threat-intel CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws The CISA has issued an urgent warning to federal agencies and all organizations regarding several actively exploited vulnerabilities in Adobe ColdFusion, Langflow, Joomla extensions, and CitrixBleed. These flaws, includi… SecurityWeek · Jul 8, 2026 Critical CVE-2026-48282CVE-2026-55255CVE-2026-33017vulnerabilityexploitationpatch
threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror
vulnerability Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts A critical remote code execution (RCE) vulnerability, CVE-2026-8037, in Progress Kemp LoadMaster is currently being actively exploited. The flaw allows unauthenticated attackers to execute arbitrary commands on vulnerabl… The Hacker News · Jul 1, 2026 Critical CVE-2026-8037CVE-2024-1212rcecommand injectionload balancer
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai
vulnerability CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue CISA has added a critical remote code execution (RCE) vulnerability, CVE-2026-12569, affecting PTC Windchill PDMlink and FlexPLM to its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability, stemming from imp… The Hacker News · Jun 26, 2026 Critical CVE-2026-12569rcewindchillweb shell
supply-chain Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE A vulnerability in the Google Cloud Vertex AI Python SDK (versions 1.139.0 - 1.140.0) allowed attackers to hijack model uploads and execute remote code execution (RCE) within a target's Vertex AI serving infrastructure.… Palo Alto Unit 42 · Jun 16, 2026 High sdkrcebucket squatting
vulnerability Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on pa… The Hacker News · Jun 10, 2026 Critical CVE-2025-10263CVE-2026-8863CVE-2026-45657USzero-dayrcebitlocker
vulnerability Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS Six vulnerabilities, dubbed Proto6, have been identified in protobuf.js, a JavaScript implementation of Protocol Buffers. These flaws could lead to remote code execution (RCE) and denial-of-service (DoS) attacks, primari… The Hacker News · Jun 10, 2026 High CVE-2026-44289CVE-2026-44290CVE-2026-44291node.jsprotobufrce
vulnerability Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Microsoft released its June 2026 security patch update, addressing 206 vulnerabilities across its product suite. A significant portion, 32 critical vulnerabilities, focus on remote code execution (RCE) issues within prod… Cisco Talos · Jun 9, 2026 High CVE-2026-42985CVE-2026-47291CVE-2026-44803remote code executionbuffer overflowinteger overflow
vulnerability Critical UniFi OS bug lets hackers gain root without authentication A critical vulnerability in UniFi OS Server versions 5.0.6 and earlier allows attackers to gain root access without authentication by chaining three previously identified flaws. This vulnerability, detailed by Bishop Fox… BleepingComputer · Jun 8, 2026 Critical CVE-2026-34908CVE-2026-34909CVE-2026-34910remote code executionroot accessauthentication bypass
vulnerability Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479) A 2-year-old remote code execution (RCE) vulnerability, CVE-2026-23479, was discovered in Redis 7.2.0 by an autonomous AI security tool, Team Xint Code. The flaw, stemming from a use-after-free issue in the `unblockClien… The Hacker News · Jun 3, 2026 High CVE-2026-23479UKuse-after-freerceredis
threat-intel Critical Windows Netlogon RCE flaw now exploited in attacks A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity… BleepingComputer · Jun 1, 2026 Critical CVE-2026-41089CVE-2026-45585CVE-2026-33825BErcenetlogonwindows
vulnerability Exploit Code Published for Critical Flowise RCE Vulnerability A critical remote code execution (RCE) vulnerability, CVE-2026-40933, has been discovered in Flowise, a popular open-source AI agent platform. The flaw, stemming from a command injection issue within the Anthropic MCP pr… SecurityWeek · May 30, 2026 Critical CVE-2026-40933rcecommand injectionai
threat-intel In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks This week’s cybersecurity news highlights a range of incidents, including a data breach affecting Trump Mobile customers, ongoing Russian government intrusion into US Treasury systems, and vulnerabilities in popular soft… SecurityWeek · May 29, 2026 High UNCHdata breachsupply chainphishing
vulnerability Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code A critical remote code execution (RCE) vulnerability has been identified in Gogs, a popular self-hosted Git service, allowing authenticated users to execute arbitrary code. The flaw, detailed by Jonah Burgess, stems from… The Hacker News · May 28, 2026 Critical rcegitrebase
vulnerability New Gogs zero-day flaw lets hackers get remote code execution A zero-day vulnerability (CVE-2024-39933) has been identified in Gogs, a self-hosted Git service, allowing authenticated attackers to execute remote code execution (RCE). The flaw, initially discovered by Jonah Burgess,… BleepingComputer · May 28, 2026 High CVE-2024-39933CVE-2024-39932CVE-2026-26194USCNJPzero-dayrcegit
vulnerability Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Microsoft released its May 2026 Patch Tuesday update, addressing 137 vulnerabilities across its product suite. The update includes a significant number of critical vulnerabilities, primarily remote code execution (RCE) f… Cisco Talos · May 12, 2026 High CVE-2026-32161CVE-2026-33109CVE-2026-33844rcebuffer overflowuse after free
vulnerability CVE-2025-68670: discovering an RCE vulnerability in xrdp This report details a remote code execution (RCE) vulnerability, CVE-2025-68670, discovered in the Kaspersky xrdp server. The vulnerability exists within the xrdp_wm_parse_domain_information function due to a buffer over… Securelist · May 8, 2026 Critical CVE-2025-68670buffer_overflowrcexrdp
threat-intel Exploits and vulnerabilities in Q1 2026 This Securelist report analyzes vulnerability trends and exploitation activity during Q1 2026, focusing on the expansion of exploit kits targeting Microsoft Office, Windows, and Linux operating systems. The report highli… Securelist · May 7, 2026 High CVE-2018-0802CVE-2017-11882CVE-2017-0199USvulnerabilityexploitationrce