Tag
A remote code execution vulnerability has been found in Unitree robots, and it is wormable, enabling attackers to infect and control multiple robots.
This CVE describes a prototype pollution vulnerability in n8n that can be exploited for remote code execution through a Git node gadget chain.
Researchers used publicly available AI models to discover a critical zero-click, memory-corruption vulnerability in Zoom's annotation feature, allowing remote code execution on all meeting participants across all platforms. Zoom has issued fixes, but the research highlights how AI is lowering the barrier to nation-state-level exploits.
This article breaks down the MCP security attack chain behind CVE-2025-53773, where a single prompt injection lets a developer agent modify its own configuration and achieve remote code execution. It details the hop-by-hop escalation and the key control that stops it.
A critical remote code execution vulnerability (CVE-2026-66066) has been discovered in Ruby on Rails' Active Storage when using the default Vips image processor, affecting Rails 7.x and 8.x default configurations. Patches have been released and immediate upgrading is recommended.
Research reveals a critical vulnerability in Azure Cosmos DB's Gremlin API that could have allowed attackers to compromise all databases in the service, including Microsoft's internal ones. Microsoft has fully remediated the issue and no customer action is required.
A heap buffer overflow vulnerability in Dnsmasq (CVE-2026-2291) allows remote code execution via a malicious upstream DNS server. The issue was introduced in version 2.73 and fixed in 2.92rel2 and 2.93.
A detailed write-up from ProjectDiscovery detailing how they discovered a critical SQL injection vulnerability in Apple's Book Travel portal via Masa/Mura CMS and achieved Remote Code Execution.
Hackers are actively exploiting a critical remote code execution vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, affecting versions up to 1.9.12. The flaw allows unescaped form values to be passed to eval(), enabling full site compromise. Wordfence urges immediate plugin updates.
A critical heap buffer overflow vulnerability in Nginx's rewrite module (CVE-2026-42945) allows unauthenticated remote code execution, with a proof-of-concept exploit released. The bug affects Nginx versions from 0.6.27 to 1.30.0 and various Nginx Plus releases.
Researchers used an autonomous system to discover a critical heap buffer overflow vulnerability in NGINX's rewrite module (CVE-2026-42945), present since 2008, enabling remote code execution. Multiple CVEs were confirmed by NGINX.
A security researcher discovered a Remote Code Execution (RCE) vulnerability in Claude Code caused by improper parsing of deeplink settings, allowing arbitrary command injection via hooks. The issue has been resolved in version 2.1.118.
This article details the discovery and disclosure of CVE-2025-5518 (React2Shell), a critical remote code execution vulnerability in React Server Components, explaining how researchers bypassed Flight protocol validations to access object prototypes.
Security researcher Lachlan discovered and reported a critical remote code execution vulnerability dubbed "React2Shell" in React's Server Components protocol to Meta on November 30, 2025. Meta released a fix and public advisory (CVE-2025-55182) on December 3, urging developers to update immediately as the vulnerability affected millions of websites built with React/Next.js.