CWE-77 - Command Injection is a cwe tracked across 9 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed May 20, 2026; most recent activity July 21, 2026.
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
Tenable has released Security Center Patch SC202607.1 to address multiple vulnerabilities in third-party components, including Apache, OpenSSL, PostgreSQL, PHP, and Redis. The patch resolves critical issues such as SQL…
Multiple critical vulnerabilities affecting Gogs and Jinjava have been disclosed, with severe impacts including remote code execution (RCE) and unauthorized file access. Gogs vulnerabilities include CVE-2025-64111…
CVE-2026-16117 was published on July 18, 2026, detailing a critical vulnerability in @fastify/http-proxy versions up to 11.5.0. The flaw allows attackers to bypass request prefix rewrites when the prefix is URL-encoded,…
A newly disclosed vulnerability in Microsoft 365 Copilot Enterprise, named SearchLeak (CVE-2026-42824), allows attackers to exfiltrate sensitive data with a single click on a crafted link. Discovered by Varonis Threat…
Seiko Solutions' SkyBridge MB-A100 and MB-A110 routers are affected by a high-severity OS command injection vulnerability (CVE-2026-50043) disclosed on July 1, 2026. The flaw allows authenticated attackers to execute…
SUSE has released a security update addressing multiple vulnerabilities in Cockpit, impacting SUSE Linux Enterprise and openSUSE systems. Notably, CVE-2026-4802 allows remote command execution via unsanitized…
On March 10, 2026, three critical vulnerabilities were published affecting Substance3D software. CVE-2026-21365 and CVE-2026-27219 both impact Substance3D - Painter versions 11.1.2 and earlier, exposing users to…
AISLE has launched Snapshot, an on-premises AI vulnerability scanner designed for regulated enterprises. This tool allows organizations to maintain control over their source code and security data while scanning for…