Related Threat Clusters
-
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
CVE-2026-47668: Unauthenticated RCE Vulnerability in DbGate
DbGate's JSON script runner has a critical vulnerability (CVE-2026-47668) that allows unauthenticated remote code execution via the functionName parameter in JSON script assign commands. The vulnerability arises from…
2 articles · Updated June 6, 2026 -
Monsta FTP Remote Code Execution Vulnerability CVE-2025-34299 Exploited
A remote code execution vulnerability, CVE-2025-34299, has been identified in Monsta FTP. This zero-day exploit allows attackers to execute arbitrary code remotely, affecting users of the software. The situation has led…
2 articles · Updated November 10, 2025 -
Critical SmarterMail Vulnerability Allows Remote Code Execution
A critical remote code execution vulnerability, CVE-2025-52691, has been found in SmarterTools' SmarterMail solution. This flaw has a maximum CVSS score of 10.0, indicating its severe potential impact on systems using…
2 articles · Updated January 9, 2026 -
HPE OneView Software Vulnerability Enables Remote Code Execution
Hewlett Packard Enterprise (HPE) has addressed a critical vulnerability in its OneView software, identified as CVE-2025-37164, which allows attackers to execute arbitrary code remotely without authentication. This flaw…
15 articles · Updated December 18, 2025 -
SAP Releases January 2026 Security Patches for Critical Vulnerabilities
On January 13, 2026, SAP issued 17 new security notes during its monthly Security Patch Day, addressing critical injection flaws and remote code execution vulnerabilities in key products. Organizations are urged to…
6 articles · Updated January 13, 2026 -
MonikerLink RCE Vulnerability in Outlook Exploited with PoC Release
The MonikerLink vulnerability in Microsoft Outlook allows for remote code execution via malicious hyperlinks in emails. Discovered by Check Point Research, a proof-of-concept exploit has been released, potentially…
2 articles · Updated December 1, 2025 -
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
IBM Langflow OSS is facing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-9198, which allows unauthenticated attackers to execute arbitrary code on default deployments. The vulnerability…
14 articles · Updated August 5, 2026 -
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
On June 17, 2026, F5 released emergency patches for two critical vulnerabilities in NGINX, CVE-2026-42530 and CVE-2026-42055. These vulnerabilities affect NGINX Open Source, NGINX Plus, and related products, allowing…
24 articles · Updated June 18, 2026 -
Critical Remote Code Execution Flaw Discovered in Flowise MCP Server
Flowise has disclosed a critical remote code execution vulnerability, tracked as CVE-2026-56274, affecting versions prior to 3.1.2 of its Custom MCP Server feature. The flaw allows attackers to exploit multiple OS…
2 articles · Updated June 23, 2026
Recent Intelligence Reports
- ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir's First Coordinated AI ... — Tech.Yahoo · August 31, 2026
- Neocloud Security Deep Dive Report: Alarming Infrastructure Configuration Errors, Cross ... — Weex · August 31, 2026
- SemiAnalysis releases Neocloud security deep report — Chaincatcher · August 30, 2026
- SemiAnalysis Discovers Critical Security Vulnerabilities in Neocloud Infrastructure — Kucoin · August 30, 2026
- Two critical vulnerabilities in Next.js – remote code execution on Windows — Heise.De · August 28, 2026
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — Thehackernews · August 27, 2026
- A Reported Log4j RCE Is More Complicated Than It Looks — Sonatype · August 27, 2026
- WAF Release - 2026-08-26 - Emergency · Changelog — Developers.Cloudflare · August 26, 2026