vulnerability Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth A security researcher discovered two separate root remote code execution (RCE) vulnerabilities in Unitree's G1 and G1 EDU humanoid robots. One vulnerability, accessible via Bluetooth, allows attackers to gain root access without pairing, while the other involves a network-adjacent path. Unitree has addressed the cloud… The Hacker News · 2d ago High CVE-2026-76639CVE-2026-76640roboticsrcebluetooth
vulnerability Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE Next.js has released security patches to address two critical vulnerabilities. The first, a Windows path traversal flaw, allows unauthenticated remote code execution when processing specially crafted AVIF images. The sec… The Hacker News · 3d ago High CVE-2026-75604avifrcelibheif
vulnerability Zoneminder A critical Remote Code Execution (RCE) vulnerability exists in Zoneminder versions 1.37.48 and 1.38.3, allowing authenticated users to execute arbitrary operating system commands. The vulnerability stems from an Improper… CISA Advisories · 5d ago Critical CVE-2026-76060vulnerabilityrceos command injection
vulnerability Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data A critical, actively exploited vulnerability in Oracle WebLogic Server allows unauthenticated attackers to access sensitive data. Despite patches being released in January, threat actors are still leveraging this flaw, p… The Hacker News · 5d ago Critical CVE-2026-21962CVE-2020-14882CVE-2020-2551rceweblogiccve-2026-21962
vulnerability 91 Vulnerabilities Patched in Spring Application Framework Broadcom released a massive update addressing 91 vulnerabilities within the Spring application framework. Many of these flaws, including a critical Remote Code Execution (RCE) vulnerability, could be exploited for variou… SecurityWeek · 6d ago High CVE-2026-59270CVE-2026-59285CVE-2026-59318springvulnerabilityrce
vulnerability Critical Isolated-vm Vulnerability Leads to RCE on Host A critical type confusion vulnerability in the isolated-vm Node.js library is being exploited to achieve remote code execution (RCE) on the host system. The vulnerability stems from a flawed data transfer mechanism withi… SecurityWeek · Aug 21, 2026 Critical rcetype-confusionnode.js
threat-intel ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More This week’s ThreatsDay bulletin highlights a diverse range of security threats, including a Remote Code Execution vulnerability in Gogs, a sophisticated Mabna Institute cyber espionage campaign targeting universities and… The Hacker News · Aug 20, 2026 Critical CVE-2026-52813CVE-2026-52810CVE-2026-43774IRUSrcecyber espionagegit hooks
vulnerability Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Cisco has released patches to address 15 critical and high-severity vulnerabilities across its products, including Crosswork and BroadWorks. These flaws could lead to remote code execution, authentication bypasses, and d… SecurityWeek · Aug 20, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358vulnerabilitypatchsecurity
vulnerability CISA gives feds 3 days to fix actively exploited Ray RCE bug The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency advisory to federal agencies, demanding they address a rapidly exploited Remote Code Execution (RCE) vulnerability in Ray Ray, a widely… The Register · Aug 18, 2026 High CVE-2025-62593ray rayrcevulnerability
vulnerability 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw A critical vulnerability in the Forminator Forms plugin for WordPress is exposing over 300,000 websites to potential remote code execution attacks. The flaw stems from inadequate file type validation, allowing attackers… SecurityWeek · Aug 18, 2026 Critical CVE-2026-15748wordpressvulnerabilityrce
threat-intel Video Call Exploit Chains Two Flaws in Unisoc Modems Researchers at SSD Secure Disclosure have discovered a new exploit chain targeting Unisoc T612 modems, allowing attackers to gain kernel-level access on Android devices. The vulnerability combines a previously disclosed… Dark Reading · Aug 17, 2026 High CHcellularmodemandroid
vulnerability Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access Security researchers at SSD Secure Disclosure have discovered a two-stage exploit chain that allows attackers to gain full Android kernel access on devices using Unisoc modem firmware. The vulnerability stems from a shar… The Hacker News · Aug 17, 2026 High CVE-2025-31718CVE-2022-20210CHandroidmodemkernel
vulnerability Siemens Siveillance Video Siemens has released security advisories addressing a Remote Code Execution (RCE) vulnerability in its Siveillance Video Management Servers. Versions V2023 R3 through V2025 are affected, allowing users with edit permissi… CISA Advisories · Aug 13, 2026 High CVE-2026-3014rcecve-2026-3014industrial control systems
vulnerability Belgium's eID Authentication Opens Citizen Accounts to RCE A critical vulnerability was discovered in Belgium's eID authentication system due to a severely flawed browser extension, "Connective." This vulnerability allowed attackers to steal Belgian citizens' identities, payment… Dark Reading · Aug 13, 2026 Critical BEbrowser extensionsrceidentity theft
vulnerability Vulnérabilité dans WordPress (13 août 2026) A remote code execution vulnerability has been identified in older versions of WordPress, allowing attackers to execute arbitrary code. This affects WordPress versions prior to 7.0.4, and requires immediate patching to p… CERT-FR · Aug 13, 2026 Critical CVE-2026-65640wordpressrcevulnerability
vulnerability SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform SonicWall has released patches to address eight critical vulnerabilities in its discontinued GMS platform and Email Security products. These flaws, including remote code execution and command injection, could allow attac… SecurityWeek · Aug 12, 2026 Critical CVE-2026-66147CVE-2026-66145CVE-2026-66149vulnerabilitypatchrce
vulnerability Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack Microsoft released a security update containing 398 new vulnerabilities, with one zero-day flaw actively being exploited by Check Point Research's Lazarus group as part of Operation Dream Job. This zero-day (CVE-2026-688… The Hacker News · Aug 11, 2026 High CVE-2026-68820CVE-2026-62878CVE-2026-62893zero-dayrceexploit
vulnerability Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE Researchers at Rapid7 discovered a chain of vulnerabilities in Microsoft SharePoint, allowing unauthenticated attackers to impersonate users, including administrators, through a complex AI-assisted process. The initial b… The Hacker News · Aug 11, 2026 High CVE-2026-55040CVE-2026-63520jwtsharepointrce
vulnerability SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities SAP released 28 security notes on August 2026 Patch Day to address a range of critical vulnerabilities across its products, including SAP Commerce Cloud, NetWeaver Application Server ABAP, and ABAP Platform. These flaws… SecurityWeek · Aug 11, 2026 Critical CVE-2026-58231CVE-2026-44772CVE-2026-44758vulnerabilitypatchcode injection
vulnerability ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j 2, potentially allowing attackers to execute arbitrary code through a malicious log message. This vulnerability, alongside r… SANS Internet Storm Center · Aug 11, 2026 Critical log4jrcevulnerability