ZCyberNews
中文

#remote-code-execution

18 articles

Technology, enterprise, and government sectors have been the primary targets in a wave of remote-code-execution attacks documented across 19 articles from April 14 to June 28, 2026. The coverage includes 12 critical and 7 high-severity vulnerabilities, with top CVEs including CVE-2026-8836 (CVSS 10), CVE-2026-41089 (CVSS 9.8), CVE-2026-41265 (CVSS 9.8), CVE-2026-45185 (CVSS 9.8), and CVE-2026-5760 (CVSS 9.8). These exploits have impacted organizations globally, with particular concentration in Europe and North America, affecting software development and telecommunications alongside the primary sectors.

CVE-2026-45408: Shell Injection in Dokku PaaS Lets AuthenticatedCRITICAL
Vulnerabilities

CVE-2026-45408: Shell Injection in Dokku PaaS Lets Authenticated

CVE-2026-45408 (CVSS 9.0) in Dokku <0.38.2 lets authenticated users inject shell commands via crafted app names in git push operations. No public exploit yet.

CVE-2026-45408
3 min read
Windows domain controller and Netlogon authentication traffic under active exploitation alert for CVE-2026-41089.CRITICAL
Vulnerabilities

CVE-2026-41089: Windows Netlogon RCE Exploited in Wild

CVE-2026-41089 is a critical Windows Netlogon RCE now reported as exploited in the wild, with Microsoft CNA scoring it CVSS 9.8.

CVE-2026-41089
4 min read
CVE-2026-8836: CVSS 10.0 Stack Overflow in lwIP SNMPv3 ParserCRITICAL
Vulnerabilities

CVE-2026-8836: CVSS 10.0 Stack Overflow in lwIP SNMPv3 Parser

CVE-2026-8836 is a CVSS 10.0 stack-based buffer overflow in lwIP up to 2.2.1's SNMPv3 USM handler. Remote unauthenticated attackers can trigger code execution via crafted...

CVE-2026-8836
3 min read
CVE-2024-57728: SimpleHelp Path Traversal Lets Admins UploadHIGH
Vulnerabilities

CVE-2024-57728: SimpleHelp Path Traversal Lets Admins Upload

CISA adds CVE-2024-57728 to Known Exploited Vulnerabilities: SimpleHelp path traversal via zip slip allows admin users to upload arbitrary files and execute code. Due May 8, 2026.

CVE-2024-57728
3 min read
Chrome 148.0.7778.168 Patches Integer Overflows, Sandbox Escape RiskHIGH
Vulnerabilities

Chrome 148.0.7778.168 Patches Integer Overflows, Sandbox Escape Risk

CVE-2026-8573 (CVSS 8.3) and CVE-2026-8577 (CVSS 8.8) in Chrome 148 on Windows allow sandbox escape and RCE via crafted video or HTML pages. Update now.

CVE-2026-8577CVE-2026-8573
4 min read
F5 Patches 51 Flaws: NGINX DoS, BIG-IP RCE Among Critical FixesCRITICAL
Vulnerabilities

F5 Patches 51 Flaws: NGINX DoS, BIG-IP RCE Among Critical Fixes

F5 fixed 19 high-severity and 32 medium-severity bugs across BIG-IP, BIG-IQ, and NGINX. The most severe, CVE-2026-42945 (CVSS 9.2), enables heap overflow DoS in NGINX rewrite...

CVE-2026-42945CVE-2026-41225CVE-2026-41957+2
4 min read
Exim BDAT Use-After-Free Flaw CVE-2026-45185 Enables Remote CodeCRITICAL
Vulnerabilities

Exim BDAT Use-After-Free Flaw CVE-2026-45185 Enables Remote Code

CVE-2026-45185 (Dead.Letter) is a use-after-free in Exim's BDAT handling affecting GnuTLS builds — CVSS 9.8, remote code execution risk. Patches released.

CVE-2026-45185
3 min read
Custom css-js-php WordPress Plugin SQLi Leads to RCE (CVE-2026-6433)CRITICAL
Vulnerabilities

Custom css-js-php WordPress Plugin SQLi Leads to RCE (CVE-2026-6433)

CVE-2026-6433: Unauthenticated SQL injection in Custom css-js-php plugin ≤2.0.7 lets attackers execute arbitrary PHP via eval(). No patch available.

CVE-2026-6433
3 min read
Aero CMS 0.0.1 PHP Code Injection Flaw Lets Authenticated AttackersHIGH
Vulnerabilities

Aero CMS 0.0.1 PHP Code Injection Flaw Lets Authenticated Attackers

CVE-2022-50944 (CVSS 8.8): Authenticated attackers can upload malicious PHP files via the image parameter in Aero CMS 0.0.1, achieving remote code execution on the server.

CVE-2022-50944
3 min read
CVE-2025-69690: Netgate pfSense CE Module Installer RCE via BackupCRITICAL
Vulnerabilities

CVE-2025-69690: Netgate pfSense CE Module Installer RCE via Backup

CVE-2025-69690 (CVSS 9.1) lets authenticated admins achieve remote code execution on pfSense CE 2.7.2 by crafting a backup file with a serialized PHP object.

CVE-2025-69690
3 min read
DrayTek Vigor 2960 OS Command Injection Flaw Allows UnauthenticatedHIGH
Vulnerabilities

DrayTek Vigor 2960 OS Command Injection Flaw Allows Unauthenticated

CVE-2022-50994 (CVSS 8.1): Unauthenticated attackers can inject shell commands via the formpassword parameter in the CGI login handler of DrayTek Vigor 2960 routers running...

CVE-2022-50994
3 min read
Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in Limited AttacksHIGH
Vulnerabilities

Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in Limited Attacks

Ivanti warns CVE-2026-6973, a high-severity RCE in EPMM 12.8.0.0 and earlier, is under limited zero-day exploitation. Patches available; 850+ EPMM instances exposed online.

CVE-2026-6973CVE-2026-5786CVE-2026-5787+4
4 min read
Palo Alto PAN-OS CVE-2026-0300 Attacked via Captive PortalCRITICAL
Vulnerabilities

Palo Alto PAN-OS CVE-2026-0300 Attacked via Captive Portal

CVE-2026-0300 is a critical PAN-OS buffer overflow in the User-ID Authentication Portal. Fixed builds are upcoming, so disable or restrict the portal immediately.

CVE-2026-0300
4 min read
Apache Patches Critical HTTP/2 Double-Free Flaw CVE-2026-23918CRITICAL
Vulnerabilities

Apache Patches Critical HTTP/2 Double-Free Flaw CVE-2026-23918

Apache HTTP Server CVE-2026-23918 (CVSS 8.8) enables DoS and potential RCE via double-free in HTTP/2 handling. Affects all mod_http2 users. Patch now.

CVE-2026-23918
3 min read
Flowise RCE Vulnerability CVE-2026-41265 Carries CVSS 9.8CRITICAL
Vulnerabilities

Flowise RCE Vulnerability CVE-2026-41265 Carries CVSS 9.8

CVE-2026-41265 in Flowise Airtable_Agent allows unauthenticated remote code execution with CVSS 9.8. ZDI advisory details code injection in default installations.

CVE-2026-41265
3 min read
CVE-2026-25874: Unpatched RCE Flaw in Hugging Face LeRobotCRITICAL
Vulnerabilities

CVE-2026-25874: Unpatched RCE Flaw in Hugging Face LeRobot

CVE-2026-25874 (CVSS 9.3) in Hugging Face LeRobot enables unauthenticated RCE via unsafe deserialization.

CVE-2026-25874
2 min read
GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git PushHIGH
Vulnerabilities

GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

CVE-2026-3854 (CVSS 8.7) lets authenticated users with push access achieve remote code execution on GitHub.com and GitHub Enterprise Server via a crafted git push command.

CVE-2026-3854
4 min read
SGLang Vulnerability CVE-2026-5760 Enables Remote Code Execution via GGUF FilesCRITICAL
Vulnerabilities

SGLang Vulnerability CVE-2026-5760 Enables Remote Code Execution via GGUF Files

CVE-2026-5760, a critical 9.8 CVSS flaw in the SGLang inference engine, allows attackers to execute arbitrary code by uploading malicious GGUF model files, compromising AI/ML serving deployments.

CVE-2026-5760
2 min read

Stay Updated

Get the latest cybersecurity news delivered to your inbox.