remote code execution
-
Adobe ColdFusion flaw exploited within hours of disclosure, researcher says
Attackers are exploiting a maximum-severity Adobe ColdFusion flaw, CVE-2026-48282, within hours of disclosure, according to a researcher. The bug can enable remote code execution on unpatched systems, and officials have urged rapid patching.
-
Microsoft details AutoJack flaw that could let a web page trigger code on AI agent hosts
Microsoft said a flaw in AutoGen Studio could let a single web page trigger code execution on the host running an AI browsing agent. The issue affects two pre-release PyPI builds, while the stable release is not exposed.
-
Unpatched Langflow flaw under active exploitation, researchers say
An unpatched Langflow flaw tracked as CVE-2026-5027 is being actively exploited, researchers say. The bug can allow arbitrary file writes, and about 7,000 instances are exposed online.
-
Veeam patches critical backup software flaw that could allow remote code execution
Veeam patched a critical flaw in Backup & Replication that could allow remote code execution on a backup server. The bug affects some 12.x releases and was fixed in version 12.3.2.4854.
-
CISA adds exploited Magento extension flaw to known vulnerabilities list
CISA added a critical Magento extension flaw to its exploited vulnerabilities catalog after reports of active abuse. The bug, CVE-2026-45247, can allow remote code execution and affects versions of Mirasvit Cache Warmer before 1.11.12.
-
Critical Gogs flaw can let authenticated users run code on servers
A critical, unpatched flaw in Gogs can let authenticated users run arbitrary code on affected servers under certain conditions, with Rapid7 rating the issue 9.4 on the CVSS scale and reporting no CVE yet.
-
Microsoft patches SharePoint flaw that could let authenticated attackers run code
Microsoft has patched a SharePoint remote code execution flaw tracked as CVE-2026-45659, saying an authenticated attacker with Site Member access could exploit it. The update covers several SharePoint Server versions.
-
Researchers disclose critical SEPPMail gateway flaws that could allow remote code execution
Researchers disclosed seven critical flaws in SEPPMail Secure E-Mail Gateway that could allow remote code execution and reading of arbitrary mail. SEPPmail has issued fixes across recent versions, including patches for multiple CVEs rated above 9.0.
-
NGINX flaw left hidden for 18 years could allow remote code execution
A critical NGINX rewrite module flaw hidden for 18 years can let a remote attacker trigger code execution or denial of service with crafted requests, according to a technical analysis and vendor advisory.
-
Critical Exim flaw can let remote attackers run code on affected servers
A critical Exim flaw fixed in version 4.99.3 could let unauthenticated attackers execute code on affected mail servers. The bug affects some GnuTLS-based builds before 4.99.3 and is triggered during TLS shutdown with chunked SMTP traffic.







