Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > remote code execution
#remote code execution

Critical ArangoDB Flaws Enable Login Bypass and Root-Level Code Execution

10 September 2026  |  dark6  |  Vulnerability

Two critical ArangoDB vulnerabilities can be chained to bypass authentication, manipulate database content and execute code with root privileges. Version 3.12.11 contains fixes, and exposed deployments should be...

>> read more

Critical Ivanti Flaws Expose ITSM and Mobile Management Systems to RCE and Admin Takeover

9 September 2026  |  dark6  |  Vulnerability

Ivanti has disclosed ten vulnerabilities across EPMM, Neurons for ITSM and Sentry, including unauthenticated remote-code-execution flaws rated 9.8. Cloud instances have been patched, while on-premises customers and Sentry...

>> read more

Ivanti Patches Nine Critical Flaws Across EPMM, Neurons for ITSM, and Sentry

9 September 2026  |  dark6  |  Vulnerability

Ivanti has disclosed a cluster of vulnerabilities spanning Endpoint Manager Mobile, Neurons for ITSM, and Sentry, several rated up to 9.9 in severity and capable of unauthenticated remote...

>> read more

Adobe Commerce Stores Face Active StyleSmuggler Zero-Day Attacks With No Official Patch

8 September 2026  |  dark6  |  Vulnerability

Attackers are exploiting an unauthenticated remote-code-execution flaw across current Magento Open Source and Adobe Commerce releases. Store operators should treat the incident as an active compromise risk and...

>> read more

Critical ASUS Control Center Chain Opens Managed Fleets to Root Takeover

8 September 2026  |  dark6  |  Vulnerability

A CVSS 10.0 flaw chain in ASUS Control Center Enterprise can reportedly give an unauthenticated network attacker a root shell and control of centrally managed devices. Organizations should...

>> read more

TP-Link Patches Archer AX55 Flaws Enabling Code Execution and Password Theft

5 September 2026  |  dark6  |  Vulnerability

TP-Link has fixed two Archer AX55 v4 vulnerabilities affecting EasyMesh and web login security. A local attacker could crash or potentially take over the router, while captured HTTP...

>> read more

Attackers Are Already Probing a Critical Flaw in Sangoma’s Switchvox VoIP Platform

4 September 2026  |  dark6  |  Vulnerability

A critical, unauthenticated SQL injection flaw in Sangoma Switchvox is being actively probed in the wild just weeks after a patch became available. With thousands of phone systems...

>> read more

Critical VMware Workstation and Fusion Bugs Let Attackers Break Out of the Virtual Machine

4 September 2026  |  dark6  |  Vulnerability

Broadcom has patched two vulnerabilities in VMware Workstation and Fusion that allow an attacker with access to a guest virtual machine to execute code on the underlying host,...

>> read more