Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > remote code execution
#remote code execution

Old Microsoft SQL Server RCE Returns in Active Attacks, Triggering CISA Forensic Mandate

28 August 2026  |  dark6  |  Vulnerability

CISA says attackers are exploiting CVE-2019-1068, a Microsoft SQL Server remote-code execution flaw, and has ordered both remediation and forensic triage. Database owners should patch exposed systems, review...

>> read more

Critical Next.js Flaws Put Windows Servers and AVIF Image Processing at Risk of RCE

27 August 2026  |  dark6  |  Vulnerability

Two critical Next.js vulnerabilities may enable unauthenticated remote code execution through Windows path handling and AVIF image processing. Vercel fixed both issues in Next.js 15.5.24 and 16.3.3, with...

>> read more

Legacy VNC Login on macOS Screen Sharing Could Hand Attackers a Root Shell

17 August 2026  |  dark6  |  Vulnerability

Researchers found that macOS's Screen Sharing service kept its file-transfer helpers running as root even when a session was authenticated with nothing more than a shared VNC password....

>> read more

Citrix NetScaler Root-Level RCE Flaw Goes Public With Working Exploit Code

15 August 2026  |  dark6  |  Vulnerability

A publicly released proof-of-concept shows how a pre-authentication heap overflow in Citrix NetScaler ADC and Gateway can be turned into unauthenticated, root-level remote code execution. There is no...

>> read more

Unpatched GeoServer Zero-Day Under Active Attack as Researchers Warn of RCE Risk

15 August 2026  |  dark6  |  Vulnerability

A newly disclosed, unpatched SQL injection flaw in the open-source mapping platform GeoServer is already being probed by attackers just hours after it went public. Under certain database...

>> read more

New WordPress Flaw Turns a Failed Login Attempt Into Full Server Takeover

9 August 2026  |  dark6  |  Vulnerability

A newly disclosed WordPress vulnerability, dubbed XSS2Shell and tracked as CVE-2026-64638, chains a decade-old parsing quirk in the login page into full remote code execution, putting an estimated...

>> read more

One Click, Total Takeover: The RCE Bug That Hid Inside Cursor, VS Code, and Google Antigravity

5 August 2026  |  dark6  |  Vulnerability

Security researchers at AISLE uncovered a one-click remote code execution flaw shared by Cursor, Microsoft VS Code, and Google Antigravity, all three built on the same underlying codebase....

>> read more

Six Ways to Break Flowise: New RCE Chain Puts AI Workflow Servers at Risk

5 August 2026  |  dark6  |  Vulnerability

Security researchers at Elttam disclosed six separate remote code execution flaws in the Flowise AI workflow platform, spanning CSV processing, sandboxed JavaScript, and database configuration. Several of the...

>> read more