Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > remote code execution
#remote code execution

Click2Shell Chain Turns One Malicious Link Into WordPress Server Takeover

19 September 2026  |  dark6  |  Vulnerability

WordPress has fixed a theme-preview weakness that can silently install an attacker-selected theme when an administrator opens a crafted link. Paired with unsafe pre-activation code in a theme,...

>> read more

Critical Check Point Login Flaw Exposes Management Servers to Root Takeover

17 September 2026  |  dark6  |  Vulnerability

Check Point has issued an urgent fix for CVE-2026-91843, a remotely exploitable buffer overflow that can grant root privileges before authentication. Administrators should deploy and verify the LivePatch...

>> read more

Chinese Hacking Crew Weaponizes Critical Gitea Flaw to Hijack Self-Hosted Git Servers Worldwide

16 September 2026  |  dark6  |  Vulnerability

A Chinese-speaking intrusion set tracked as Red Heron is exploiting a critical remote-code-execution bug in self-hosted Gitea instances, deploying a custom Linux implant and rootkit against victims in...

>> read more

Dell ObjectScale CVSS 10 Flaw Exposes Enterprise Storage to Remote Takeover

14 September 2026  |  dark6  |  Vulnerability

Dell has fixed a maximum-severity ObjectScale vulnerability that could let an unauthenticated remote attacker execute code on exposed storage systems. Organizations should upgrade quickly, reduce management-plane exposure and...

>> read more

Critical CSF Flaw Exposes cPanel Servers to Unauthenticated Command Execution

12 September 2026  |  dark6  |  Vulnerability

A critical flaw in ConfigServer Security & Firewall can let remote attackers execute commands through its optional MESSENGER service without logging in. Administrators using CSF 14.00 through 16.29...

>> read more

AI Agent Swarm Exploits PaperCut Flaws Across 440 Servers Worldwide

10 September 2026  |  dark6  |  Vulnerability

A Russian-speaking operator used hundreds of autonomous AI agents to compromise 440 PaperCut servers across 48 countries. Although only a fraction reached domain administrator, the campaign shows how...

>> read more

Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution

10 September 2026  |  dark6  |  Vulnerability

Two critical ArangoDB vulnerabilities can be chained to bypass authentication, manipulate database content and execute code with root privileges. Version 3.12.11 contains fixes, and exposed deployments should be...

>> read more

Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover

9 September 2026  |  dark6  |  Vulnerability

Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...

>> read more