Rce
Curated coverage and analysis in this editorial area.

Synology DS925+: Root RCE via Redis MailPlus, Patch Available
ZDI-26-423 reveals a cryptographic flaw in the Synology DS925+ MailPlus Redis component. Network-adjacent attackers achieve unauthenti…

Samsung rlottie: RCE Bug in Lottie Files Masked by a "Medium" CVSS
A numeric truncation flaw in Samsung rlottie enables remote code execution via malicious Lottie animations. The CVSS 5.5 rating unders…

Autel EV Charger: Remote RCE via OCPP WebSocket, Discovered at Pwn2Own
The ZDI-26-437 vulnerability in the Autel MaxiCharger AC Elite Home enables pre-authentication remote code execution via an integer un…

CVE-2026-6071: RCE in Rockwell Arena Simulation via Malicious DOE File
Trend Micro's Zero Day Initiative disclosed CVE-2026-6071, an out-of-bounds write in Rockwell Automation Arena Simulation's DOE file p…

Zimbra 10.1.20 Patches Critical Command Injection Among Nine Vulnerabilities
Zimbra released version 10.1.20 of the Collaboration Suite on July 20, 2026, fixing nine security flaws. The most severe is a command…

Oracle Patches PeopleSoft Flaw That Emptied 300 Servers in Six Weeks
The July 2026 Critical Patch Update fixes CVE-2026-35278 and CVE-2026-35273, the pre-auth RCE and privilege-escalation chain exploited…

WordPress: wp2shell Chain Exploited in the Wild 24 Hours After AI-Assisted Discovery
The wp2shell vulnerability chain in WordPress Core was discovered using AI for roughly $25, published July 17, and actively exploited…

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter
CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Patch Day: Mozilla Confirms Public Exploits for Firefox as Adobe and VMware Ship CVSS 9+ Fixes
On July 15, 2026, four vendors released critical updates simultaneously. Mozilla broke with standard practice by explicitly confirming…

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available
ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

SharePoint Critical RCE via Cryptographic Signature Flaw: The Token Danger
CVE-2026-50522 enables unauthenticated remote code execution on SharePoint Server by bypassing cryptographic verification on session t…

SharePoint On-Premises Under Attack: Three Days to Patch Actively Exploited RCE
Microsoft confirmed active exploitation of CVE-2026-58644 in SharePoint Server on-premises. CISA added the flaw to the KEV catalog wit…