Rce
Curated coverage and analysis in this editorial area.

LiteLLM CVE-2026-42271: CISA Confirms Active Exploitation of CVSS 10.0 RCE Chain
CISA has added CVE-2026-42271 to its KEV catalog, confirming active exploitation of a command injection vulnerability in LiteLLM. When…

Gogs Patches Critical CVSS 9.4 Zero-Day; Over 2,300 Servers Exposed
Gogs 0.14.3 addresses a critical argument injection zero-day in the git rebase function. Default configurations allowing open registra…

Gogs Zero-Day RCE: CVSS 9.4 Critical Flaw Remains Unpatched After Two Months
A critical argument injection vulnerability in Gogs' git rebase functionality enables remote code execution. Despite disclosure to mai…

CISA Adds Critical Magento Mirasvit RCE to KEV Catalog, Sets 72-Hour Patch Deadline
CISA added CVE-2026-45247 to its Known Exploited Vulnerabilities (KEV) catalog on June 3, 2026. The flaw is a PHP object injection in…

Everest Forms Pro: Critical RCE Exploited Months After Patch Release
Threat actors are actively exploiting CVE-2026-3300 in the Everest Forms Pro WordPress plugin. Although version 1.9.13 has been availa…

Microsoft Patched This Pwn2Own Edge RCE Weeks Ago—But the Disclosure Gap Leaves Enterprises Exposed
CVE-2026-45495: A directory traversal vulnerability in Microsoft Edge feedback logs enables remote code execution. While Microsoft rel…

CVE-2026-48095: 7-Zip NTFS Handler Heap Overflow
A heap overflow in 7-Zip’s NTFS handler allows for RCE via crafted files. The vulnerability involves signature-based file routing that…

Kemp LoadMaster API Flaw Enables Authenticated RCE: CVSS 8.8 Vulnerability Patched
CVE-2026-3517 in Progress Software Kemp LoadMaster allows authenticated users to execute arbitrary code via command injection in the c…

CVE-2026-0826: Root RCE Vulnerability Hits HP Poly Enterprise VoIP Phones
A critical stack-based buffer overflow in HP Poly Voice's SDP parsing allows unauthenticated remote code execution with root privilege…

Microsoft Patched a Critical SharePoint RCE but Omitted the CVE from Official Documentation
CVE-2026-45659, a CVSS 8.8 SharePoint Server RCE, was missing from Microsoft’s May 2026 security update list. While the patch was dist…

Critical Flowise RCE: Exploit Code Released for CVSS 9.9 Vulnerability
Obsidian Security has published proof-of-concept exploit code for CVE-2026-40933, a critical RCE vulnerability in Flowise. The flaw le…

FortiClient EMS: EKZ Infostealer May Target VPN Management Channels
CVE-2026-35616 (CVSS 9.8): Compromised FortiClient EMS platforms could be transformed into malware delivery vehicles. Attacks in May 2…