Posts Tagged ‘RCE’
Adobe Commerce Magento RCE Vulnerability Under Attack
An Adobe Commerce Magento RCE vulnerability nicknamed StyleSmuggler let attackers plant Rust-based Linux backdoors on live webshops for at least five days before Adobe shipped a fix. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, the flaw requires no authentication and has already been used to backdoor real merchant sites, not just proof-of-concept…
Read MoreSonicWall SMA1000 RCE Vulnerability: Patch Now
A new SonicWall SMA1000 RCE vulnerability is under active exploitation: an unauthenticated server-side request forgery chained with an OS command injection lets an attacker take full root-level control of the appliance with no login required. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, with a federal deadline of September 5,…
Read MorePaperCut RCE Vulnerability Actively Exploited
A newly disclosed PaperCut RCE vulnerability is already being exploited against PaperCut NG and PaperCut MF print management servers worldwide. PaperCut confirmed active attacks on August 27, 2026, shipped an emergency patch within hours, then replaced it with a hardened second patch the next morning after researchers found the first fix incomplete. Every organization running…
Read MoreMicrosoft Entra ID RCE Vulnerability Exploited
Microsoft disclosed a maximum-severity Microsoft Entra ID RCE vulnerability on August 20, 2026, and confirmed the flaw was already being exploited in the wild before the advisory went public. CVE-2026-69836 carries a CVSS score of 10.0, needs no authentication and no user interaction, and sits in the identity backbone underneath Microsoft 365, Azure AD sign-in,…
Read MoreWindows IKE RCE: Patched in April, Exploited Now
CVE-2026-33824 Windows IKE RCE has gone from a quietly patched bug in April to an actively exploited flaw four months later: CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026, giving U.S. federal agencies until August 21 to patch — while Microsoft’s own advisory still lists it as not exploited. What…
Read More
