Rce

20 posts tagged with “Rce”

Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)
cvelibreofficelibreoffice-calc

Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)

How to fix CVE-2026-63277: upgrade LibreOffice to 26.2.5 or 26.8.0. A saved Calc external data link could load a remote Java driver on open; five sibling file-read, file-write and SSRF bugs are fixed in the same release.

Oct 5, 2026
Read
Zammad session fixation to root hits CISA KEV
cvezammadhelpdesk

Zammad session fixation to root hits CISA KEV

How to fix CVE-2026-102489: upgrade Zammad to 7.2.0 (leave 6.5 EOL trains; chain with CVE-2026-102490)

Oct 2, 2026
Read
Unsloth RCE: malicious Hugging Face model config.json injects code
cveunslothunsloth-zoo

Unsloth RCE: malicious Hugging Face model config.json injects code

How to fix CVE-2026-93348: upgrade unsloth-zoo to 2026.8.14+ and unsloth to 2026.8.20+

Sep 28, 2026
Read
BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)
cvenetscalercitrix

BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)

How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23

Sep 27, 2026
Read
WordPress page template include hits CISA KEV
cvewordpresslfi

WordPress page template include hits CISA KEV

How to fix CVE-2026-87902: upgrade WordPress to 7.1.2 (or your branch patch).

Sep 25, 2026
Read
SharePoint code injection hits CISA KEV
cvesharepointmicrosoft

SharePoint code injection hits CISA KEV

How to fix CVE-2026-65660: upgrade SharePoint Server to the August 2026 fixed builds (SE 16.0.19725.20522 / 2019 16.0.10417.20198 / 2016 16.0.5565.1001)

Sep 25, 2026
Read
F5 BIG-IP APM OAuth RCE hits CISA KEV
cvef5big-ip

F5 BIG-IP APM OAuth RCE hits CISA KEV

CVE-2026-94127 affects BIG-IP APM virtual servers configured as OAuth Authorization Servers. Apply the F5 engineering hotfix for your branch.

Sep 22, 2026
Read
BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)
ghsacvenextjs

BREAKING: CVE-2026-94545 Next.js next/og ImageResponse RCE (GHSA-vcvr-r3jv-pc5j)

How to fix CVE-2026-94545: upgrade next to 16.3.6 (15.5.26 hardening if you stay on 15.x)

Sep 22, 2026
Read
Temporal write access can run shell on your Worker Service host
cvetemporalrce

Temporal write access can run shell on your Worker Service host

How to fix CVE-2026-89139: upgrade Temporal Server to 1.31.3 or 1.30.7

Sep 21, 2026
Read
BREAKING: Unbound DNSKEY digest overflow can RCE your resolver (1.26.1)
cveunbounddns

BREAKING: Unbound DNSKEY digest overflow can RCE your resolver (1.26.1)

How to fix CVE-2026-81642: upgrade Unbound to 1.26.1

Sep 16, 2026
Read
BREAKING: CVE-2026-0310 PAN-OS XML overflow gives unauth root on PA-Series
cvepan-ospalo-alto

BREAKING: CVE-2026-0310 PAN-OS XML overflow gives unauth root on PA-Series

How to fix CVE-2026-0310: upgrade PAN-OS to the fixed hotfix for your train (for example 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, 10.2.18-h10). Unauth XML to management web or dataplane can root PA-Series firewalls.

Sep 10, 2026
Read
CVE-2026-75021: fastify-cli debug-host bind can expose Inspector RCE
cvefastify-clinodejs

CVE-2026-75021: fastify-cli debug-host bind can expose Inspector RCE

How to fix CVE-2026-75021: upgrade fastify-cli to 8.0.1

Sep 8, 2026
Read
BREAKING: CVE-2026-75650 lets unauth callers run code on Adobe Commerce and Magento
cveadobe-commercemagento

BREAKING: CVE-2026-75650 lets unauth callers run code on Adobe Commerce and Magento

How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 from repo.magento.com, then rotate the Commerce encryption key and every credential it protected

Sep 7, 2026
Read
BREAKING: CVE-2026-75650 is unauthenticated RCE in Adobe Commerce and Magento, already exploited
cveadobe-commercemagento

BREAKING: CVE-2026-75650 is unauthenticated RCE in Adobe Commerce and Magento, already exploited

How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 for Adobe Commerce / Magento Open Source, then rotate the encryption key and all protected credentials

Sep 7, 2026
Read
BREAKING: CVE-2026-9317 lets anyone who can reach your Nango runner run code
cvenangorce

BREAKING: CVE-2026-9317 lets anyone who can reach your Nango runner run code

How to fix CVE-2026-9317: upgrade nango to 0.71.6 and set NANGO_INTERNAL_AUTH_REQUIRED=true

Sep 4, 2026
Read
BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH
cvewatchguardfireware

BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH

How to fix CVE-2026-19315: upgrade Fireware OS to 2026.2.2, 12.12.2, or 12.5.20

Aug 28, 2026
Read
CVE-2026-81934: Redis TLS pending-list use-after-free
cveredistls

CVE-2026-81934: Redis TLS pending-list use-after-free

CVE-2026-81934 is High (CVSS 7.5). Upgrade Redis Open Source to 8.10.1, 8.8.2, 8.6.6, 8.4.6, 8.2.9, 7.4.11, 7.2.16, or 6.2.24.

Aug 27, 2026
Read
CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
cvechainlitmcp

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

Aug 25, 2026
Read
Next.js August 2026 fixes: CVE-2026-75604 Windows RCE and separate AVIF issue
cvenextjsrce

Next.js August 2026 fixes: CVE-2026-75604 Windows RCE and separate AVIF issue

CVE-2026-75604 is the Windows incremental-cache path traversal. Upgrade Next.js to 15.5.24 or 16.3.3. The AVIF optimizer issue is separate.

Aug 25, 2026
Read
CVE-2026-18420: OpenSearch Dashboards TSVB Prototype Pollution RCE
cvesecurityopensearch

CVE-2026-18420: OpenSearch Dashboards TSVB Prototype Pollution RCE

How to fix CVE-2026-18420: upgrade OpenSearch Dashboards to 3.8.0. Authenticated TSVB metrics JSON prototype pollution RCE. Affects OSS and AWS Managed >=3.0.0 <3.8.0.

Aug 21, 2026
Read