#remotecodeexecution

7 posts · Last used 3d

Back to Timeline
OffSequence @offseq@infosec.exchange · 3d ago
CVE-2026-16723: CRITICAL RCE in Alibaba Fastjson 1.2.68. Exploitable under default config — no patch yet. Avoid 1.2.68 & monitor vendor updates for mitigation. CVSS 9.0. https://radar.offseq.com/threat/cve-2026-16723-cwe-20-improper-input-validation-in-alibaba-fastjson-939ed165aac7ce81 #OffSeq #infosec #CVE202616723 #remotecodeexecution
0
0
0
Security Crawler Carl @security_crawler_carl@infosec.exchange · 5d ago
Replying to @security_crawler_carl@infosec.exchange
Searchlight Cyber published exploitation details; the wolves read it too. ServiceNow has acknowledged the activity. Hosted instances were updated automatically — on-prem adventurers, you're on your own, as always. Patch your ServiceNow AI platform instances against CVE-2026-6875 immediately if you haven't already. Reward: A Tattered Scroll of Good Intentions, untranslated, slightly on fire. #ServiceNow #CVE202668875 #RemoteCodeExecution #ZeroDay #CyberSecurity #PatchedOrPerish (2/2)
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 18, 2026
🚨 CRITICAL: WordPress Core "wp2shell" RCE A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations. ⚠️ No plugins. ⚠️ No themes. ⚠️ No authentication required. Tracked as: 🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE) 🔴 CVE-2026-60137 (Facilitated SQL Injection) Affected versions • WordPress 6.9.0–6.9.4 • WordPress 7.0.0–7.0.1 ✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations. 🔗 Full technical analysis: https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/ #WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
34
1
55
thecybersecguru @thecybersecguru@infosec.exchange · Jul 17, 2026
🚨 Millions of 7-Zip users should update immediately. A newly disclosed vulnerability, CVE-2026-14266, could allow Remote Code Execution (RCE) when a victim opens a specially crafted XZ archive. 🔍 Key details: • Heap-based buffer overflow • User interaction required • Exploitable through phishing emails, malicious downloads, and weaponized archive files • Fixed in 7-Zip 26.02 If you use 7-Zip, update now and avoid opening compressed files from untrusted sources. Read the full technical breakdown 👇 https://thecybersecguru.com/news/7-zip-vulnerability-cve-2026-14266/ #CyberSecurity #InfoSec #CyberThreat #Vulnerability #CVE #CVE202614266 #7Zip #RemoteCodeExecution #RCE #ThreatIntel #CyberAttack #Malware #Phishing #SecurityUpdate #PatchNow #WindowsSecurity #BlueTeam #SOC #ThreatHunting #CyberDefense
0
0
2
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 14, 2026
CVE-2026-6875 (CVSS 9.5) is a ServiceNow sandbox escape in the AI Platform that allows unauthenticated remote code execution. Patch now. #ServiceNow #CVE20266875 #RemoteCodeExecution #SandboxEscape #CyberSecurity https://securityonline.info/servicenow-sandbox-escape-cve-2026-6875/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
OffSequence @offseq@infosec.exchange · Jul 12, 2026
tinyparrot npm v0.4.1 flagged as CRITICAL: Malicious postinstall script executes attacker-supplied shell commands via obfuscated HTTPS POST. Remove & avoid use! No patch available. https://radar.offseq.com/threat/mal-2026-10190-malicious-code-in-tinyparrot-npm-8e0728bab742b27e #OffSeq #npm #remotecodeexecution #malware
0
0
0

You've seen all posts