This vulnerability allows unauthenticated remote code execution if the subsystem is enabled and reachable over the network. The issue arises because a ZeroMQ PULL socket binds to an external IP without authentication or deserialization safeguards, allowing malicious pickle payloads to be processed. No patch is currently available, and the maintainers have not responded to coordination efforts. Mitigations include disabling the pickle IPC feature and restricting network access to the vulnerable interface. Join the discussion | CERT/CC | 07/16/2026, 14:43:27 UTC Added: 08/04/2026, 13:00:07 UTC |
A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave 0 A set of three vulnerabilities were discovered in the BigWave driver on the Pixel 9 device, which is accessible from the mediacodec sandboxed context. One of these bugs enables a use-after-free condition that allows escaping the mediacodec sandbox and achieving arbitrary kernel read/write on the Pixel 9. The vulnerabilities were fixed on January 5, 2026. The BigWave driver accelerates AV1 decoding and is exposed to userland processes in the mediacodec SELinux context, which is intended to be constrained. The use-after-free arises from a race condition between ioctl processing and a worker thread handling hardware jobs, leading to a kernel object being freed while still referenced. Join the discussion | Google Project Zero | 01/14/2026, 18:00:00 UTC Added: 08/04/2026, 12:57:56 UTC |
CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents ToolsCVE-2026-18733 0 Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733. The shell tool includes a human consent gate that prompts the operator to approve commands before they run. The tool also exposed a non_interactive parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted content the agent reads (indirect prompt injection), could set non_interactive to true, which bypasses the consent gate and allows arbitrary operating system commands to execute on the agent's host without operator approval. Impacted versions: < 0.8.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | AWS Security Bulletins | 08/03/2026, 20:38:42 UTC Added: 08/03/2026, 20:45:32 UTC |
Showing 1 to 10 of 126 results