vulnerability Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code Two unpatched vulnerabilities in Kaltura's HTML5 video player library (mwEmbed) allow remote attackers to read arbitrary files and execute code on a server, without requiring authentication. These flaws stem from unsafe deserialization and can be exploited even if the player is hosted on Kaltura's shared CDN infrastruc… The Hacker News · 4d ago High CVE-2026-19913CVE-2026-19912unpatcheddeserializationremote code execution
vulnerability Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution Microsoft has patched a critical vulnerability in Entra ID, which has been exploited in the wild. The flaw allows remote code execution, and while Microsoft has addressed it, it highlights the ongoing need for vigilance… The Hacker News · Aug 21, 2026 Critical CVE-2026-69836CVE-2026-68820entria idazure adremote code execution
vulnerability ISC Stormcast For Monday, August 17th, 2026 https://isc.sans.edu/podcastdetail/10054, (Mon, Aug 17th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Aug 17, 2026 Critical strutsvulnerabilitydeserialization
vulnerability AVEVA Enterprise SCADA A critical vulnerability (CVE-2025-7639) has been identified in AVEVA Enterprise SCADA, allowing an authenticated attacker with specific privileges to tamper with serialized data and potentially execute code. This vulner… CISA Advisories · Aug 13, 2026 High CVE-2025-7639cve-2025-7639deserializationcode execution
vulnerability Multiples vulnérabilités dans Progress Telerik (07 août 2026) A security advisory from CERT-FR details multiple vulnerabilities within Progress Telerik's ASP.NET AJAX product. These vulnerabilities include remote code execution, denial of service, and data breaches, allowing attack… CERT-FR · Aug 7, 2026 High CVE-2026-14932CVE-2026-13181CVE-2026-13182vulnerabilitydeserializationssrf
vulnerability CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild A critical vulnerability (CVE-2026-63077) in JetBrains TeamCity, allowing unauthenticated remote code execution, is currently being actively exploited in the wild. CISA has issued a Binding Operational Directive requirin… The Hacker News · Aug 6, 2026 Critical CVE-2026-63077cveremote code executiondeserialization
vulnerability Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability JetBrains TeamCity, a popular CI/CD platform, is experiencing a critical vulnerability (CVE-2026-63077) that allows unauthenticated attackers to execute commands on the server. CISA has added the vulnerability to its lis… SecurityWeek · Aug 6, 2026 Critical CVE-2026-63077vulnerabilityrcedeserialization
vulnerability Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A critical SharePoint vulnerability (CVE-2026-50522) is currently being actively exploited, allowing attackers to execute code remotely and steal machine keys. Microsoft released a patch last month, but attackers are lev… The Hacker News · Jul 21, 2026 Critical CVE-2026-50522CVE-2026-56164CVE-2026-58644sharepointvulnerabilityrce
vulnerability ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Jul 21, 2026 Critical apachestrutsvulnerability
vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code e… The Hacker News · Jul 17, 2026 Critical CVE-2026-58644sharepointvulnerabilitydeserialization
vulnerability ISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Jul 14, 2026 Critical strutsdeserializationremote code execution
vulnerability ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Jul 13, 2026 High activemqvulnerabilitydeserialization
vulnerability Delta Electronics DTM Soft A vulnerability has been identified in Delta Electronics’ DTM Soft software, allowing for potential arbitrary code execution via deserialization of untrusted data. This poses a risk to critical manufacturing operations g… CISA Advisories · Jun 25, 2026 High CVE-2026-12578WOdeserializationcwe-502critical manufacturing
threat-intel LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution A critical vulnerability chain in LangGraph, an open-source AI agent framework, has been disclosed, allowing for remote code execution via SQL injection and unsafe deserialization. The flaws, affecting versions prior to… The Hacker News · Jun 12, 2026 Critical CVE-2025-67644CVE-2026-28277CVE-2026-27022USsql injectionremote code executionai agent
vulnerability CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2026-45247, affecting the Mirasvit Cache Warmer Magento extension to its KEV catalog. This flaw allows for remote c… The Hacker News · Jun 4, 2026 Critical CVE-2026-45247USUKFRphpobjectdeserialization
threat-intel KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS was exploited to deploy the Godzilla web shell and establish Cobalt Strike Beacon access. The flaw, stemming from hard-coded ASP.NET machine keys, allowe… The Hacker News · May 26, 2026 Critical CVE-2026-5426JPzero-daydeserializationasp.net