Topic
Remote Code Execution
15 reports tagged Remote Code Execution, spanning news and vulnerability coverage.
Articles tagged Remote Code Execution
-
NewsCISA confirms attacks on WordPress core file inclusion flaw
CISA added a WordPress core file inclusion bug that can lead to code execution to its KEV catalog, set a three-day federal deadline and required forensic triage.
-
Vulnerability2 CVEs: Check Point Quantum Security Gateway & Check Point Quantum Security Management (CVE-2026-85102)
Two CVSS 9.8 Check Point flaws, a VPN-negotiation RCE in Quantum Security Gateway and a pre-auth upload bug in Management, were CISA KEV-listed September 22.
-
VulnerabilityF5 BIG-IP APM Vulnerability (CVE-2026-94127)
CVE-2026-94127 is a CVSS 9.8 heap overflow in F5 BIG-IP APM enabling unauthenticated RCE when APM acts as an OAuth Authorization Server; CISA KEV-listed.
-
VulnerabilityAjax.NET Professional Insecure Deserialization (CVE-2021-23758)
CVE-2021-23758 is a 2021 CVSS 8.1 deserialization RCE in Ajax.NET Professional, added to CISA KEV in August 2026.
-
VulnerabilityGitea Code Injection (CVE-2026-60004)
CVE-2026-60004 is a CVSS 9.8 code injection flaw in Gitea allowing RCE via the diffpatch API, confirmed exploited by both CISA and VulnCheck KEV.
-
VulnerabilityKopia Command Injection (CVE-2026-45695)
CVE-2026-45695 is a CVSS 9.8 OS command injection flaw enabling unauthenticated RCE in the Kopia backup tool before 0.23.0, reported exploited by VulnCheck KEV.
-
VulnerabilityLangflow Code Injection (CVE-2026-0768)
CVE-2026-0768 is a CVSS 9.8 code injection flaw in Langflow allowing unauthenticated remote code execution as root, reported exploited by VulnCheck KEV.
-
VulnerabilityMicrosoft SQL Server Vulnerability (CVE-2019-1068)
CVE-2019-1068 is a 2019 CVSS 8.8 remote code execution flaw in Microsoft SQL Server, added to CISA KEV in August 2026 for newly observed exploitation.
-
VulnerabilityProfilePress Vulnerability (CVE-2026-66047)
CVE-2026-66047 is a CVSS 8.1 unauthenticated RCE in the ProfilePress WordPress plugin, reported exploited by VulnCheck alone.
-
VulnerabilitySPIP Code Injection (CVE-2026-77806)
CVE-2026-77806 is a CVSS 9.8 code injection flaw in the SPIP CMS allowing unauthenticated RCE, with NVD itself noting exploitation in the wild.
-
VulnerabilityThe Events Calendar Code Injection (CVE-2026-78159)
CVE-2026-78159 is a CVSS 9.8 code injection flaw enabling unauthenticated RCE in WordPress plugin The Events Calendar, reported exploited by VulnCheck KEV.
-
VulnerabilityThe Events Calendar Insecure Deserialization (CVE-2026-78006)
CVE-2026-78006 is a CVSS 9.8 deserialization flaw enabling unauthenticated RCE in WordPress plugin The Events Calendar, reported exploited by VulnCheck KEV.
-
VulnerabilityvBulletin Vulnerability (CVE-2026-61511)
CVE-2026-61511 is a CVSS 9.8 eval injection flaw in vBulletin allowing unauthenticated RCE, reported exploited by VulnCheck with a near-maximum EPSS score.
-
VulnerabilityGift Cards For WooCommerce Pro Vulnerability (CVE-2026-15039)
CVE-2026-15039 is a CVSS 9.8 unrestricted file upload flaw in a WooCommerce gift-card plugin allowing unauthenticated RCE, reported exploited by VulnCheck.
-
VulnerabilityWP Compress Code Injection (CVE-2026-73343)
CVE-2026-73343 is a CVSS 10.0 code injection flaw enabling unauthenticated RCE in WP Compress before 7.20.01, reported as exploited by VulnCheck's KEV catalog.