Tag

Remote Code Execution

All articles tagged with #remote code execution

CISA orders rapid patch for actively exploited Zimbra flaw
security1 day ago

CISA orders rapid patch for actively exploited Zimbra flaw

CISA has ordered U.S. federal agencies to patch CVE-2026-73570 in Zimbra Collaboration Suite within three days after the flaw was actively exploited, enabling unauthenticated remote code execution via a SNMP command-injection vulnerability when SNMP notifications are enabled. Zimbra patched the vulnerability in version 10.1.20 (July 20). CERT Polska flagged exploitation in the wild; Shadowserver reports thousands of exposed Zimbra servers and hundreds of compromised instances. Authorities urge checking logs for suspicious activity and for files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps, and /tmp over the past month. Given ZCS’s widespread use, governments and businesses remain at risk, with past campaigns tied to APT groups exploiting Zimbra flaws.

Entra ID RCE Flaw Prompts Cloud Security Scrutiny as Patch Goes Server‑Side
cyber-security2 days ago

Entra ID RCE Flaw Prompts Cloud Security Scrutiny as Patch Goes Server‑Side

Microsoft disclosed a critical remote code execution vulnerability in Entra ID (CVE-2026-69836) caused by deserialization of untrusted data (CWE-502) that could allow unauthenticated attackers to run arbitrary code on the identity service. Microsoft has deployed a server-side patch with no customer action required; initial reports of in‑the‑wild exploitation are now clarified as not currently active. Security teams should still review Entra ID sign-in logs, tighten conditional access, and monitor privileged roles across the Microsoft ecosystem.

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution
security2 days ago

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution

Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that could let attackers with no privileges execute code remotely and escalate privileges. Key flaws include CVE-2026-69836 in Entra ID (deserialization of untrusted data), CVE-2026-65816 and CVE-2026-69555 in Azure Arc, CVE-2026-65801 in Exchange Online, and CVE-2026-65770 affecting an Azure Managed Instance for Apache Cassandra. Patches are in place and no action is required, with exploit code not publicly available. An August update notes CVE-2026-69836 was initially misflagged as exploited in the wild.

Zimbra RCE Flaw CVE-2026-73570 Actively Exploited in the Wild
technology4 days ago

Zimbra RCE Flaw CVE-2026-73570 Actively Exploited in the Wild

Polish CERT Polska reports active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite, a SNMP-related command-injection remote-code-execution flaw. Zimbra patched it in 10.1.20 (July 20). Unauthenticated attackers can trigger OS commands via crafted SMTP requests when SNMP is enabled. Shadowserver lists over 12,000 exposed Zimbra servers, mainly in Europe and Asia; admins should check logs for anomalies and update to the patched release.

GeoServer Zero-Day Actively Exploited, Elevating RCE Risk
technology10 days ago

GeoServer Zero-Day Actively Exploited, Elevating RCE Risk

A newly disclosed, unpatched GeoServer SQL injection zero-day is being actively exploited, with potential remote code execution. Researchers report hundreds of attempts from a small IP pool; no CVE yet. Admins should identify exposed instances, restrict public access, and monitor for a vendor patch. GeoServer has a history of severe vulnerabilities, so stay alert for updates.

Active macOS Screen Sharing Flaw Lets Attackers Gain Root Access
technology11 days ago

Active macOS Screen Sharing Flaw Lets Attackers Gain Root Access

A high-severity macOS flaw (CVE-2026-65400) in the screen-sharing feature is under active exploitation, allowing remote attackers to gain root access when port 5900 is exposed to the Internet. Affected systems can be controlled remotely, with attackers potentially installing malware or stealing data. Apple has patched the vulnerability for macOS Tahoe, Sequoia, and Sonoma. For now, reports indicate attackers are using the flaw to deploy Monero miners; best defenses include turning off screen sharing when not in use, blocking port 5900, and applying the latest updates or connecting via VPN/SSH when needed.

JetBrains flags critical TeamCity RCE via auth bypass (CVE-2026-63077)
security25 days ago

JetBrains flags critical TeamCity RCE via auth bypass (CVE-2026-63077)

JetBrains warns that TeamCity On-Premises is vulnerable to a critical authentication bypass vulnerability (CVE-2026-63077) that could enable remote code execution via the agent polling protocol. All On-Prem versions are affected; Cloud customers are protected. Mitigations include upgrading to TeamCity 2025.11.7 or 2026.1.3, or applying the patch plugin for older releases (with restart required for 2017.1–2018.1). TeamCity 2024.03+ auto-downloads patches. Follow best practices to limit exposure (VPN/private networks) since exposing login pages or REST APIs can give attackers entry. No active exploitation reported as of the advisory, but prompt remediation is advised.

SharePoint deserialization flaw used to steal machine keys and sustain access after patching
security1 month ago

SharePoint deserialization flaw used to steal machine keys and sustain access after patching

Security researchers warn that the critical SharePoint deserialization flaw CVE-2026-50522 is being exploited to steal machine keys, enabling attackers to forge tokens and linger on-premises deployments even after patches; PoC exploits circulated online, prompting defenders to apply July updates and rotate credentials to limit exposure.

Public WordPress wp2shell Exploit Triggers Global RCE Wave
security1 month ago

Public WordPress wp2shell Exploit Triggers Global RCE Wave

Attackers are abusing two flaws, CVE-2026-63030 and CVE-2026-60137 (wp2shell), to achieve unauthenticated remote code execution on stock WordPress installs. Public PoCs and AI-assisted tooling have spurred widespread scanning and exploitation, including admin account creation, malicious plugins, and web shells like CMSmap. While automatic updates and some WAF protections have reduced risk, many sites may remain unpatched; defenders should patch immediately and audit for indicators of compromise such as new admins and suspicious plugins.

WordPress under attack: chained flaws enable pre-auth remote code execution after patches
technology1 month ago

WordPress under attack: chained flaws enable pre-auth remote code execution after patches

After WordPress released patches for CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API route confusion), attackers quickly weaponized both flaws to enable unauthenticated remote code execution. Public PoCs and AI-assisted tooling spurred rapid exploitation, with tens of thousands of attempts and hundreds of backdoor admin accounts, fake plugins, and attempts to fetch tools like Overlord RAT. WordPress also forced auto-updates for affected sites. Patches are in WordPress 6.9.5 and 7.1 Beta 2 (6.8.6 for the SQLi; older versions affected differently). Admins should patch immediately and audit for backdoors and suspicious plugins.

Patch Released for NGINX Two-Pass Overflow That Could Enable Remote Code Execution
technology1 month ago

Patch Released for NGINX Two-Pass Overflow That Could Enable Remote Code Execution

F5 issued fixes for a critical NGINX flaw (CVE-2026-42533) that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the script engine via a specific two-pass evaluation of regex-based maps, potentially causing a crash or remote code execution if ASLR is disabled. All versions up to 1.31.2 are affected; upgrade to nginx 1.30.4 (stable), 1.31.3 (mainline), or NGINX Plus 37.0.3.1. As a temporary mitigation, switch affected regex maps to named captures, though full remediation requires upgrading; exposure depends on configuration, not just version.

Microsoft patches 570 flaws in July 2026 Patch Tuesday, including three zero-days
technology1 month ago

Microsoft patches 570 flaws in July 2026 Patch Tuesday, including three zero-days

Microsoft’s July 2026 Patch Tuesday fixes roughly 570 vulnerabilities across Windows, Office, Azure, and related services, including three zero-days. The updates cover remote code execution, elevation of privilege, spoofing, and information disclosure across a wide range of components such as AD DS, RDP, Office apps, and core OS subsystems, so applying these patches promptly is essential to reduce exposure.

Unsecured Splunk Flaw Could Allow Unauthenticated Writes and Remote Code Execution
security2 months ago

Unsecured Splunk Flaw Could Allow Unauthenticated Writes and Remote Code Execution

Security updates fix CVE-2026-20253 in Splunk Enterprise, a critical flaw that allowed unauthenticated file operations and potential pre-auth remote code execution via the PostgreSQL sidecar endpoint; affected versions include 10.0.0–10.0.6 (fixed in 10.0.7) and 10.2.0–10.2.3 (fixed in 10.2.4); Splunk Cloud and Splunk 10.4 are not affected. An attacker could abuse /backup and /restore to drop malicious SQL and write a payload to the file system, escalating to code execution; users should upgrade immediately.