Tag

Remote Code Execution

All articles tagged with #remote code execution

Citrix NetScaler Zero-Day Exploitation Triggers Global Emergency Patching
cybersecurity11 days ago

Citrix NetScaler Zero-Day Exploitation Triggers Global Emergency Patching

Citrix NetScaler appliances are facing active exploitation of critical zero-day vulnerabilities, specifically CVE-2026-88771, which allows unauthenticated remote code execution on default configurations. The flaw stems from improper input validation in a Perl script used for log analysis, enabling attackers to inject commands via crafted HTTP requests. While Citrix released patches for eight total vulnerabilities, the delay in official disclosure allowed threat actors to exploit the flaw in the wild before government agencies intervened. CISA has now mandated that U.S. federal agencies patch these systems by September 30, while Dutch hospitals have already restricted patient access to mitigate risks. The incident highlights a recurring pattern of Citrix NetScaler vulnerabilities being exploited before official advisories are published, prompting security firms to urge immediate isolation of affected devices.

Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days
security12 days ago

Citrix Confirms Active Exploitation of Two NetScaler RCE Zero-Days

Citrix confirmed on September 27 that two critical remote code execution (RCE) vulnerabilities in NetScaler ADC and Gateway are being actively exploited in the wild. The flaws, identified as CVE-2026-88771 and CVE-2026-88772, both carry a CVSS v4 score of 9.5. CVE-2026-88771 affects all default configurations, while CVE-2026-88772 impacts devices with DTLS enabled, which is standard for VPN virtual servers. Citrix released patches for these and six additional vulnerabilities, urging immediate installation. The disclosure followed private warnings from the Dutch NCSC and security firm watchTowr, with some administrators taking appliances offline before the official advisory.

WordPress 7.1.2 Patched as Attackers Escalate Exploitation of Critical Path Traversal Flaw
cybersecurity15 days ago

WordPress 7.1.2 Patched as Attackers Escalate Exploitation of Critical Path Traversal Flaw

Attackers began exploiting a critical WordPress vulnerability within hours of its disclosure, escalating from reconnaissance to active remote code execution attempts. The flaw, CVE-2026-87902, allows unauthenticated attackers to load arbitrary PHP files if specific theme and server conditions are met. WordPress released version 7.1.2 to fix the issue, urging immediate updates as exploitation attempts surged tenfold.

Attackers Exploit WordPress Path Traversal Flaw Within Hours of Patch Release
security15 days ago

Attackers Exploit WordPress Path Traversal Flaw Within Hours of Patch Release

WordPress released version 7.1.2 on September 22 to fix CVE-2026-87902, a critical unauthenticated path traversal vulnerability. The flaw allows attackers to load arbitrary PHP files, potentially leading to remote code execution on servers with specific configurations. Attackers began exploiting the vulnerability within hours of the patch, escalating from reconnaissance to writing malicious files. Site owners are urged to update immediately, as the fix is backported to all supported branches down to version 4.7.

WordPress 7.1.2 Patched as Attackers Exploit Critical Path Traversal Flaw
cybersecurity15 days ago

WordPress 7.1.2 Patched as Attackers Exploit Critical Path Traversal Flaw

WordPress released version 7.1.2 on September 22 to fix CVE-2026-87902, a critical unauthenticated path traversal vulnerability. Attackers began exploiting the flaw within hours of the patch, escalating from reconnaissance to writing malicious files that execute shell commands. The vulnerability, rated 9.2/10, affects versions 4.7 through 7.1.1 and requires specific server configurations for full remote code execution.

PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch
security1 month ago

PaperCut Flaw Chain Enables Unauthenticated Remote Code Execution, Prompting Emergency Patch

Hackers chained two PaperCut NG/MF flaws—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading)—to trigger unauthenticated remote code execution and alter server configuration; after an emergency patch with further hardening, exploitation appears limited but active, with attackers using Base64-encoded commands to identify the victim and a Java class to enumerate processes and files. Organizations should remove public exposure, apply the latest patches, and restrict access to trusted networks while monitoring logs for compromise indicators.

PaperCut rolls out second emergency patch to seal auth-bypass and RCE flaws
security1 month ago

PaperCut rolls out second emergency patch to seal auth-bypass and RCE flaws

PaperCut released Emergency Patch Release 2 to address two actively exploited flaws in NG/MF—CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (unsafe dynamic class loading leading to remote code execution). The update adds hardening beyond the first patch and is required for NG/MF 24–26; customers should upgrade (and restrict web interface access with firewalls) while investigators track post-exploitation activity and IOCs.

CISA orders rapid patch for actively exploited Zimbra flaw
security1 month ago

CISA orders rapid patch for actively exploited Zimbra flaw

CISA has ordered U.S. federal agencies to patch CVE-2026-73570 in Zimbra Collaboration Suite within three days after the flaw was actively exploited, enabling unauthenticated remote code execution via a SNMP command-injection vulnerability when SNMP notifications are enabled. Zimbra patched the vulnerability in version 10.1.20 (July 20). CERT Polska flagged exploitation in the wild; Shadowserver reports thousands of exposed Zimbra servers and hundreds of compromised instances. Authorities urge checking logs for suspicious activity and for files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps, and /tmp over the past month. Given ZCS’s widespread use, governments and businesses remain at risk, with past campaigns tied to APT groups exploiting Zimbra flaws.

Entra ID RCE Flaw Prompts Cloud Security Scrutiny as Patch Goes Server‑Side
cyber-security1 month ago

Entra ID RCE Flaw Prompts Cloud Security Scrutiny as Patch Goes Server‑Side

Microsoft disclosed a critical remote code execution vulnerability in Entra ID (CVE-2026-69836) caused by deserialization of untrusted data (CWE-502) that could allow unauthenticated attackers to run arbitrary code on the identity service. Microsoft has deployed a server-side patch with no customer action required; initial reports of in‑the‑wild exploitation are now clarified as not currently active. Security teams should still review Entra ID sign-in logs, tighten conditional access, and monitor privileged roles across the Microsoft ecosystem.

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution
security1 month ago

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution

Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that could let attackers with no privileges execute code remotely and escalate privileges. Key flaws include CVE-2026-69836 in Entra ID (deserialization of untrusted data), CVE-2026-65816 and CVE-2026-69555 in Azure Arc, CVE-2026-65801 in Exchange Online, and CVE-2026-65770 affecting an Azure Managed Instance for Apache Cassandra. Patches are in place and no action is required, with exploit code not publicly available. An August update notes CVE-2026-69836 was initially misflagged as exploited in the wild.

Zimbra RCE Flaw CVE-2026-73570 Actively Exploited in the Wild
technology1 month ago

Zimbra RCE Flaw CVE-2026-73570 Actively Exploited in the Wild

Polish CERT Polska reports active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite, a SNMP-related command-injection remote-code-execution flaw. Zimbra patched it in 10.1.20 (July 20). Unauthenticated attackers can trigger OS commands via crafted SMTP requests when SNMP is enabled. Shadowserver lists over 12,000 exposed Zimbra servers, mainly in Europe and Asia; admins should check logs for anomalies and update to the patched release.

GeoServer Zero-Day Actively Exploited, Elevating RCE Risk
technology1 month ago

GeoServer Zero-Day Actively Exploited, Elevating RCE Risk

A newly disclosed, unpatched GeoServer SQL injection zero-day is being actively exploited, with potential remote code execution. Researchers report hundreds of attempts from a small IP pool; no CVE yet. Admins should identify exposed instances, restrict public access, and monitor for a vendor patch. GeoServer has a history of severe vulnerabilities, so stay alert for updates.

Active macOS Screen Sharing Flaw Lets Attackers Gain Root Access
technology1 month ago

Active macOS Screen Sharing Flaw Lets Attackers Gain Root Access

A high-severity macOS flaw (CVE-2026-65400) in the screen-sharing feature is under active exploitation, allowing remote attackers to gain root access when port 5900 is exposed to the Internet. Affected systems can be controlled remotely, with attackers potentially installing malware or stealing data. Apple has patched the vulnerability for macOS Tahoe, Sequoia, and Sonoma. For now, reports indicate attackers are using the flaw to deploy Monero miners; best defenses include turning off screen sharing when not in use, blocking port 5900, and applying the latest updates or connecting via VPN/SSH when needed.

JetBrains flags critical TeamCity RCE via auth bypass (CVE-2026-63077)
security2 months ago

JetBrains flags critical TeamCity RCE via auth bypass (CVE-2026-63077)

JetBrains warns that TeamCity On-Premises is vulnerable to a critical authentication bypass vulnerability (CVE-2026-63077) that could enable remote code execution via the agent polling protocol. All On-Prem versions are affected; Cloud customers are protected. Mitigations include upgrading to TeamCity 2025.11.7 or 2026.1.3, or applying the patch plugin for older releases (with restart required for 2017.1–2018.1). TeamCity 2024.03+ auto-downloads patches. Follow best practices to limit exposure (VPN/private networks) since exposing login pages or REST APIs can give attackers entry. No active exploitation reported as of the advisory, but prompt remediation is advised.