vulnerability ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code remotely. This exploit could lead to widespread data breaches and… SANS Internet Storm Center · Aug 10, 2026 Critical log4jrcevulnerability
vulnerability Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability JetBrains TeamCity, a popular CI/CD platform, is experiencing a critical vulnerability (CVE-2026-63077) that allows unauthenticated attackers to execute commands on the server. CISA has added the vulnerability to its lis… SecurityWeek · Aug 6, 2026 Critical CVE-2026-63077vulnerabilityrcedeserialization
vulnerability ISC Stormcast For Tuesday, August 4th, 2026 https://isc.sans.edu/podcastdetail/10036, (Tue, Aug 4th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Aug 4, 2026 Critical activemqrcevulnerability
vulnerability ISC Stormcast For Monday, August 3rd, 2026 https://isc.sans.edu/podcastdetail/10034, (Mon, Aug 3rd) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability, along… SANS Internet Storm Center · Aug 3, 2026 Critical log4jrcejndi
vulnerability Ruby on Rails Patches Critical Vulnerability A critical vulnerability in Ruby on Rails, specifically related to image processing using the libvips library, has been patched. Attackers could potentially read arbitrary files and expose secrets, leading to remote code… SecurityWeek · Aug 1, 2026 Critical CVE-2026-66066rubyrailslibvips
vulnerability Critical Code Execution Vulnerability Patched in TeamCity JetBrains has released patches to address a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises, allowing unauthenticated attackers to execute code on the server. This flaw can lead to data breaches, configur… SecurityWeek · Jul 31, 2026 Critical CVE-2026-63077rcevulnerabilitypatch
vulnerability Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads A critical vulnerability (CVE-2026-66066, CVSS 9.5) in Ruby on Rails' Active Storage component, using libvips for image processing, allows unauthenticated attackers to read arbitrary files from application servers. This… The Hacker News · Jul 29, 2026 Critical CVE-2026-66066rubyrailslibvips
vulnerability New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands A critical remote code execution (RCE) vulnerability in Gitea allows a user with repository write access to plant a Git hook and execute shell commands as the Gitea service account. The vulnerability, tracked as CVE-2026… The Hacker News · Jul 29, 2026 High CVE-2026-60004rcegitvulnerability
vulnerability Unpatched Fastjson Vulnerability Exploited in Attacks A critical remote code execution (RCE) vulnerability in Fastjson, a popular Java JSON processing library, has been actively exploited by threat actors. The vulnerability, tracked as CVE-2026-16723, allows attackers to ex… SecurityWeek · Jul 28, 2026 Critical CVE-2026-16723USSGCArcejsonspring boot
vulnerability ISC Stormcast For Tuesday, July 28th, 2026 https://isc.sans.edu/podcastdetail/10026, (Tue, Jul 28th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise a… SANS Internet Storm Center · Jul 28, 2026 Critical rceapacheactivemq
vulnerability Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw A public exploit for a remote code execution vulnerability in vBulletin has been released, targeting versions 6.2.1 and earlier, and 6.1.6 and earlier. The vulnerability allows unauthenticated code execution, but the exp… The Hacker News · Jul 27, 2026 High CVE-2026-61511CVE-2025-48827CVE-2025-48828rcevbulletinremote-code-execution
vulnerability PTC Windchill Vulnerability Exploited in Ransomware Campaign A critical remote code execution vulnerability in PTC's Windchill and FlexPLM PLM platforms has been exploited by a Cl0p ransomware affiliate in a targeted campaign. The attackers are leveraging a chain of vulnerabilitie… SecurityWeek · Jul 27, 2026 Critical CVE-2026-12569rcevulnerabilityransomware
vulnerability Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available A critical Remote Code Execution (RCE) vulnerability in Fastjson 1.x, a Java JSON library by Alibaba, is being actively exploited. Attackers are leveraging a type-resolution path to execute arbitrary code in Spring Boot… The Hacker News · Jul 25, 2026 High CVE-2026-16723USSGCArcejsonjava
vulnerability Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A researcher, depthfirst, has published a proof-of-concept exploit targeting GitLab 18.11.3 and earlier, allowing authenticated users to execute arbitrary commands as the ‘git’ user. The vulnerability stems from flaws wi… The Hacker News · Jul 25, 2026 High rcejupyterjson
threat-intel Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Researchers have discovered two remote code execution (RCE) vulnerabilities in Redis, identified through AI-assisted research. The vulnerabilities, dubbed ‘Kimi K3 agents,’ allowed attackers to exploit Redis versions 6.2… The Hacker News · Jul 24, 2026 High CVE-2026-25589CVE-2026-25243rcerediszero-day
vulnerability Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A critical SharePoint vulnerability (CVE-2026-50522) is currently being actively exploited, allowing attackers to execute code remotely and steal machine keys. Microsoft released a patch last month, but attackers are lev… The Hacker News · Jul 21, 2026 Critical CVE-2026-50522CVE-2026-56164CVE-2026-58644sharepointvulnerabilityrce
vulnerability New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code A critical vulnerability (RCE) exists in WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1, allowing unauthenticated attackers to execute code via a batch request. While no CVE has been assigned yet, WordPr… The Hacker News · Jul 17, 2026 Critical wordpressrcevulnerability
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
vulnerability Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft released its July 2026 security update, containing 622 vulnerabilities, with 57 classified as critical. Several of these, including those affecting Active Directory Federation Services, SharePoint Server, and v… Cisco Talos · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50370vulnerabilityrceeop
vulnerability Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th) Microsoft's July Patch Tuesday release includes a massive 622 vulnerabilities, with a significant number already exploited. Many of these vulnerabilities affect products like Edge and SharePoint, and a notable one – a B… SANS Internet Storm Center · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayvulnerabilitymicrosoft