Rce
Curated coverage and analysis in this editorial area.

CVE-2026-9787: RCE in Quest NetVault Backup with SYSTEM Execution
A vulnerability in the NVBULogDaemon component of Quest NetVault Backup enables remote code execution with authentication bypass. The…

ZDI-26-377: XSS in NetVault Backup Enables Auth Bypass and SYSTEM RCE Chain
An XSS flaw in the viewclient page of Quest NetVault Backup lets a remote attacker bypass authentication and, when chained with other…

Cursor Hit by Two Critical CVEs: RCE and Zero-Click via Sandbox Prompt Injection
Two vulnerabilities in Cursor rated CVSS 9.8 allow sandbox escape and remote code execution without user interaction. The fix is avail…

Langflow RCE Exploited for Miner Worm: 19-Day Campaign
CVE-2026-33017: Commodity operators exploit exposed AI endpoints to deploy Lambsys, an SSH worm that compromises entire enterprise inf…

Public PoC for CVE-2026-55200: libssh2 at Risk of RCE
A working proof-of-concept for CVE-2026-55200, a critical CVSS 9.2 vulnerability in libssh2, was released on June 23, 2026. The pre-au…

PTC Windchill: First In-the-Wild Exploitation of a PLM System
CVE-2026-12569 is the first PTC vulnerability added to the CISA KEV catalog. Active exploitation with persistent JSP webshells, patche…

Adobe Reader: Patch Now for CVE-2026-27278, RCE via PDF
Adobe has released APSB26-26 for CVE-2026-27278, a Use-After-Free vulnerability in Acrobat Reader DC that enables remote code executio…

FlowiseAI CSV Agent RCE: Arbitrary Python Code Execution with Authentication Bypass
ZDI-26-365 discloses a remote code execution vulnerability in FlowiseAI's CSV Agent: Python code injection via customReadCSV with auth…

CVE-2026-9779: RCE in ATEN Unizon via Flawed Cryptographic Signature Check
The ZDI-26-383 vulnerability enables remote code execution with SYSTEM privileges by exploiting a signature verification error in ATEN…

Unraid: Command Injection in ToggleState.php Enables RCE
CVE-2026-9773 in the Unraid web server: command injection in ToggleState.php allows authenticated remote code execution. CVSS 8.8, fix…

Samsung rlottie: RCE via Integer Truncation, Open-Source Patch Available
A short-vs-int type error in Samsung's rlottie graphics library enables remote code execution through a malicious animation file. A pa…

Atril RCE via EPUB: Patch Available Nine Days Before Disclosure
ZDI-26-360: A heap buffer overflow in the MATE Desktop's Atril document viewer enables remote code execution through malicious EPUB fi…