// 2 CRITICAL · 6 ZERO-DAY · 16 CVE · 13 EXPLOIT · 2 ADVISORY IN THE LAST 24H
rceCRITICAL

Ivanti Confirms Post-Auth RCE in EPMM Under Active Exploitation

Ivanti has warned of targeted attacks exploiting CVE-2026-6973, a post-authentication RCE flaw in on-premise EPMM. The vulnerability,…

May 16, 2026views - 141

rceCVE

CVE-2026-3854: Critical GitHub RCE Leaves 88% of On-Premise Servers Exposed

Wiz Research has detailed CVE-2026-3854, a critical RCE vulnerability in GitHub’s internal Git pipeline. While GitHub.com was patched…

May 13, 2026views - 201

rceCRITICAL

MetInfo CMS Under RCE Attack: Critical Vulnerability CVE-2026-29014 Actively Exploited

Threat actors are weaponizing CVE-2026-29014, an unauthenticated RCE vulnerability (CVSS 9.8) in MetInfo CMS. Activity spiked on May 1…

May 11, 2026views - 234

rceCVE

CVE-2026-3854: Critical RCE Vulnerability in GitHub Triggered via Single ‘git push’

A specifically crafted git push command can execute remote code on GitHub.com and GitHub Enterprise Server. While the cloud environmen…

May 11, 2026views - 538

rceCRITICAL

Critical GitHub RCE: Single Git Push Triggers Backend Code Execution

CVE-2026-3854 allows RCE on GitHub.com and GHES via a single git push. The discovery, facilitated by AI-assisted reverse engineering o…

May 07, 2026views - 236

rceCVE

CVE-2026-22679: Critical Weaver E-cology RCE Under Active Attack Since March

An exposed debug endpoint in Weaver E-cology 10.0 allows unauthenticated remote code execution. Attacks have been detected since March…

May 05, 2026views - 204