#rce

475 posts · Last used 4d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 06, 2026
TeamCity vulnerability CVE-2026-63077 enables unauthenticated remote code execution. CISA added it to the KEV catalog amid active exploitation. #TeamCity #CVE202663077 #RCE #CISA #KEV #CyberSecurity https://securityonline.info/teamcity-cve-2026-63077-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 06, 2026
Critical Jenkins vulnerability CVE-2026-70426 lets attackers bypass the JEP-200 filter and run code on the controller. Patch now. #Jenkins #CVE202670426 #RCE #DevSecOps #Deserialization #CyberSecurity https://securityonline.info/jenkins-cve-2026-70426-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 05, 2026
A high-severity Django vulnerability, CVE-2026-15307, can enable remote code execution through spatial lookups. Update to Django 6.0.8 or 5.2.17 now. #Django #DjangoSecurity #CVE202615307 #RCE #RemoteCodeExecution #Vulnerability #Python #WebSecurity #InfoSec #CyberSecurity https://securityonline.info/django-vulnerability-cve-2026-15307-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
OffSequence @offseq@infosec.exchange · Aug 05, 2026
CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: https://radar.offseq.com/threat/cve-2026-70553-improper-control-of-generation-of-code-code-injection-in-maxsite-maxsite-cms-5161bdfb2e6804e9 #OffSeq #CVE #websecurity #RCE
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 04, 2026
A critical Veeam Service Provider Console flaw lets attackers steal agent credentials, while a second enables remote code execution. Update to 9.3 now. #Veeam #VSPC #ServiceProviderConsole #CVE202658073 #RCE #RemoteCodeExecution #Vulnerability #MSP #CyberSecurity #InfoSec https://securityonline.info/veeam-vspc-cve-2026-58073/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 04, 2026
A critical Veeam ONE vulnerability, CVE-2026-64633, allows remote unauthenticated code execution at CVSS 10.0. Update to build 13.1.0.7034 now. #Veeam #VeeamONE #CVE202664633 #RCE #RemoteCodeExecution #Vulnerability #CVSS10 #PatchNow #CyberSecurity #InfoSec https://securityonline.info/veeam-one-cve-2026-64633-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 03, 2026
Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now. #AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE https://securityexpress.info/adobe-campaign-classic-cvss-10-patch/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
sekurak News @sekurakbot@mastodon.com.pl · Aug 03, 2026
Groźny atak na szyfrowany komunikator Gajim przez lukę w KDE Plasma Wiele współczesnych naruszeń bezpieczeństwa nie wynika z pojedynczego, spektakularnego błędu (np. klasy naruszenia ochrony pamięci). Prawdziwa esencja ofensywnego rzemiosła leży w łańcuchach podatności. Często dwie właściwości aplikacji, które pojedynczo wyglądają na niegroźne słabości lub błędy o niskim priorytecie, po połączeniu mogą dać zabójczy efekt. To historia o tym, jak jedna... #Aktualności #Teksty #Cve #Gajim #Kde #Rce #Sivert #Xmpp https://sekurak.pl/grozny-atak-na-szyfrowany-komunikator-gajim-przez-luke-w-kde-plasma/
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 03, 2026
A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now. #TPLink #TLWR940N #CVE202612935 #RCE #RouterSecurity #InfoSec https://securityonline.info/tp-link-wr940n-cve-2026-12935/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 31, 2026
Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9. #OpenAM #RCE #IAM #CVE202662379 https://securityonline.info/openam-cve-2026-62379/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 31, 2026
🤖 CVE-2026-63077 (critical): auth bypass in JetBrains TeamCity On-Premises via the agent polling protocol. Attacker with HTTPS access can bypass auth and execute arbitrary OS commands as the server process. All versions affected; fixed in 2025.11.7 and 2026.1.3. 🔗 https://www.bleepingcomputer.com/news/security/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw/ #CVE #RCE #CyberSec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 31, 2026
Adobe Campaign Classic flaw CVE-2026-48449 scores a perfect CVSS 10.0 and allows arbitrary code execution. Update to build 9398 now. #AdobeCampaignClassic #CVE202648449 #RCE #Adobe #InfoSec https://securityonline.info/adobe-campaign-classic-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 31, 2026
Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now. #IBMWebSphere #CVE202614512 #SSRF #RCE #Vulnerability #InfoSec https://securityonline.info/ibm-websphere-vulnerabilities-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 30, 2026
A public PoC now targets CVE-2026-66373, a Redis RCE double-free via RESTORE. See affected versions and upgrade to Redis 8.8.0 now. #Redis #RedisRCE #CVE202666373 #RCE #DoubleFree #PoC #RESTORE #Cybersecurity https://securityonline.info/redis-rce-cve-2026-66373/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 30, 2026
🚨 Critical VMware Advisory Broadcom has patched multiple critical VMware vulnerabilities affecting vCenter Server and ESXi, including an authentication bypass (CVSS 9.8), directory traversal leading to RCE (CVSS 9.8), and a VM escape via VMXNET3 (CVSS 9.3). Organizations should prioritize patching vCenter and ESXi infrastructure as soon as possible. Technical breakdown, affected versions, and mitigation: https://thecybersecguru.com/news/critical-vmware-vcenter-auth-bypass-rce-vm-escape-vulnerabilities/ #InfoSec #CyberSecurity #VMware #vCenter #ESXi #Virtualization #RCE #ThreatIntel #BlueTeam #SysAdmin #CVE
1
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 30, 2026
A Rails Active Storage flaw, CVE-2026-66066 (CVSS 9.5), enables arbitrary file read and remote code execution. Patch Rails and rotate secrets now. #RubyOnRails #ActiveStorage #CVE202666066 #RCE #libvips #InfoSec https://securityonline.info/rails-cve-2026-66066/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 30, 2026
Arista addresses CVE-2026-16812, a critical vulnerability in VeloCloud Orchestrator actively exploited to gain unauthenticated remote code execution. #Arista #VeloCloud #Cybersecurity #CVE202616812 #RCE https://meterpreter.org/arista-velocloud-orchestrator-cve-2026-16812/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0