Rce
Curated coverage and analysis in this editorial area.

F5 Patches Critical NGINX Flaws: Conditional RCE at CVSS 9.2 Demands Immediate Action
F5 released out-of-band patches on June 17, 2026 for two critical vulnerabilities in NGINX Open Source. Both carry a CVSS v4.0 score o…

AutoJack: A Single Web Page Hijacks AI Agents to Execute Code on the Host
Microsoft Security has disclosed AutoJack, a three-vulnerability chain in AutoGen Studio that turns browsing-capable AI agents into ve…

Splunk Enterprise PostgreSQL Sidecar Bug (CVSS 9.8) Enables Unauthenticated RCE
CVE-2026-20253 allows unauthenticated remote code execution on Splunk Enterprise. The web proxy on port 8000 exposes an internal Postg…

CISA Adds Joomla JCE to KEV: Pre-Auth RCE, CVSS 10.0
CISA added CVE-2026-48907 to the Known Exploited Vulnerabilities catalog on June 16, 2026, confirming active exploitation of a pre-aut…

Vertex AI SDK: Cross-Tenant Bucket Squatting Enabled RCE
Google Cloud Vertex AI SDK versions 1.139.0 through 1.140.0 were vulnerable to cross-tenant bucket squatting leading to remote code ex…

ZDI-26-356: Apache Reverse Proxy Betrayed by AJP Backend
CVE-2026-34032 in mod_proxy_ajp lets a compromised AJP backend read out of bounds, with potential escalation to RCE via vulnerability…

Adobe Acrobat Reader: UAF in Annotation Parser Enables RCE via Malicious PDF
CVE-2026-27220: use-after-free in Adobe Acrobat Reader DC's Annotation parser, CVSS 7.8. Patch available, no known in-the-wild exploit…

Langflow CVE-2026-5027: RCE Under Active Exploitation with 7,000 Instances Exposed
A critical path traversal vulnerability in Langflow is being exploited in the wild. CVE-2026-5027 (CVSS 8.8) enables unauthenticated r…

LangGraph Vulnerability Chain Grants RCE via AI Agent Persistence
Check Point Research has uncovered a SQL injection and deserialization chain in LangGraph that enables RCE on self-hosted deployments.…

ZDI-26-360: RCE Vulnerability in MATE’s Atril Document Viewer Patched in Version 1.26.4
A heap-based buffer overflow in the Atril EPUB parser (MATE Desktop) allows for remote code execution. The vulnerability is addressed…

Kemp LoadMaster: Critical Pre-Auth RCE (CVSS 9.8) Triggers Urgent Patching
Progress Software has released a critical patch for Kemp LoadMaster following the coordinated disclosure of three pre-authentication R…

Adobe USD Plugin: GLTF Heap Overflow Enables Remote Code Execution
Adobe patches CVE-2026-48292, a CVSS 7.8 heap overflow in the usdGltf plugin. While no in-the-wild exploits are reported, 3D productio…