Threats Tagged 'rce'
View all threats tagged with 'rce'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'rce'
Click on any threat for detailed analysis and mitigation recommendations
WordPress patched a vulnerability called Click2Shell that allowed attackers to automatically install and preview inactive themes via specially crafted URLs. This flaw could lead to remote code execution (RCE) by abusing how theme slugs are interpreted differently by the themes API and JavaScript in an administrator's browser. Attackers could force installation of attacker-selected themes fetched from the official WordPress.org catalog without administrator consent. Some inactive third-party themes could be exploited for PHP code execution during the Customizer preview, enabling attackers to execute code under the WordPress server account without needing an attacker WordPress account. The vulnerability was fixed in WordPress version 7.1.1 and backported to versions as early as 4.7. Join the discussion | SecurityWeek | 09/22/2026, 10:22:27 UTC Added: 09/22/2026, 10:32:45 UTC |
0 Orkes Conductor versions before 3.30.2 contain a critical unauthenticated remote code execution vulnerability. Attackers can submit malicious inline workflow definitions with JavaScript or Python expressions to the workflow API endpoint without authentication. This exploits unsandboxed GraalVM evaluators with permissive host access, enabling arbitrary OS command execution via Java reflection or subprocess calls. Join the discussion | CVE Database V5 | 09/18/2026, 08:42:18 UTC Added: 06/30/2026, 18:51:33 UTC |
A critical vulnerability (CVE-2026-91843) affects Check Point Security Management and Log Server products, allowing unauthenticated remote code execution with root privileges via the login process. No evidence of active exploitation in the wild has been reported. Check Point has issued patches and advises immediate updates for systems without automatic patching. Additionally, Tanium and Kaspersky have patched multiple vulnerabilities in their products, including SQL injection and code execution flaws. These vulnerabilities pose significant risks if left unpatched. Join the discussion | SecurityWeek | 09/18/2026, 07:14:04 UTC Added: 09/18/2026, 07:16:37 UTC |
Cisco has released patches for multiple critical vulnerabilities affecting Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. These vulnerabilities include remote code execution, command injection, authentication bypass, SQL injection, and other flaws that could lead to root access and denial-of-service conditions. Some of the vulnerabilities have been publicly disclosed and exploited in the wild, including a zero-day authentication bypass in ISE. Cisco has issued security advisories detailing these issues and providing fixes. Join the discussion | SecurityWeek | 09/17/2026, 12:17:40 UTC Added: 09/17/2026, 12:31:40 UTC |
MLflow's dspy and statsmodels model flavors contain vulnerabilities that bypass the MLFLOW_ALLOW_PICKLE_DESERIALIZATION safety control designed to prevent unsafe pickle deserialization. The dspy flavor conditionally applies this control only if the model path ends with .pkl, allowing bypass if the file extension differs. The statsmodels flavor does not apply the control at all. This allows arbitrary remote code execution via malicious pickle payloads when loading models through these flavors. The vulnerability was confirmed in MLflow 3.12.0. The statsmodels flavor issue is patched in versions 3.15.0 and later. Users should upgrade and avoid using the dspy flavor until a fix is available. Join the discussion | CERT/CC | 09/16/2026, 17:10:46 UTC Added: 09/16/2026, 17:14:13 UTC |
0 CVE-2026-81578 is a high-severity authentication bypass vulnerability in PaperCut MF/NG that enables attackers to impersonate legitimate users and obtain authentication tokens. The vulnerability was exploited in a sophisticated phishing campaign named GhostCode, which used device code phishing via web contact forms and abused Microsoft's OAuth 2.0 device authorization grant flow. Attackers used obfuscated, password-protected HTML files and residential proxy rotation to evade detection and harvest credentials. The campaign involved registering attacker-controlled devices and harvesting emails shortly after victim authentication. Join the discussion | CVE Database V5 | 09/16/2026, 12:51:13 UTC Added: 08/28/2026, 15:38:05 UTC |
Two critical unauthenticated remote code execution (RCE) vulnerabilities affect The Events Calendar WordPress plugin versions before 6.17.3.1 and 6.17.4.1. These flaws allow attackers to execute arbitrary code and potentially take over affected WordPress sites. The first vulnerability (CVE-2026-78159) involves unauthenticated code injection via insufficient validation, patched in version 6.17.3.1. The second (CVE-2026-78006) is an unauthenticated PHP object injection exploitable if event comments are enabled, fixed in version 6.17.4.1. Approximately 240,000 sites using vulnerable versions may be exposed, though exploitation requires comments to be enabled. Both vulnerabilities lead to full site compromise if exploited. Join the discussion | SecurityWeek | 09/16/2026, 11:32:53 UTC Added: 09/16/2026, 11:46:36 UTC |
The GemStuffer incident involved AI agents exploiting a documentation feature in RubyGems infrastructure to achieve remote code execution (RCE). Specifically, the YARD tool's --load option in .yardopts files was abused to execute arbitrary Ruby code during automated documentation builds on RubyDoc.info. The attackers created disposable accounts, bypassed email confirmation, and uploaded over 2,000 malicious packages that weaponized this feature. This incident highlights a broader class of vulnerabilities where legitimate scripting or code execution features in configuration files are abused in package ecosystems. The attack demonstrates a real supply chain risk from automated AI-driven exploitation. Join the discussion | Reddit Cybersecurity | 09/15/2026, 22:24:22 UTC Added: 09/16/2026, 16:46:27 UTC |
0 A Chinese-speaking threat actor tracked as Red Heron rapidly weaponized CVE-2026-60004, a critical Gitea remote code execution vulnerability, within days of public disclosure in July 2026. The actor scanned 1,386 Gitea instances across seven countries, successfully compromising organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka. Activities included source code theft, credential collection, SSH persistence, and lateral movement, with one case escalating from a vulnerable Gitea server to root access across a three-node Proxmox cluster. An exposed staging server revealed targeting taxonomies using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, and government sectors. The campaign deployed JITTERLY, a C++ Linux implant with 30+ post-exploitation commands, embedding SIXZUT, a previously undocumented LD_PRELOAD rootkit capable of hiding files, processes, and network connections while protecting the implant from termination. Join the discussion | SecurityWeek | 09/15/2026, 13:05:50 UTC Added: 08/26/2026, 05:22:13 UTC |
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...] Join the discussion | Bleeping Computer | 09/15/2026, 12:16:32 UTC Added: 09/16/2026, 05:47:03 UTC |
Showing 1 to 10 of 739 results