<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Remote Code Execution</title><description>Cybersecurity articles tagged #Remote Code Execution on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>CVE-2026-73749: HPE ArubaOS-CX RCE Flaw Patched</title><link>https://runtimerebel.com/blog/cve-2026-73749-hpe-arubaos-cx-rce-flaw-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-73749-hpe-arubaos-cx-rce-flaw-patched</guid><description>HPE patches a critical remote code execution flaw, CVE-2026-73749, in ArubaOS-CX switches. Unauthenticated attackers can exploit a buffer overflow.</description><pubDate>Thu, 03 Sep 2026 19:00:03 GMT</pubDate><category>Remote Code Execution</category><category>Buffer Overflow</category><category>HPE</category><category>ArubaOS CX</category><category>CVE-2026-73749</category></item><item><title>Critical Cisco Nexus 9000 RCE (CVE-2026-20212) &amp; IOS XR Hardening</title><link>https://runtimerebel.com/blog/critical-cisco-nexus-9000-rce-cve-2026-20212-ios-xr-hardening</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-cisco-nexus-9000-rce-cve-2026-20212-ios-xr-hardening</guid><description>Cisco addresses a critical RCE flaw (CVE-2026-20212) in Nexus 9000 switches, alongside significant IOS XR hardening updates.</description><pubDate>Thu, 03 Sep 2026 18:59:35 GMT</pubDate><category>Remote Code Execution</category><category>CVE-2026-20212</category><category>CVE-2026-20274</category><category>CVE-2026-20279</category><category>Cisco Nexus 9000</category></item><item><title>CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection</title><link>https://runtimerebel.com/blog/cve-2026-9586-sangoma-switchvox-rce-via-sql-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-9586-sangoma-switchvox-rce-via-sql-injection</guid><description>Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.</description><pubDate>Wed, 02 Sep 2026 19:12:29 GMT</pubDate><category>CVE-2026-9586</category><category>Sangoma Switchvox</category><category>SQL Injection</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-49869: Kestra OSS OS Command Injection Exploited</title><link>https://runtimerebel.com/blog/cve-2026-49869-kestra-oss-os-command-injection-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-49869-kestra-oss-os-command-injection-exploited</guid><description>CISA has added CVE-2026-49869, an OS command injection in Kestra OSS, to its KEV catalog, confirming active exploitation by unauthenticated attackers.</description><pubDate>Wed, 02 Sep 2026 19:11:22 GMT</pubDate><category>CVE-2026-49869</category><category>Kestra OSS</category><category>OS Command Injection</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>CVE-2021-23758: Ajax.NET RCE via Deserialization of Untrusted Data</title><link>https://runtimerebel.com/blog/cve-2021-23758-ajax-net-rce-via-deserialization-of-untrusted-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2021-23758-ajax-net-rce-via-deserialization-of-untrusted-data</guid><description>CVE-2021-23758 in Ajax.NET Professional allows remote code execution via untrusted data deserialization, with CISA confirming active exploitation.</description><pubDate>Tue, 01 Sep 2026 02:58:41 GMT</pubDate><category>CVE-2021-23758</category><category>Ajax NET Professional</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>CVE-2026-60004: Gitea Code Injection Under Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-60004-gitea-code-injection-under-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-60004-gitea-code-injection-under-active-exploitation</guid><description>CISA confirms active exploitation of CVE-2026-60004, a Gitea code injection vulnerability allowing shell command execution with repository write access.</description><pubDate>Wed, 26 Aug 2026 00:45:21 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-60004</category><category>Gitea</category><category>Code Injection</category></item><item><title>Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated</title><link>https://runtimerebel.com/blog/microsoft-entra-id-rce-flaw-cve-2026-69836-fully-mitigated</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-entra-id-rce-flaw-cve-2026-69836-fully-mitigated</guid><description>Microsoft has fully mitigated a critical remote code execution flaw, CVE-2026-69836, in Entra ID (formerly Azure AD). No customer action is required.</description><pubDate>Sun, 23 Aug 2026 08:18:38 GMT</pubDate><category>Microsoft Entra ID</category><category>Azure AD</category><category>Remote Code Execution</category><category>Deserialization</category><category>Cloud Security</category></item><item><title>CVE-2026-72529: Critical RCE in TrueConf Server via Missing Auth</title><link>https://runtimerebel.com/blog/cve-2026-72529-critical-rce-in-trueconf-server-via-missing-auth</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72529-critical-rce-in-trueconf-server-via-missing-auth</guid><description>CISA warns of active exploitation of CVE-2026-72529 in TrueConf Server, allowing remote attackers to execute arbitrary scripts via port 4307/TCP.</description><pubDate>Fri, 21 Aug 2026 00:48:00 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-72529</category><category>TrueConf Server</category><category>Missing Authentication</category></item><item><title>CVE-2026-72530: TrueConf Server Remote Code Execution</title><link>https://runtimerebel.com/blog/cve-2026-72530-trueconf-server-remote-code-execution</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72530-trueconf-server-remote-code-execution</guid><description>CISA confirms active exploitation of CVE-2026-72530, a TrueConf Server code injection flaw leading to remote code execution. Immediate patching is critical.</description><pubDate>Fri, 21 Aug 2026 00:47:12 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>Vulnerability Management</category><category>CVE-2026-72530</category><category>TrueConf Server</category></item><item><title>Zimbra CVE-2026-73570 Actively Exploited: Patch Now</title><link>https://runtimerebel.com/blog/zimbra-cve-2026-73570-actively-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/zimbra-cve-2026-73570-actively-exploited-patch-now</guid><description>Active exploitation targets Zimbra servers via CVE-2026-73570, a high-severity flaw allowing unauthenticated RCE. Patch to v10.1.20 now.</description><pubDate>Thu, 20 Aug 2026 16:24:30 GMT</pubDate><category>Zimbra</category><category>Exploitation</category><category>Remote Code Execution</category><category>CVE-2026-73570</category><category>Zimbra Collaboration Suite</category></item><item><title>CVE-2026-32475: Elementor Pro Unauthenticated RCE Flaw</title><link>https://runtimerebel.com/blog/cve-2026-32475-elementor-pro-unauthenticated-rce-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-32475-elementor-pro-unauthenticated-rce-flaw</guid><description>A critical flaw, CVE-2026-32475, in Elementor Pro allows unauthenticated attackers to upload PHP files and execute code, affecting versions &lt;= 4.2.1.</description><pubDate>Thu, 20 Aug 2026 08:26:43 GMT</pubDate><category>WordPress</category><category>Remote Code Execution</category><category>CVE-2026-32475</category><category>Elementor Pro</category><category>File Upload Vulnerability</category></item><item><title>CVE-2026-33824: Microsoft IKE Double Free RCE Exploit</title><link>https://runtimerebel.com/blog/cve-2026-33824-microsoft-ike-double-free-rce-exploit</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33824-microsoft-ike-double-free-rce-exploit</guid><description>CISA confirms active exploitation of CVE-2026-33824 in Microsoft Internet Key Exchange (IKE) Service Extensions, enabling remote code execution.</description><pubDate>Wed, 19 Aug 2026 00:43:34 GMT</pubDate><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-33824</category><category>Microsoft IKE</category><category>Double Free</category></item><item><title>Unisoc Modem Exploit Chain: Android Takeover via Video Call</title><link>https://runtimerebel.com/blog/unisoc-modem-exploit-chain-android-takeover-via-video-call</link><guid isPermaLink="true">https://runtimerebel.com/blog/unisoc-modem-exploit-chain-android-takeover-via-video-call</guid><description>An exploit chain targeting Unisoc modems allows remote Android device takeover through a malicious video call, requiring victim interaction.</description><pubDate>Tue, 18 Aug 2026 00:41:53 GMT</pubDate><category>Android</category><category>Mobile Security</category><category>Remote Code Execution</category><category>Exploit Chain</category><category>Unisoc</category></item><item><title>CVE-2025-62593: Ray-Project Ray RCE Exploited In Wild</title><link>https://runtimerebel.com/blog/cve-2025-62593-ray-project-ray-rce-exploited-in-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-62593-ray-project-ray-rce-exploited-in-wild</guid><description>CISA confirms active exploitation of CVE-2025-62593, a critical code injection vulnerability in Ray-Project Ray allowing remote code execution. Developers are targeted.</description><pubDate>Mon, 17 Aug 2026 16:20:50 GMT</pubDate><category>Remote Code Execution</category><category>RCE</category><category>CISA KEV</category><category>CVE-2025-62593</category><category>Ray Project</category></item><item><title>SharePoint RCE via CVE-2026-55040 &amp; CVE-2026-63520: Patch Now</title><link>https://runtimerebel.com/blog/sharepoint-rce-via-cve-2026-55040-cve-2026-63520-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/sharepoint-rce-via-cve-2026-55040-cve-2026-63520-patch-now</guid><description>An AI-assisted exploit chain, leveraging CVE-2026-55040 and CVE-2026-63520, enables unauthenticated RCE on Microsoft SharePoint Server. Immediate patching is critical.</description><pubDate>Mon, 17 Aug 2026 00:39:44 GMT</pubDate><category>Microsoft SharePoint</category><category>Remote Code Execution</category><category>Vulnerability Chaining</category><category>AI in Cybersecurity</category><category>CVE-2026-55040</category></item><item><title>CVE-2026-72898: Metabase SQL Injection Active Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-72898-metabase-sql-injection-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-72898-metabase-sql-injection-active-exploitation</guid><description>CISA adds Metabase CVE-2026-72898 SQL injection to its KEV catalog, enabling unauthenticated remote attackers to gain admin access.</description><pubDate>Wed, 12 Aug 2026 01:08:08 GMT</pubDate><category>CVE-2026-72898</category><category>Metabase</category><category>SQL Injection</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>CVE-2026-63077: JetBrains TeamCity RCE via Deserialization</title><link>https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-rce-via-deserialization</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-rce-via-deserialization</guid><description>CISA adds CVE-2026-63077 to KEV, indicating active exploitation of a JetBrains TeamCity deserialization RCE vulnerability.</description><pubDate>Tue, 11 Aug 2026 16:54:33 GMT</pubDate><category>CVE-2026-63077</category><category>JetBrains TeamCity</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms</title><link>https://runtimerebel.com/blog/metabase-zero-day-sql-vulnerability-threatens-analytics-platforms</link><guid isPermaLink="true">https://runtimerebel.com/blog/metabase-zero-day-sql-vulnerability-threatens-analytics-platforms</guid><description>Unpatched Metabase business-analytics zero-day vulnerability allows remote administrative access and threatens downstream corporate networks.</description><pubDate>Tue, 11 Aug 2026 16:50:53 GMT</pubDate><category>Metabase</category><category>Zero-Day</category><category>Remote Code Execution</category><category>SQL Injection</category><category>Vulnerability</category></item><item><title>CVE-2026-53413: Zoom Zero-Click RCE – Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-53413-zoom-zero-click-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-53413-zoom-zero-click-rce-patch-now</guid><description>Zoom patches CVE-2026-53413, a critical zero-click RCE in its annotator function, affecting all clients. Immediate patching is advised.</description><pubDate>Tue, 11 Aug 2026 16:49:49 GMT</pubDate><category>Remote Code Execution</category><category>Zero Click</category><category>Memory Corruption</category><category>CVE-2026-53413</category><category>Zoom</category></item><item><title>Pixel 9 Zero-Click RCE: Exploiting Dolby Unified Decoder</title><link>https://runtimerebel.com/blog/pixel-9-zero-click-rce-exploiting-dolby-unified-decoder</link><guid isPermaLink="true">https://runtimerebel.com/blog/pixel-9-zero-click-rce-exploiting-dolby-unified-decoder</guid><description>Project Zero details a zero-click exploit chain targeting Google Pixel 9 via the Dolby Unified Decoder, leading to arbitrary code execution.</description><pubDate>Sat, 08 Aug 2026 08:35:48 GMT</pubDate><category>Google Pixel</category><category>CVE-2025-54957</category><category>Zero-Day</category><category>Remote Code Execution</category><category>Android</category></item><item><title>Bendix EC80 Hidden RCE and DoS Flaws in Brake Controllers</title><link>https://runtimerebel.com/blog/bendix-ec80-hidden-rce-and-dos-flaws-in-brake-controllers</link><guid isPermaLink="true">https://runtimerebel.com/blog/bendix-ec80-hidden-rce-and-dos-flaws-in-brake-controllers</guid><description>NMFTA reveals Bendix EC80 heavy-truck brake controllers fixed critical, wirelessly reachable remote code execution and DoS flaws in a safety recall.</description><pubDate>Sat, 08 Aug 2026 08:29:05 GMT</pubDate><category>Nmfta</category><category>Remote Code Execution</category><category>Denial of Service</category><category>Supply Chain</category><category>Bendix</category></item><item><title>CVE-2026-8037: Progress LoadMaster Command Injection RCE</title><link>https://runtimerebel.com/blog/cve-2026-8037-progress-loadmaster-command-injection-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-8037-progress-loadmaster-command-injection-rce</guid><description>Progress LoadMaster command injection (CVE-2026-8037) allows unauthenticated attackers to execute arbitrary commands. Active exploitation confirmed by CISA.</description><pubDate>Sat, 08 Aug 2026 01:04:01 GMT</pubDate><category>Command Injection</category><category>Remote Code Execution</category><category>CISA KEV</category><category>CVE-2026-8037</category><category>Progress LoadMaster</category></item><item><title>Google ADK for Python RCE: Agent-to-Agent Attacks Expose Secrets</title><link>https://runtimerebel.com/blog/google-adk-for-python-rce-agent-to-agent-attacks-expose-secrets</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-adk-for-python-rce-agent-to-agent-attacks-expose-secrets</guid><description>Pillar Security uncovered agent-to-agent RCE flaws in Google&apos;s ADK for Python, allowing secret exposure and PR tampering, risking supply chain integrity.</description><pubDate>Tue, 04 Aug 2026 11:22:21 GMT</pubDate><category>Supply Chain Attack</category><category>Remote Code Execution</category><category>Google Adk Python</category><category>Agent Development Kit</category><category>Pull Request Tampering</category></item><item><title>CVE-2026-50522: SharePoint RCE via Deserialization — Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-via-deserialization-patch-now</guid><description>CISA confirmed active exploitation of CVE-2026-50522 in Microsoft SharePoint. Attackers leverage a deserialization vulnerability to execute code remotely. Patch…</description><pubDate>Sun, 02 Aug 2026 16:49:14 GMT</pubDate><category>CVE-2026-50522</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>Remote Code Execution</category><category>CISA KEV</category></item><item><title>VMware Critical Flaws: Auth Bypass, RCE, VM Escapes Patched</title><link>https://runtimerebel.com/blog/vmware-critical-flaws-auth-bypass-rce-vm-escapes-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-critical-flaws-auth-bypass-rce-vm-escapes-patched</guid><description>VMware has patched critical vulnerabilities across vCenter, ESX, Workstation, and Fusion, addressing authentication bypass, remote code execution, and VM escapes.</description><pubDate>Thu, 30 Jul 2026 21:12:31 GMT</pubDate><category>VMware vCenter</category><category>VMware ESX</category><category>VMware Workstation</category><category>VMware Fusion</category><category>Authentication Bypass</category><category>Remote Code Execution</category><category>VM Escape</category></item><item><title>CVE-2024-24691: Zoom Windows Client Account Takeover - Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-24691-zoom-windows-client-account-takeover-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-24691-zoom-windows-client-account-takeover-patch-now</guid><description>Zoom has addressed CVE-2024-24691, a critical 9.6 CVSS vulnerability in Windows clients allowing unauthenticated account takeover. Learn how to patch and defend.</description><pubDate>Wed, 15 Jul 2026 21:05:22 GMT</pubDate><category>CVE-2024-24691</category><category>Zoom</category><category>Account Takeover</category><category>Windows</category><category>Remote Code Execution</category></item><item><title>CVE-2026-45659: SharePoint RCE Exploitation - Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-exploitation-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-exploitation-mitigation-guide</guid><description>CISA adds CVE-2026-45659, a high-severity SharePoint Server deserialization flaw, to KEV catalog after confirmed active exploitation by threat actors.</description><pubDate>Thu, 02 Jul 2026 07:34:50 GMT</pubDate><category>CVE-2026-45659</category><category>Microsoft SharePoint</category><category>Deserialization</category><category>CISA KEV</category><category>Remote Code Execution</category></item><item><title>CryptoBandits Malware: Tor-Abusing Backdoor &amp; Data Theft</title><link>https://runtimerebel.com/blog/cryptobandits-malware-tor-abusing-backdoor-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/cryptobandits-malware-tor-abusing-backdoor-data-theft</guid><description>CryptoBandits malware functions as a backdoor, leveraging Tor and a SOCKS5 proxy for stealthy data theft and remote code execution capabilities.</description><pubDate>Fri, 19 Jun 2026 16:55:32 GMT</pubDate><category>CryptoBandits</category><category>Backdoor</category><category>Tor</category><category>SOCKS5 Proxy</category><category>Data Theft</category><category>Remote Code Execution</category></item><item><title>Gogs RCE via CVE-2024-39930 — Mitigation and Patch Guide</title><link>https://runtimerebel.com/blog/gogs-rce-via-cve-2024-39930-mitigation-and-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/gogs-rce-via-cve-2024-39930-mitigation-and-patch-guide</guid><description>A critical argument injection in Gogs (CVE-2024-39930) allows authenticated users to achieve RCE via malicious pull requests. Learn how to patch and defend.</description><pubDate>Fri, 29 May 2026 13:19:23 GMT</pubDate><category>Gogs</category><category>CVE-2024-39930</category><category>Remote Code Execution</category><category>Git Security</category></item><item><title>Gogs Authenticated RCE: Arbitrary Code Execution - Mitigation Guide</title><link>https://runtimerebel.com/blog/gogs-authenticated-rce-arbitrary-code-execution-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/gogs-authenticated-rce-arbitrary-code-execution-mitigation-guide</guid><description>A critical RCE vulnerability in Gogs allows authenticated users to execute arbitrary code. Runtime Rebel provides an analysis and urgent mitigation guidance.</description><pubDate>Thu, 28 May 2026 20:52:47 GMT</pubDate><category>Gogs</category><category>RCE</category><category>Git Service</category><category>Authenticated RCE</category><category>Remote Code Execution</category></item><item><title>Exim RCE: Unauthenticated Remote Code Execution Critical Flaw</title><link>https://runtimerebel.com/blog/exim-rce-unauthenticated-remote-code-execution-critical-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/exim-rce-unauthenticated-remote-code-execution-critical-flaw</guid><description>A new critical flaw in Exim mailer allows unauthenticated remote code execution on certain configurations. Immediate patching is vital for security professionals.</description><pubDate>Wed, 13 May 2026 20:39:16 GMT</pubDate><category>Exim</category><category>RCE</category><category>Mailer</category><category>Remote Code Execution</category><category>Mail Server</category></item><item><title>cPanel CVE-2026-41940 Exploitation: 40,000 Servers Compromised</title><link>https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploitation-40000-servers-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/cpanel-cve-2026-41940-exploitation-40000-servers-compromised</guid><description>Attackers leverage a zero-day vulnerability in cPanel, identified as CVE-2026-41940, to gain administrative access to over 40,000 hosting servers.</description><pubDate>Mon, 04 May 2026 08:56:30 GMT</pubDate><category>cPanel</category><category>CVE-2026-41940</category><category>Remote Code Execution</category><category>Server Security</category></item><item><title>CVE-2024-36985: Splunk Enterprise RCE via File Upload - Patch Guide</title><link>https://runtimerebel.com/blog/cve-2024-36985-splunk-enterprise-rce-via-file-upload-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-36985-splunk-enterprise-rce-via-file-upload-patch-guide</guid><description>Splunk patches a high-severity RCE vulnerability (CVE-2024-36985) allowing low-privileged users to execute code on Windows-based Enterprise instances.</description><pubDate>Thu, 16 Apr 2026 12:34:23 GMT</pubDate><category>CVE-2024-36985</category><category>Splunk Enterprise</category><category>Remote Code Execution</category><category>Windows Security</category><category>Patch Management</category></item><item><title>Adobe Reader Zero-Day Exploited via Malicious PDF Documents</title><link>https://runtimerebel.com/blog/adobe-reader-zero-day-exploited-via-malicious-pdf-documents</link><guid isPermaLink="true">https://runtimerebel.com/blog/adobe-reader-zero-day-exploited-via-malicious-pdf-documents</guid><description>Researchers reveal a sophisticated Adobe Reader zero-day exploit used in the wild since late 2025, involving malicious PDF invoices to compromise systems.</description><pubDate>Thu, 09 Apr 2026 12:41:49 GMT</pubDate><category>Adobe Reader</category><category>Zero-Day</category><category>PDF Exploitation</category><category>EXPMON</category><category>Remote Code Execution</category></item><item><title>Apache ActiveMQ Classic RCE via Jolokia API: Patch Now</title><link>https://runtimerebel.com/blog/apache-activemq-classic-rce-via-jolokia-api-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/apache-activemq-classic-rce-via-jolokia-api-patch-now</guid><description>An unauthenticated Remote Code Execution flaw, present for 13 years, impacts Apache ActiveMQ Classic, allowing full system compromise. Immediate patching is critical.</description><pubDate>Thu, 09 Apr 2026 00:35:30 GMT</pubDate><category>Apache ActiveMQ Classic</category><category>RCE</category><category>Jolokia API</category><category>Remote Code Execution</category></item><item><title>Ninja Forms RCE via Arbitrary File Upload: Mitigation Guide</title><link>https://runtimerebel.com/blog/ninja-forms-rce-via-arbitrary-file-upload-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ninja-forms-rce-via-arbitrary-file-upload-mitigation-guide</guid><description>Hackers are actively exploiting a critical Ninja Forms vulnerability to upload arbitrary files and achieve RCE. Learn how to secure your WordPress site now.</description><pubDate>Wed, 08 Apr 2026 12:28:42 GMT</pubDate><category>WordPress</category><category>Ninja Forms</category><category>Remote Code Execution</category><category>Active Exploitation</category><category>File Upload</category></item><item><title>Quest KACE SMA CVE-2025-32975 Exploited — Critical Patch Guidance</title><link>https://runtimerebel.com/blog/quest-kace-sma-cve-2025-32975-exploited-critical-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/quest-kace-sma-cve-2025-32975-exploited-critical-patch-guidance</guid><description>Threat actors are exploiting a critical CVSS 10.0 vulnerability, CVE-2025-32975, in Quest KACE Systems Management Appliances exposed to the internet.</description><pubDate>Mon, 23 Mar 2026 08:25:12 GMT</pubDate><category>CVE-2025-32975</category><category>Quest Software</category><category>KACE SMA</category><category>Remote Code Execution</category><category>Active Exploitation</category></item><item><title>Microsoft March Patch Tuesday: 84 Flaws Fixed Including Public Zero-Days</title><link>https://runtimerebel.com/blog/microsoft-march-patch-tuesday-84-flaws-fixed-including-public-zero-days</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-march-patch-tuesday-84-flaws-fixed-including-public-zero-days</guid><description>Microsoft releases March security updates for 84 vulnerabilities, including 8 Critical flaws and 2 public zero-days. Patch now to prevent RCE and privilege escalation.</description><pubDate>Wed, 11 Mar 2026 12:19:24 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Windows Security</category><category>Zero-Day</category><category>Remote Code Execution</category></item><item><title>CVE-2025-0282: Ivanti Connect Secure Heap Overflow — Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2025-0282-ivanti-connect-secure-heap-overflow-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-0282-ivanti-connect-secure-heap-overflow-mitigation-guide</guid><description>Technical analysis of the Ivanti Connect Secure heap overflow (CVE-2025-0282) allowing unauthenticated RCE. Includes detection steps and patch guidance.</description><pubDate>Wed, 04 Mar 2026 04:37:49 GMT</pubDate><category>CVE-2025-0282</category><category>Ivanti</category><category>Connect Secure</category><category>Remote Code Execution</category><category>Heap Overflow</category></item><item><title>Trend Micro Patches Critical RCE Flaws in Apex One Security Platform</title><link>https://runtimerebel.com/blog/trend-micro-patches-critical-rce-flaws-in-apex-one-security-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/trend-micro-patches-critical-rce-flaws-in-apex-one-security-platform</guid><description>Trend Micro addresses two critical vulnerabilities, CVE-2023-32524 and CVE-2023-32525, in its Apex One platform that allow for remote code execution.</description><pubDate>Thu, 26 Feb 2026 20:15:07 GMT</pubDate><category>Trend Micro</category><category>Apex One</category><category>CVE-2023-32524</category><category>CVE-2023-32525</category><category>Remote Code Execution</category><category>Endpoint Protection</category></item><item><title>Claude Code Flaws Enable RCE &amp; API Key Exfiltration</title><link>https://runtimerebel.com/blog/claude-code-flaws-enable-rce-api-key-exfiltration</link><guid isPermaLink="true">https://runtimerebel.com/blog/claude-code-flaws-enable-rce-api-key-exfiltration</guid><description>Multiple security flaws in Anthropic&apos;s Claude Code AI coding assistant allow remote code execution and API credential theft via configuration mechanisms.</description><pubDate>Wed, 25 Feb 2026 20:15:32 GMT</pubDate><category>Claude Code</category><category>Anthropic</category><category>AI</category><category>Remote Code Execution</category><category>API Key Exfiltration</category><category>Vulnerability</category><category>Development Tools</category></item><item><title>VMware Aria Operations RCE Vulnerability Patched</title><link>https://runtimerebel.com/blog/vmware-aria-operations-rce-vulnerability-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/vmware-aria-operations-rce-vulnerability-patched</guid><description>Broadcom patched high-severity vulnerabilities in VMware Aria Operations, including an RCE flaw. Organizations must update immediately to mitigate risk.</description><pubDate>Wed, 25 Feb 2026 04:42:44 GMT</pubDate><category>VMware Aria Operations</category><category>RCE</category><category>Remote Code Execution</category><category>Broadcom</category><category>Vulnerability</category><category>Patch Management</category></item></channel></rss>