Skip to main content
← All Articles

Tag

#RCE

190 articles

Advertisement

Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw
CRITICAL
Vulnerabilities

Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw

Google patches a CVSS 10.0 flaw in Gemini CLI tools that allowed unprivileged attackers to execute commands in CI/CD environments via malicious configurations.

Runtime Rebel Intel
3 min read·Apr 30, 2026
OpenEMR Flaws: Database Compromise, RCE, and Patient Data Theft Risks
CRITICAL
Vulnerabilities

OpenEMR Flaws: Database Compromise, RCE, and Patient Data Theft Risks

Analysis of 38 security flaws in OpenEMR, an EHR platform used by over 100,000 healthcare providers, enabling database compromise, RCE, and data theft.

Runtime Rebel Intel
4 min read·Apr 29, 2026
VU
CRITICAL
Vulnerabilities

GitHub Enterprise Server RCE via CVE-2024-6800 — Mitigation Guide

GitHub has patched a critical RCE vulnerability (CVE-2024-6800) in GHES that allows remote attackers to gain administrative access via SAML SSO bypass.

Runtime Rebel Intel
3 min read·Apr 29, 2026
CVE-2026-3854: GitHub RCE via Malicious Git Push Command
HIGH
Vulnerabilities

CVE-2026-3854: GitHub RCE via Malicious Git Push Command

A critical command injection vulnerability, CVE-2026-3854, allows authenticated users to achieve RCE on GitHub instances via a single git push operation.

Runtime Rebel Intel
3 min read·Apr 28, 2026
Hugging Face LeRobot RCE via CVE-2026-25874 — Mitigation Guide
CRITICAL
Vulnerabilities

Hugging Face LeRobot RCE via CVE-2026-25874 — Mitigation Guide

Technical analysis of CVE-2026-25874, a critical unpatched RCE vulnerability in Hugging Face LeRobot robotics platform with a CVSS score of 9.3.

Runtime Rebel Intel
3 min read·Apr 28, 2026
TrueConf Server RCE: PhantomCore Exploit Chain — Patch Now
CRITICAL
Threat Intel

TrueConf Server RCE: PhantomCore Exploit Chain — Patch Now

PhantomCore leverages a three-vulnerability exploit chain in TrueConf video conferencing software to target Russian networks via remote command execution.

Runtime Rebel Intel
4 min read·Apr 27, 2026
VU
CRITICAL
Vulnerabilities

Ivanti EPMM RCE via CVE-2025-22514: Technical Analysis and Patching

Critical security alert for Ivanti EPMM: CVE-2025-22514 and CVE-2025-22515 allow remote command injection and file uploads. Patch to version 12.1.0.1 immediately.

Runtime Rebel Intel
3 min read·Apr 24, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-52317: Critical File Upload Bug in Breeze Cache — Patch Now

Attackers are actively exploiting a critical unauthenticated file upload vulnerability (CVE-2024-52317) in the Breeze Cache WordPress plugin.

Runtime Rebel Intel
3 min read·Apr 24, 2026
VU
CRITICAL
Vulnerabilities

Critical RCE Threats: Confluence OGNL & Exchange Server Patching

Runtime Rebel analyzes critical RCE vulnerabilities affecting Atlassian Confluence and Microsoft Exchange Server, alongside a high-severity SQLi in WP Reset.

Runtime Rebel Intel
5 min read·Apr 23, 2026
MA
HIGH
Malware

CVE-2025-29635: Mirai Exploits EoL D-Link Routers

A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks. Urgent

Runtime Rebel Intel
4 min read·Apr 22, 2026
VU
HIGH
Vulnerabilities

Redis RCE via CONFIG Command Abuse: Detection and Mitigation

Learn how attackers exploit exposed Redis instances using the CONFIG command to achieve RCE and the specific steps required to secure your infrastructure.

Runtime Rebel Intel
4 min read·Apr 22, 2026
VU
CRITICAL
Vulnerabilities

Silex SD-330AC and AMC Manager RCE via CVE-2026-32956 — Patch Now

Silex Technology devices face critical RCE and DoS risks via 13 vulnerabilities. Critical infrastructure defenders must update to firmware Ver 1.50 immediately.

Runtime Rebel Intel
4 min read·Apr 22, 2026