Adobe Commerce
-
Public exploits published for critical WordPress core flaws, patch urged
Public exploits are now circulating for critical WordPress core flaws that can chain into unauthenticated remote code execution. Site owners are being urged to update to WordPress 6.9.5 or 7.0.2 immediately.
-
Hackers exploit critical Everest Forms Pro flaw to seize WordPress sites
Hackers are exploiting a critical flaw in Everest Forms Pro to take over WordPress sites. Wordfence said more than 29,300 attack attempts were blocked after the March patch, and some attacks created rogue administrator accounts.
-
Redis patches two-year-old use-after-free flaw that enabled remote command execution
Redis patched CVE-2026-23479, a use-after-free flaw in blocking-client code that could lead to remote command execution. The bug affected versions 7.2.0 through 8.6.2 and had gone unnoticed for more than two years.
-
Google patches critical Gemini CLI flaw that could allow remote code execution
Google fixed a critical Gemini CLI flaw that could let attackers execute commands on host systems in headless CI workflows. The issue affected specific npm and GitHub Actions versions and required explicit folder trust after the update.
-
Critical SGLang flaw can enable remote code execution
A critical flaw in SGLang, tracked as CVE-2026-5760 and rated 9.8, could allow remote code execution through a crafted model file and the /v1/rerank endpoint, according to a CERT/CC advisory.
-
Critical protobuf.js flaw enables JavaScript code execution
A critical flaw in protobuf.js can let attackers execute JavaScript code through malicious schemas, with a proof-of-concept now public. The issue affects versions 8.0.0 and 7.5.4 and earlier, and patched releases are available.
-
CISA adds Apache ActiveMQ flaw CVE-2026-34197 to exploited list
CISA says a high-severity Apache ActiveMQ Classic flaw, CVE-2026-34197, is being exploited in the wild. The agency added it to its Known Exploited Vulnerabilities catalog and ordered federal fixes by April 30.
-
Oracle issues emergency fix for critical Identity Manager and Web Services Manager RCE
Oracle issued an out-of-schedule patch for CVE-2026-21992, a critical unauthenticated remote code execution flaw in Identity Manager and Web Services Manager with a CVSS score of 9.8. Customers are urged to patch immediately.
-
Two critical n8n flaws patched after researcher finds remote code execution risk
Two critical vulnerabilities in the n8n workflow platform were reported and patched in March 2026. A technical analysis and vendor advisories show flaws that can enable remote code execution and decryption of stored credentials.









