OS Command Injection is a vulnerability tracked across 16 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed November 5, 2025; most recent activity July 20, 2026.
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
A critical vulnerability (CVE-2025-64155) in Fortinet's FortiSIEM platform allows unauthenticated remote code execution via crafted TCP requests. This OS command injection flaw affects the phMonitor service, which is…
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…
Fortinet has identified multiple critical vulnerabilities in its FortiSandbox and FortiAuthenticator products, which could allow unauthenticated attackers to execute arbitrary code remotely. The vulnerabilities are…
Two vulnerabilities in FortiWeb have been identified, both exploited in the wild. The first, a relative path traversal vulnerability (CWE-23), allows unauthenticated attackers to execute administrative commands via…
A severe security vulnerability, CVE-2026-34714, has been identified in Vim, a popular text editor. This flaw allows attackers to execute arbitrary operating system commands by tricking users into opening specially…
On March 10, 2026, Fortinet released a security advisory addressing eleven vulnerabilities in its core products, including a high-severity stack-based buffer overflow in FortiManager (CVE-2025-54820) that allows remote…
Seiko Solutions' SkyBridge MB-A100 and MB-A110 routers are affected by a high-severity OS command injection vulnerability (CVE-2026-50043) disclosed on July 1, 2026. The flaw allows authenticated attackers to execute…
Zyxel has issued security updates for a critical remote command execution vulnerability, tracked as CVE-2025-13942, affecting various router models. The flaw exists in the UPnP function, allowing unauthenticated…
Fortinet has disclosed two critical vulnerabilities affecting its FortiAP and FortiMail products. The first, an OS Command Injection vulnerability in FortiAP, allows authenticated attackers to execute unauthorized…