<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #RCE</title><description>Cybersecurity articles tagged #RCE on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Critical Type Confusion in isolated-vm Leads to Host RCE</title><link>https://runtimerebel.com/blog/critical-type-confusion-in-isolated-vm-leads-to-host-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-type-confusion-in-isolated-vm-leads-to-host-rce</guid><description>A critical type confusion vulnerability in the Node.js isolated-vm library allows remote code execution on the host system via V8 Isolates.</description><pubDate>Sun, 23 Aug 2026 08:20:33 GMT</pubDate><category>Isolated Vm</category><category>Node Js</category><category>RCE</category><category>Type Confusion</category><category>V8</category></item><item><title>CVE-2025-62593: Ray-Project Ray RCE Exploited In Wild</title><link>https://runtimerebel.com/blog/cve-2025-62593-ray-project-ray-rce-exploited-in-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-62593-ray-project-ray-rce-exploited-in-wild</guid><description>CISA confirms active exploitation of CVE-2025-62593, a critical code injection vulnerability in Ray-Project Ray allowing remote code execution. Developers are targeted.</description><pubDate>Mon, 17 Aug 2026 16:20:50 GMT</pubDate><category>Remote Code Execution</category><category>RCE</category><category>CISA KEV</category><category>CVE-2025-62593</category><category>Ray Project</category></item><item><title>CVE-2026-58231: SAP Commerce Cloud Unauthenticated RCE Flaw</title><link>https://runtimerebel.com/blog/cve-2026-58231-sap-commerce-cloud-unauthenticated-rce-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-58231-sap-commerce-cloud-unauthenticated-rce-flaw</guid><description>SAP has patched a critical flaw, CVE-2026-58231, in Commerce Cloud Data Hub Adapter allowing unauthenticated arbitrary code execution. Immediate action is urged.</description><pubDate>Sat, 15 Aug 2026 00:40:41 GMT</pubDate><category>RCE</category><category>SSRF</category><category>CVE-2026-58231</category><category>SAP Commerce Cloud</category><category>Unauthenticated</category></item><item><title>RCE Vulnerabilities in Copeland XWEB Pro &amp; Danfoss AK-SM 800A Controllers</title><link>https://runtimerebel.com/blog/rce-vulnerabilities-in-copeland-xweb-pro-danfoss-ak-sm-800a-controllers</link><guid isPermaLink="true">https://runtimerebel.com/blog/rce-vulnerabilities-in-copeland-xweb-pro-danfoss-ak-sm-800a-controllers</guid><description>Claroty Team82 discovered multiple RCE vulnerabilities in Copeland XWEB Pro and Danfoss AK-SM 800A commercial refrigeration controllers.</description><pubDate>Fri, 14 Aug 2026 16:42:26 GMT</pubDate><category>RCE</category><category>Industrial Control Systems</category><category>OT Security</category><category>Copeland XWEB Pro</category><category>Danfoss AK SM 800A</category></item><item><title>CVE-2026-59310: vCenter RCE Exploited for Reverse SSH Access</title><link>https://runtimerebel.com/blog/cve-2026-59310-vcenter-rce-exploited-for-reverse-ssh-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-59310-vcenter-rce-exploited-for-reverse-ssh-access</guid><description>A critical RCE flaw, CVE-2026-59310, in VMware vCenter Syslog Server is under active exploitation, enabling reverse SSH for persistence.</description><pubDate>Thu, 13 Aug 2026 16:45:32 GMT</pubDate><category>RCE</category><category>CVE-2026-59310</category><category>VMware</category><category>vCenter</category><category>Reverse SSH</category></item><item><title>Belgium eID Authentication RCE via Browser Extension Flaws</title><link>https://runtimerebel.com/blog/belgium-eid-authentication-rce-via-browser-extension-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/belgium-eid-authentication-rce-via-browser-extension-flaws</guid><description>Severe vulnerabilities in a key browser extension fully compromised Belgium&apos;s eID authentication trust framework, exposing citizen accounts to remote code execution.</description><pubDate>Thu, 13 Aug 2026 09:04:14 GMT</pubDate><category>Authentication</category><category>RCE</category><category>Browser Extension</category><category>Vulnerability</category><category>eID</category></item><item><title>Microsoft &amp; Apple Patch Critical RCEs and Auth Bypass Flaws</title><link>https://runtimerebel.com/blog/microsoft-apple-patch-critical-rces-and-auth-bypass-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-apple-patch-critical-rces-and-auth-bypass-flaws</guid><description>Microsoft released patches for critical-severity RCE and EoP flaws across Active Directory, Azure, and Teams. Apple fixed a Screen Sharing authentication bypass.</description><pubDate>Sun, 09 Aug 2026 08:32:17 GMT</pubDate><category>Microsoft</category><category>Apple</category><category>Vulnerabilities</category><category>RCE</category><category>Authentication Bypass</category></item><item><title>Critical Backdoors &amp; Supply Chain Attacks: Zbtlink Routers &amp; QuickFox VPN Compromised</title><link>https://runtimerebel.com/blog/critical-backdoors-supply-chain-attacks-zbtlink-routers-quickfox-vpn-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-backdoors-supply-chain-attacks-zbtlink-routers-quickfox-vpn-compromised</guid><description>Urgent warning: Zbtlink routers ship with unauthenticated root backdoors, while QuickFox VPN delivers FDMTP implant via supply chain compromise.</description><pubDate>Fri, 07 Aug 2026 16:43:45 GMT</pubDate><category>Supply Chain Attack</category><category>Backdoor</category><category>RCE</category><category>Zbtlink</category><category>QuickFox VPN</category></item><item><title>CVE-2026-64638: WordPress Pre-Auth XSS Leads to PHP RCE</title><link>https://runtimerebel.com/blog/cve-2026-64638-wordpress-pre-auth-xss-leads-to-php-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-64638-wordpress-pre-auth-xss-leads-to-php-rce</guid><description>A pre-authentication reflected XSS (CVE-2026-64638) in WordPress can be chained for PHP code execution. Patch immediately.</description><pubDate>Fri, 07 Aug 2026 16:42:22 GMT</pubDate><category>WordPress</category><category>XSS</category><category>RCE</category><category>Web Security</category><category>CVE-2026-64638</category></item><item><title>Samsung Galaxy RCE: How Bixby Was Exploited via $50k Chain</title><link>https://runtimerebel.com/blog/samsung-galaxy-rce-how-bixby-was-exploited-via-50k-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/samsung-galaxy-rce-how-bixby-was-exploited-via-50k-chain</guid><description>Discover how security researchers chained vulnerabilities to turn Bixby against Samsung phones, achieving remote system-level compromise.</description><pubDate>Thu, 06 Aug 2026 01:56:34 GMT</pubDate><category>Samsung</category><category>Zero-Day</category><category>RCE</category><category>CVE-2025-21079</category><category>CVE-2025-58486</category></item><item><title>CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60137-wordpress-core-sql-injection-to-rce-patch-now</guid><description>CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.</description><pubDate>Sun, 02 Aug 2026 02:55:48 GMT</pubDate><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>CISA KEV</category><category>CVE-2026-60137</category></item><item><title>Rails Active Storage RCE via Critical Flaw — Patch Now</title><link>https://runtimerebel.com/blog/rails-active-storage-rce-via-critical-flaw-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/rails-active-storage-rce-via-critical-flaw-patch-now</guid><description>A critical flaw in Rails Active Storage permits unauthenticated attackers to read arbitrary files and potentially achieve remote code execution.</description><pubDate>Sat, 01 Aug 2026 17:00:44 GMT</pubDate><category>Rails</category><category>Active Storage</category><category>RCE</category><category>File Read</category><category>Web Application Security</category><category>Ruby on Rails</category></item><item><title>Ruflo MCP Bridge Command Execution: Mitigation Guide</title><link>https://runtimerebel.com/blog/ruflo-mcp-bridge-command-execution-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ruflo-mcp-bridge-command-execution-mitigation-guide</guid><description>Unauthenticated attackers can exploit a critical vulnerability in Ruflo to execute commands in the MCP bridge container and spawn rogue AI swarms.</description><pubDate>Thu, 30 Jul 2026 10:26:56 GMT</pubDate><category>Ruflo</category><category>AI Security</category><category>MCP Bridge</category><category>RCE</category><category>Container Security</category></item><item><title>CVE-2026-66066: Unauthenticated File Read in Rails Active Storage</title><link>https://runtimerebel.com/blog/cve-2026-66066-unauthenticated-file-read-in-rails-active-storage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-66066-unauthenticated-file-read-in-rails-active-storage</guid><description>Unauthenticated attackers can exploit CVE-2026-66066 in Ruby on Rails Active Storage to read sensitive server files, potentially leading to full compromise.</description><pubDate>Wed, 29 Jul 2026 20:57:40 GMT</pubDate><category>CVE-2026-66066</category><category>Ruby on Rails</category><category>Active Storage</category><category>Information Disclosure</category><category>RCE</category></item><item><title>RufRoot: How to Mitigate Persistent Flaws in Ruflo AI Platforms</title><link>https://runtimerebel.com/blog/rufroot-how-to-mitigate-persistent-flaws-in-ruflo-ai-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/rufroot-how-to-mitigate-persistent-flaws-in-ruflo-ai-platforms</guid><description>Analysis of the RufRoot vulnerability in Ruflo AI hosting, detailing how unauthenticated attackers deploy malicious agent swarms via memory corruption.</description><pubDate>Wed, 29 Jul 2026 17:17:40 GMT</pubDate><category>Ruflo</category><category>Rufroot</category><category>AI Security</category><category>Memory Corruption</category><category>RCE</category></item><item><title>CVE-2026-59726: Ruflo RCE and AI Memory Poisoning Mitigation</title><link>https://runtimerebel.com/blog/cve-2026-59726-ruflo-rce-and-ai-memory-poisoning-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-59726-ruflo-rce-and-ai-memory-poisoning-mitigation</guid><description>Unauthenticated attackers can achieve RCE and poison AI memory in Ruflo versions prior to 3.16.3. Learn how to detect and mitigate CVE-2026-59726.</description><pubDate>Wed, 29 Jul 2026 17:16:23 GMT</pubDate><category>CVE-2026-59726</category><category>Ruflo</category><category>Rufroot</category><category>AI Security</category><category>RCE</category></item><item><title>CVE-2026-10702: Firefox JIT Flaw Enables Tor Browser RCE - Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-10702-firefox-jit-flaw-enables-tor-browser-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-10702-firefox-jit-flaw-enables-tor-browser-rce-patch-now</guid><description>A critical JIT compiler vulnerability in Firefox, tracked as CVE-2026-10702, allows remote code execution on Tor Browser via a single malicious webpage visit.</description><pubDate>Wed, 29 Jul 2026 14:13:03 GMT</pubDate><category>CVE-2026-10702</category><category>Firefox</category><category>Tor Browser</category><category>RCE</category><category>JIT Compiler</category><category>Nebula Security</category></item><item><title>CVE-2026-53921: Critical RCE in OpenWrt DHCPv6 Stack — Update Now</title><link>https://runtimerebel.com/blog/cve-2026-53921-critical-rce-in-openwrt-dhcpv6-stack-update-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53921-critical-rce-in-openwrt-dhcpv6-stack-update-now</guid><description>OpenWrt version 24.10.8 fixes CVE-2026-53921, a critical 9.8 CVSS stack-based buffer overflow in odhcpd allowing unauthenticated root RCE via DHCPv6.</description><pubDate>Tue, 28 Jul 2026 14:09:46 GMT</pubDate><category>CVE-2026-53921</category><category>OpenWrt</category><category>Odhcpd</category><category>RCE</category><category>DHCPv6</category><category>Router Security</category></item><item><title>CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-unauthenticated-rce-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-unauthenticated-rce-mitigation-guide</guid><description>JetBrains has disclosed a critical RCE vulnerability (CVE-2026-63077) in TeamCity On-Premises. Learn how to patch your CI/CD environment and detect exploit attempts.</description><pubDate>Tue, 28 Jul 2026 10:36:59 GMT</pubDate><category>CVE-2026-63077</category><category>JetBrains</category><category>TeamCity</category><category>RCE</category><category>CI CD Security</category></item><item><title>CVE-2026-16812: Arista VeloCloud Orchestrator Command Injection Exploit</title><link>https://runtimerebel.com/blog/cve-2026-16812-arista-velocloud-orchestrator-command-injection-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16812-arista-velocloud-orchestrator-command-injection-exploit</guid><description>Attackers are actively exploiting a critical command injection vulnerability (CVE-2026-16812) in on-premises Arista VeloCloud Orchestrator, leading to arbitrary code…</description><pubDate>Tue, 28 Jul 2026 06:28:55 GMT</pubDate><category>CVE-2026-16812</category><category>Arista VeloCloud Orchestrator</category><category>Command Injection</category><category>RCE</category><category>Active Exploitation</category></item><item><title>FastJson Zero-Day RCE Exploitation Targets US Firms</title><link>https://runtimerebel.com/blog/fastjson-zero-day-rce-exploitation-targets-us-firms</link><guid isPermaLink="true">https://runtimerebel.com/blog/fastjson-zero-day-rce-exploitation-targets-us-firms</guid><description>Hackers are actively exploiting a Zero-Day RCE vulnerability in the FastJson Java library, enabling remote code execution against US firms.</description><pubDate>Tue, 28 Jul 2026 02:37:59 GMT</pubDate><category>Fastjson</category><category>RCE</category><category>Zero-Day</category><category>Java</category><category>Us Firms</category><category>Deserialization</category></item><item><title>vBulletin 6.2.1 Pre-Auth RCE: Public Exploit Analysis and Mitigation</title><link>https://runtimerebel.com/blog/vbulletin-6-2-1-pre-auth-rce-public-exploit-analysis-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/vbulletin-6-2-1-pre-auth-rce-public-exploit-analysis-and-mitigation</guid><description>A public exploit for a pre-auth RCE vulnerability in vBulletin 6.2.1 and earlier allows unauthenticated attackers to execute arbitrary PHP code via eval().</description><pubDate>Mon, 27 Jul 2026 17:43:22 GMT</pubDate><category>vBulletin</category><category>RCE</category><category>SSD Secure Disclosure</category><category>PHP Injection</category><category>Exploit Release</category></item><item><title>PTC Windchill RCE via CVE-2022-25247 — Mitigation Guide</title><link>https://runtimerebel.com/blog/ptc-windchill-rce-via-cve-2022-25247-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ptc-windchill-rce-via-cve-2022-25247-mitigation-guide</guid><description>Attackers are exploiting a critical deserialization flaw in PTC Windchill PLM software to deploy ransomware. Learn how to detect and patch CVE-2022-25247.</description><pubDate>Mon, 27 Jul 2026 14:40:34 GMT</pubDate><category>CVE-2022-25247</category><category>PTC Windchill</category><category>Ransomware</category><category>RCE</category><category>PLM Software</category></item><item><title>n8n RCE via Expression Sandbox Escape — Mitigation Guide</title><link>https://runtimerebel.com/blog/n8n-rce-via-expression-sandbox-escape-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-rce-via-expression-sandbox-escape-mitigation-guide</guid><description>Authenticated workflow editors in n8n can execute arbitrary OS commands via a sandbox escape. Update to versions 2.31.5 or 2.32.1 to mitigate this risk.</description><pubDate>Mon, 27 Jul 2026 14:38:21 GMT</pubDate><category>N8n</category><category>CVE-2026-27577</category><category>Sandbox Escape</category><category>RCE</category><category>Security Joes</category></item><item><title>CVE-2026-16723: Fastjson 1.x RCE Exploited in Spring Boot Applications</title><link>https://runtimerebel.com/blog/cve-2026-16723-fastjson-1-x-rce-exploited-in-spring-boot-applications</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-16723-fastjson-1-x-rce-exploited-in-spring-boot-applications</guid><description>Attackers are actively exploiting a critical unauthenticated RCE vulnerability (CVE-2026-16723) in Fastjson 1.x affecting Spring Boot environments.</description><pubDate>Sat, 25 Jul 2026 13:36:48 GMT</pubDate><category>CVE-2026-16723</category><category>Fastjson</category><category>Java Security</category><category>Spring Boot</category><category>RCE</category><category>Zero-Day</category></item><item><title>Rockwell Arena Simulation RCE: CVE-2024-37367 and CVE-2024-37368 Patch</title><link>https://runtimerebel.com/blog/rockwell-arena-simulation-rce-cve-2024-37367-and-cve-2024-37368-patch</link><guid isPermaLink="true">https://runtimerebel.com/blog/rockwell-arena-simulation-rce-cve-2024-37367-and-cve-2024-37368-patch</guid><description>Rockwell Automation addresses high-severity memory corruption flaws in Arena simulation software that enable remote code execution via malicious .doe files.</description><pubDate>Sat, 25 Jul 2026 09:49:59 GMT</pubDate><category>Rockwell Automation</category><category>Arena Simulation</category><category>CVE-2024-37367</category><category>CVE-2024-37368</category><category>ICS Security</category><category>RCE</category></item><item><title>GitLab 18.11.3 RCE via Jupyter Notebook Diff — Mitigation Guide</title><link>https://runtimerebel.com/blog/gitlab-18-11-3-rce-via-jupyter-notebook-diff-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/gitlab-18-11-3-rce-via-jupyter-notebook-diff-mitigation-guide</guid><description>An exploit PoC for GitLab 18.11.3 allows authenticated users to achieve RCE as the git user by requesting diffs of crafted Jupyter notebooks. Learn how to mitigate.</description><pubDate>Sat, 25 Jul 2026 09:49:14 GMT</pubDate><category>GitLab</category><category>RCE</category><category>Jupyter Notebook</category><category>Self Managed GitLab</category><category>PoC Exploit</category></item><item><title>Bing Image Workers RCE via CVE-2026-32194: Technical Analysis</title><link>https://runtimerebel.com/blog/bing-image-workers-rce-via-cve-2026-32194-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/bing-image-workers-rce-via-cve-2026-32194-technical-analysis</guid><description>A critical vulnerability in Bing&apos;s image processing tier allowed attackers to execute code as SYSTEM/root via crafted SVGs. Learn about the remediation steps.</description><pubDate>Fri, 24 Jul 2026 13:49:24 GMT</pubDate><category>CVE-2026-32194</category><category>Microsoft Bing</category><category>RCE</category><category>Cloud Security</category><category>SVG Vulnerability</category></item><item><title>Redis RCE via Kimi K3 AI-Discovered Zero-Days: Patching Guide</title><link>https://runtimerebel.com/blog/redis-rce-via-kimi-k3-ai-discovered-zero-days-patching-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/redis-rce-via-kimi-k3-ai-discovered-zero-days-patching-guide</guid><description>Redis patches multiple critical RCE vulnerabilities discovered by Kimi K3 AI agents affecting versions 6.2, 7.4, 8.6, and 8.8 via complex exploit chains.</description><pubDate>Fri, 24 Jul 2026 10:20:15 GMT</pubDate><category>Redis</category><category>RCE</category><category>Kimi K3</category><category>Zero-Day</category><category>Memory Corruption</category><category>RedisBloom</category></item><item><title>SolarWinds ARM RCE via CVE-2024-28995 — Technical Mitigation Guide</title><link>https://runtimerebel.com/blog/solarwinds-arm-rce-via-cve-2024-28995-technical-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/solarwinds-arm-rce-via-cve-2024-28995-technical-mitigation-guide</guid><description>Critical vulnerabilities in SolarWinds Access Rights Manager (ARM), including CVE-2024-28995, allow unauthenticated RCE. Update to version 2024.3 now.</description><pubDate>Fri, 24 Jul 2026 02:47:40 GMT</pubDate><category>SolarWinds</category><category>Access Rights Manager</category><category>CVE-2024-28995</category><category>RCE</category><category>Directory Traversal</category><category>Identity Security</category></item><item><title>GeoServer CVE-2024-36401 Exploit: Rondo Botnet Mitigation Guide</title><link>https://runtimerebel.com/blog/geoserver-cve-2024-36401-exploit-rondo-botnet-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/geoserver-cve-2024-36401-exploit-rondo-botnet-mitigation-guide</guid><description>Analysis of active Rondo botnet campaigns exploiting CVE-2024-36401 in GeoServer. Learn to detect unauthenticated RCE and protect your infrastructure.</description><pubDate>Thu, 23 Jul 2026 10:28:43 GMT</pubDate><category>CVE-2024-36401</category><category>GeoServer</category><category>Rondo Botnet</category><category>RCE</category><category>DDoS</category></item><item><title>CVE-2026-50522: SharePoint RCE Exploitation to Steal Machine Keys</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-exploitation-to-steal-machine-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-exploitation-to-steal-machine-keys</guid><description>Critical CVE-2026-50522 in Microsoft SharePoint is actively exploited to steal machine keys, enabling persistent access. Understand the threat and mitigation.</description><pubDate>Tue, 21 Jul 2026 21:12:05 GMT</pubDate><category>CVE-2026-50522</category><category>SharePoint</category><category>RCE</category><category>Machine Keys</category><category>Persistence</category><category>Microsoft</category></item><item><title>AWS Kiro RCE via Indirect Prompt Injection - Mitigation Guide</title><link>https://runtimerebel.com/blog/aws-kiro-rce-via-indirect-prompt-injection-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/aws-kiro-rce-via-indirect-prompt-injection-mitigation-guide</guid><description>Research reveals a critical flaw in AWS Kiro where malicious web pages trigger RCE by rewriting configuration files via indirect prompt injection attacks.</description><pubDate>Tue, 21 Jul 2026 17:22:23 GMT</pubDate><category>AWS</category><category>Kiro</category><category>RCE</category><category>Prompt Injection</category><category>AI Security</category></item><item><title>Open-Source Android AI Agent Hijacking Leads to Host System RCE</title><link>https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/open-source-android-ai-agent-hijacking-leads-to-host-system-rce</guid><description>Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.</description><pubDate>Tue, 21 Jul 2026 13:54:29 GMT</pubDate><category>Android Security</category><category>AI Agents</category><category>Prompt Injection</category><category>RCE</category><category>Mobile Security</category><category>Appagent</category></item><item><title>ENCFORGE Ransomware Targets AI Systems via Langflow RCE</title><link>https://runtimerebel.com/blog/encforge-ransomware-targets-ai-systems-via-langflow-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/encforge-ransomware-targets-ai-systems-via-langflow-rce</guid><description>New ENCFORGE ransomware, attributed to JADEPUFFER, leverages a Langflow RCE vulnerability to encrypt AI model files, weights, and training data.</description><pubDate>Tue, 21 Jul 2026 10:39:45 GMT</pubDate><category>ENCFORGE</category><category>Ransomware</category><category>JADEPUFFER</category><category>Langflow</category><category>RCE</category><category>AI</category><category>Sysdig</category><category>Golang</category></item><item><title>WP2Shell: WordPress RCE via Chained CVE-2026-60137 &amp; CVE-2026-63030</title><link>https://runtimerebel.com/blog/wp2shell-wordpress-rce-via-chained-cve-2026-60137-cve-2026-63030</link><guid isPermaLink="true">https://runtimerebel.com/blog/wp2shell-wordpress-rce-via-chained-cve-2026-60137-cve-2026-63030</guid><description>WP2Shell exploits CVE-2026-60137 and CVE-2026-63030 to achieve remote takeover on millions of WordPress sites. Immediate patching is critical.</description><pubDate>Tue, 21 Jul 2026 02:54:17 GMT</pubDate><category>Wp2shell</category><category>WordPress</category><category>RCE</category><category>CVE-2026-60137</category><category>CVE-2026-63030</category><category>Web Security</category></item><item><title>CVE-2026-63030: WordPress Core SQLi Leads to Unauth RCE</title><link>https://runtimerebel.com/blog/cve-2026-63030-wordpress-core-sqli-leads-to-unauth-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63030-wordpress-core-sqli-leads-to-unauth-rce</guid><description>Critical SQL injection vulnerability (CVE-2026-63030) in WordPress Core enables unauthenticated remote code execution. Active exploitation confirmed.</description><pubDate>Mon, 20 Jul 2026 21:15:06 GMT</pubDate><category>CVE-2026-63030</category><category>WordPress</category><category>SQL Injection</category><category>RCE</category><category>Wp2shell</category></item><item><title>WordPress RCE and SonicWall Zero-Days: Weekly Threat Intel Update</title><link>https://runtimerebel.com/blog/wordpress-rce-and-sonicwall-zero-days-weekly-threat-intel-update</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-rce-and-sonicwall-zero-days-weekly-threat-intel-update</guid><description>Active exploitation of WordPress RCE and SonicWall zero-day vulnerabilities highlights critical risks for internet-facing systems. Learn how to mitigate.</description><pubDate>Mon, 20 Jul 2026 14:11:23 GMT</pubDate><category>WordPress</category><category>SonicWall</category><category>SharePoint</category><category>RCE</category><category>Zero-Day</category></item><item><title>7-Zip RCE via CVE-2026-14266: XZ Archive Extraction Patch Guidance</title><link>https://runtimerebel.com/blog/7-zip-rce-via-cve-2026-14266-xz-archive-extraction-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/7-zip-rce-via-cve-2026-14266-xz-archive-extraction-patch-guidance</guid><description>7-Zip versions prior to 26.02 are vulnerable to a heap-based buffer overflow. Learn how to mitigate CVE-2026-14266 and secure XZ archive extractions.</description><pubDate>Mon, 20 Jul 2026 10:54:46 GMT</pubDate><category>7 Zip</category><category>CVE-2026-14266</category><category>XZ Archive</category><category>Buffer Overflow</category><category>RCE</category></item><item><title>WP2Shell Vulnerabilities CVE-2026-60137 &amp; CVE-2026-63030 Exploited</title><link>https://runtimerebel.com/blog/wp2shell-vulnerabilities-cve-2026-60137-cve-2026-63030-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/wp2shell-vulnerabilities-cve-2026-60137-cve-2026-63030-exploited</guid><description>WordPress sites face active exploitation via WP2Shell vulnerabilities CVE-2026-60137 and CVE-2026-63030. Learn the technical details and mitigation steps.</description><pubDate>Mon, 20 Jul 2026 06:49:53 GMT</pubDate><category>Wp2shell</category><category>WordPress</category><category>CVE-2026-60137</category><category>CVE-2026-63030</category><category>RCE</category><category>Active Exploitation</category></item><item><title>CVE-2026-42533: NGINX RCE and Denial of Service — Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-42533-nginx-rce-and-denial-of-service-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42533-nginx-rce-and-denial-of-service-mitigation-guide</guid><description>Exploit analysis of CVE-2026-42533, a critical heap buffer overflow in NGINX. Learn how to detect and patch worker process crashes and potential RCE.</description><pubDate>Mon, 20 Jul 2026 03:26:34 GMT</pubDate><category>CVE-2026-42533</category><category>NGINX</category><category>RCE</category><category>Heap Overflow</category><category>F5</category><category>Vulnerability</category></item><item><title>WordPress wp2shell RCE: Public Exploits Released for Core Flaws</title><link>https://runtimerebel.com/blog/wordpress-wp2shell-rce-public-exploits-released-for-core-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-wp2shell-rce-public-exploits-released-for-core-flaws</guid><description>Public exploits for wp2shell RCE flaws in WordPress Core are now available. Learn how to detect, mitigate, and patch these critical vulnerabilities immediately.</description><pubDate>Sat, 18 Jul 2026 20:51:39 GMT</pubDate><category>WordPress</category><category>RCE</category><category>Wp2shell</category><category>Exploit Available</category><category>Patching</category></item><item><title>7-Zip 24.05 RCE via Malicious Archives: Patch Guidance</title><link>https://runtimerebel.com/blog/7-zip-24-05-rce-via-malicious-archives-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/7-zip-24-05-rce-via-malicious-archives-patch-guidance</guid><description>7-Zip version 24.05 addresses a critical remote code execution vulnerability found in archive handling. Learn how to detect and mitigate this risk in your SOC.</description><pubDate>Sat, 18 Jul 2026 20:51:18 GMT</pubDate><category>7 Zip</category><category>RCE</category><category>Patch Management</category><category>Archive Security</category></item><item><title>WordPress Core RCE wp2shell: Versions 6.9 and 7.0 Vulnerable</title><link>https://runtimerebel.com/blog/wordpress-core-rce-wp2shell-versions-6-9-and-7-0-vulnerable</link><guid isPermaLink="true">https://runtimerebel.com/blog/wordpress-core-rce-wp2shell-versions-6-9-and-7-0-vulnerable</guid><description>Unauthenticated attackers can achieve RCE on WordPress 6.9 and 7.0 core installations via the wp2shell flaw. Learn how to secure your site today.</description><pubDate>Sat, 18 Jul 2026 02:36:35 GMT</pubDate><category>WordPress</category><category>Wp2shell</category><category>RCE</category><category>Assetnote</category><category>Core Vulnerability</category></item><item><title>CVE-2026-58644: SharePoint RCE Zero-Day Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2026-58644-sharepoint-rce-zero-day-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-58644-sharepoint-rce-zero-day-exploited-in-the-wild</guid><description>CISA adds CVE-2026-58644, a critical Microsoft SharePoint Server deserialization RCE vulnerability with a CVSS 9.8, to its Known Exploited Vulnerabilities catalog.</description><pubDate>Fri, 17 Jul 2026 09:58:24 GMT</pubDate><category>CVE-2026-58644</category><category>SharePoint</category><category>Microsoft</category><category>CISA KEV</category><category>RCE</category></item><item><title>Security Vendors Patch Severe RCE and LPE Vulnerabilities</title><link>https://runtimerebel.com/blog/security-vendors-patch-severe-rce-and-lpe-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-vendors-patch-severe-rce-and-lpe-vulnerabilities</guid><description>Analysis of critical vulnerabilities in Trend Micro, Tanium, ESET, and Tenable products, including CVE-2024-48904 and local privilege escalation flaws.</description><pubDate>Thu, 16 Jul 2026 06:20:15 GMT</pubDate><category>Trend Micro</category><category>Tanium</category><category>ESET</category><category>Tenable</category><category>CVE-2024-48904</category><category>RCE</category><category>Privilege Escalation</category></item><item><title>Exposed Cloud Functions: Hardening GCP Serverless Against LFI &amp; RCE</title><link>https://runtimerebel.com/blog/exposed-cloud-functions-hardening-gcp-serverless-against-lfi-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-cloud-functions-hardening-gcp-serverless-against-lfi-rce</guid><description>Mandiant identifies exposed serverless functions as initial access points. Learn to harden Google Cloud Run against LFI and RCE with IAM, WAF, and secure SDLC.</description><pubDate>Wed, 15 Jul 2026 17:23:18 GMT</pubDate><category>Google Cloud</category><category>Cloud Run</category><category>Serverless</category><category>LFI</category><category>Command Injection</category><category>RCE</category><category>WAF</category><category>Cloud Armor</category><category>IAM</category><category>Mandiant</category><category>Cloud Security Posture Management</category></item><item><title>Cursor RCE via Malicious Git Executable — Unpatched Vulnerability Alert</title><link>https://runtimerebel.com/blog/cursor-rce-via-malicious-git-executable-unpatched-vulnerability-alert</link><guid isPermaLink="true">https://runtimerebel.com/blog/cursor-rce-via-malicious-git-executable-unpatched-vulnerability-alert</guid><description>An unpatched vulnerability in the Cursor AI code editor allows RCE when users clone a malicious Git repository containing a crafted git.exe in the project root.</description><pubDate>Wed, 15 Jul 2026 17:21:36 GMT</pubDate><category>Cursor</category><category>RCE</category><category>Git</category><category>Code Editor</category><category>Supply Chain</category><category>Unpatched Vulnerability</category><category>Code Execution</category></item><item><title>CVE-2024-10022: Progress ShareFile Storage Zones Controller Zero-Day</title><link>https://runtimerebel.com/blog/cve-2024-10022-progress-sharefile-storage-zones-controller-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-10022-progress-sharefile-storage-zones-controller-zero-day</guid><description>Progress Software patches a critical zero-day in ShareFile Storage Zones Controller. Learn how to detect and mitigate this improper access control exploit.</description><pubDate>Wed, 15 Jul 2026 10:07:10 GMT</pubDate><category>CVE-2024-10022</category><category>Progress Software</category><category>ShareFile</category><category>Zero-Day</category><category>RCE</category></item><item><title>SonicWall SMA1000 Series RCE via CVE-2026-15409 — Mitigation Guide</title><link>https://runtimerebel.com/blog/sonicwall-sma1000-series-rce-via-cve-2026-15409-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-sma1000-series-rce-via-cve-2026-15409-mitigation-guide</guid><description>SonicWall warns of two critical zero-day vulnerabilities in SMA1000 series appliances (CVE-2026-15409, CVE-2026-15410) allowing remote code execution.</description><pubDate>Wed, 15 Jul 2026 06:16:04 GMT</pubDate><category>SonicWall</category><category>SMA1000</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><category>RCE</category><category>Zero-Day</category></item></channel></rss>