Rce
Curated coverage and analysis in this editorial area.

Heimdall Data: Root RCE in Database Proxy Poses Infrastructure-Wide Risk
ZDI-26-479 reveals a directory traversal flaw in the uploadJar method of Heimdall Data Database Proxy. Authentication is required, but…

CISA Adds CVE-2026-8037 to KEV: 792 Exploit Attempts Against LoadMaster
CISA added CVE-2026-8037 to the Known Exploited Vulnerabilities catalog on August 7, 2026, after KEVIntel telemetry recorded 792 explo…

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility
Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…

Gitea: Critical File Read via Org-mode, RCE Risk with CVSS 9.8
CVE-2026-59774 affects Gitea 1.22.1 through 1.27.0: an unauthenticated attack exploits Org-mode markup to read arbitrary files and pot…

ZDI-26-520: Pre-auth RCE in Phoenix Contact EV Charging Controller
A path-validation flaw in the firmware-update endpoint of the Phoenix Contact CHARX SEC-3150 EV charging controller allows unauthentic…

TP-Link Omada: 15 Zero-Touch Provisioning Flaws Expose Enterprise Networks
Forescout discovered 15 vulnerabilities in TP-Link Omada's Zero-Touch Provisioning. An attack chain combining CVE-2025-7850 and CVE-20…

Sony XAV-9500ES: Bluetooth RCE Found at Pwn2Own, Fix Available
A heap-based buffer overflow in the AVRCP parser of the Sony XAV-9500ES allows remote code execution by an attacker with a paired Blue…

ZDI-26-463: RCE in GStreamer via MRF File, Patch Available
Trend Micro's Zero Day Initiative published advisory ZDI-26-463 detailing a remote code execution vulnerability in GStreamer's MRF par…

Apple Patches ImageIO RCE: Numeric Truncation Fixed in macOS Tahoe 26.6
CVE-2026-43780 in Apple's ImageIO framework allowed remote code execution via malicious textures. The fix is available today across ei…

CVE-2026-63077: Critical RCE in JetBrains TeamCity, CVSS 9.8
JetBrains has patched a deserialization vulnerability in TeamCity On-Premises with a CVSS 9.8 score. The unauthenticated RCE via the a…

WatchGuard FireWare OS: Directory Traversal in sigd Service Opens Path to Code Execution
A directory traversal vulnerability in the sigd service of WatchGuard FireWare OS allows an authenticated remote attacker to create ar…

CVE-2026-66066: Unauthenticated RCE in Rails via Active Storage, Public Metasploit Exploit
A critical Ruby on Rails vulnerability enables arbitrary file read and unauthenticated RCE through Active Storage when using libvips.…