Advertisement
CVE-2026-73749: HPE ArubaOS-CX RCE Flaw Patched
HPE patches a critical remote code execution flaw, CVE-2026-73749, in ArubaOS-CX switches. Unauthenticated attackers can exploit a buffer overflow.
Critical Cisco Nexus 9000 RCE (CVE-2026-20212) & IOS XR Hardening
Cisco addresses a critical RCE flaw (CVE-2026-20212) in Nexus 9000 switches, alongside significant IOS XR hardening updates.
CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection
Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.
CVE-2026-49869: Kestra OSS OS Command Injection Exploited
CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.
CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data
CVE-2021-23758 in Ajax.NET Professional allows remote code execution via untrusted data deserialization, with CISA confirming active exploitation.
CVE-2026-60004: Gitea Code Injection Under Active Exploitation
CISA confirms active exploitation of CVE-2026-60004, a Gitea code injection vulnerability allowing shell command execution with repository write access.
Advertisement
Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated
Microsoft has fully mitigated a critical remote code execution flaw, CVE-2026-69836, in Entra ID (formerly Azure AD). No customer action is required.
CVE-2026-72529: Critical RCE in TrueConf Server via Missing Auth
CISA warns of active exploitation of CVE-2026-72529 in TrueConf Server, allowing remote attackers to execute arbitrary scripts via port 4307/TCP.
CVE-2026-72530: TrueConf Server Remote Code Execution
CISA confirms active exploitation of CVE-2026-72530, a TrueConf Server code injection flaw leading to remote code execution. Immediate patching is critical.
Zimbra CVE-2026-73570 Actively Exploited: Patch Now
Active exploitation targets Zimbra servers via CVE-2026-73570, a high-severity flaw allowing unauthenticated RCE. Patch to v10.1.20 now.
CVE-2026-32475: Elementor Pro Unauthenticated RCE Flaw
A critical flaw, CVE-2026-32475, in Elementor Pro allows unauthenticated attackers to upload PHP files and execute code, affecting versions <= 4.2.1.
CVE-2026-33824: Microsoft IKE Double Free RCE Exploit
CISA confirms active exploitation of CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions, enabling remote code execution.
Unisoc Modem Exploit Chain: Android Takeover via Video Call
An exploit chain targeting Unisoc modems allows remote Android device takeover through a malicious video call, requiring victim interaction.
CVE-2025-62593: Ray-Project Ray RCE Exploited In Wild
CISA confirms active exploitation of CVE-2025-62593, a critical code injection vulnerability in Ray-Project Ray allowing remote code execution. Developers are targeted.
SharePoint RCE via CVE-2026-55040 & CVE-2026-63520: Patch Now
An AI-assisted exploit chain, leveraging CVE-2026-55040 and CVE-2026-63520, enables unauthenticated RCE on Microsoft SharePoint Server. Immediate patching is critical.
CVE-2026-72898: Metabase SQL Injection Active Exploitation
CISA adds Metabase CVE-2026-72898 SQL injection to its KEV catalog, enabling unauthenticated remote attackers to gain admin access.
CVE-2026-63077: JetBrains TeamCity RCE via Deserialization
CISA adds CVE-2026-63077 to KEV, indicating active exploitation of a JetBrains TeamCity deserialization RCE vulnerability.
Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms
Unpatched Metabase business-analytics zero-day vulnerability allows remote administrative access and threatens downstream corporate networks.
CVE-2026-53413: Zoom Zero-Click RCE – Patch Now
Zoom patches CVE-2026-53413, a critical zero-click RCE in its annotator function, affecting all clients. Immediate patching is advised.
Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder
Project Zero details a zero-click exploit chain targeting Google Pixel 9 via the Dolby Unified Decoder, leading to arbitrary code execution.
Bendix EC80 Hidden RCE and DoS Flaws in Brake Controllers
NMFTA reveals Bendix EC80 heavy-truck brake controllers fixed critical, wirelessly reachable remote code execution and DoS flaws in a safety recall.
CVE-2026-8037: Progress LoadMaster Command Injection RCE
Progress LoadMaster command injection (CVE-2026-8037) allows unauthenticated attackers to execute arbitrary commands. Active exploitation confirmed by CISA.
Google ADK for Python RCE: Agent-to-Agent Attacks Expose Secrets
Pillar Security uncovered agent-to-agent RCE flaws in Google's ADK for Python, allowing secret exposure and PR tampering, risking supply chain integrity.
CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now
CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…