Posts Tagged ‘RCE’
TeamCity CVE-2026-63077 RCE: Unauthenticated CI/CD Takeover
TeamCity CVE-2026-63077 RCE lets an unauthenticated attacker send a single crafted request to a TeamCity On-Premises server and execute operating system commands — no login, no valid session, no user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on August 5 with a three-day remediation deadline, and exploitation is now active in the…
Read MoreGitLab Oj Spill RCE Exploit Goes Public
The GitLab Oj Spill RCE is now public: a working exploit chain and full technical writeup were released on July 24 for a remote-code-execution flaw that GitLab quietly patched six weeks earlier, on June 10. If your self-managed GitLab instance is still on 18.10.7 or older, any developer who can push a commit can now…
Read Morewp2shell WordPress RCE: Patch Now
wp2shell WordPress RCE is now a two-CVE chain in CISA’s Known Exploited Vulnerabilities catalog — and it lets a completely unauthenticated attacker execute code on a default WordPress install with no plugins involved. If you run self-hosted WordPress and haven’t confirmed the July 17 auto-update landed, check today. What Happened wp2shell WordPress RCE combines two…
Read MoreCVE-2026-50522 SharePoint RCE: Patching Isn’t Enough
CVE-2026-50522 SharePoint RCE is now the third actively exploited remote code execution flaw hitting Microsoft’s on-premises collaboration platform in three weeks — and this one lets attackers steal cryptographic machine keys that remain valid long after the server is patched. If you run SharePoint Server 2016, 2019, or Subscription Edition on-premises, patching is no longer…
Read MoreServiceNow CVE-2026-6875 RCE: Sandbox Escape Exploited
ServiceNow CVE-2026-6875 RCE is now being actively exploited: a critical, unauthenticated sandbox-escape vulnerability in the ServiceNow AI Platform is under attack barely a week after the vendor shipped a fix, and ServiceNow’s own advisory has not yet caught up with independent confirmation of the exploitation. What Happened ServiceNow CVE-2026-6875 RCE traces back to a sandbox-escape…
Read More
