Command-Injection
CVE-2026-89094: A Malicious Template Repository Gets You RCE on Forgejo — and Gitea
A crafted .forgejo/template file lets any low-privileged authenticated user turn 'create repository from template' into remote code execution as the Git-forge service account. Forgejo (CVE-2026-89094, CVSS 9.9) and upstream Gitea both shipped emergency patches.
Two Critical Command Injection Flaws in Advantech WISE-6610 Industrial Gateways (CVE-2026-79697, CVE-2026-79698)
Two CVSS 9.9 command injection bugs in Advantech's WISE-6610 cellular IoT gateway let an attacker with access to the admin web UI run arbitrary OS commands as root, with public exploit code already circulating.
CVE-2026-9586: Unauthenticated SQLi-to-RCE in Sangoma Switchvox Under Active Exploitation
An unauthenticated SQL injection in Sangoma Switchvox's phone-provisioning endpoint escalates to root command execution and is now being used in the wild to plant reverse shells on internet-exposed VoIP servers.
CVE-2026-60004: Gitea diffpatch Code Injection Now Under Active Exploitation, Added to CISA KEV
A critical Gitea flaw lets any repository writer install a malicious Git hook via the diffpatch endpoint and run shell commands as the Gitea OS user. CISA confirms in-the-wild exploitation and gave federal agencies until August 28 to patch.
CVE-2026-73570: Unauthenticated Zimbra RCE via SNMP Notifications Under Active Exploitation
CERT Polska confirms in-the-wild exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration's SNMP notification handling — patched in 10.1.20, but plenty of mail servers haven't updated.
Evooo1Bot: New Mirai-Derived Linux Botnet Chains Eight CVEs Spanning 2007–2025 Against Routers and Edge Devices
Evooo1Bot, a modular Mirai-derived Linux botnet tracked by FortiGuard Labs, exploits eight known CVEs dating back to 2007 across routers, firewalls, and industrial gateways to build a SOCKS5 proxy and DDoS network.
CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited — CISA Sets July 30 Deadline
An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.
Six Bulletins, One Bug Class: What Ubiquiti's 2026 UniFi Cadence Reveals About Shared-OS Edge Platforms
Since October 2025, Ubiquiti has shipped six security bulletins covering the UniFi line — five of them containing CVSS 9.9-10.0 flaws, two of them the exact same shell-injection bug class shipped seven months apart. This is what happens when one Nginx gateway and one OS layer sit in front of your network, your cameras, and your door locks.
PraisonAI: Two More Critical RCEs (CVE-2026-61445, CVE-2026-61447) as AICoder Runs LLM Output Unsandboxed
PraisonAI's AICoder component writes files and executes shell commands straight from LLM tool calls with no path validation, and CodeAgent._execute_python() runs LLM-generated Python with no AST checks or sandboxing — two CVSS 9.9 and 10.0 flaws, patched in 4.6.78.
Ubiquiti's Bulletin 066: A CVSS 10.0 in UniFi Connect Leads 25 Flaws Across the Whole UniFi Line
Ubiquiti Security Advisory Bulletin 066 discloses 25 vulnerabilities across UniFi Connect, Talk, Access, Protect, and UniFi OS — headlined by CVE-2026-50746, a CVSS 10.0 unauthenticated command injection reachable on ~100,000 internet-facing endpoints.
CVE-2026-8037: Pre-Auth Root RCE in Progress Kemp LoadMaster Now Under Active Exploitation
CVE-2026-8037, a CVSS 9.8 uninitialized-heap flaw in Progress Kemp LoadMaster's escape_quotes() function, lets unauthenticated attackers run root commands on the load balancer's management API. eSentire observed exploitation attempts starting June 29.
GuardFall: Decades-Old Bash Quoting Tricks Defeat Safety Guards in 10 of 11 Open-Source AI Coding Agents
Adversa AI's GuardFall research shows that quote removal, $IFS spacing, command substitution, and other decades-old shell tricks bypass the command guards in opencode, Goose, Cline, Aider, and seven other open-source AI coding agents — turning a poisoned README into silent credential theft.
Ubiquiti UniFi OS Server Triple-CVE Chain Enables Unauthenticated Root RCE
Three max-severity CVEs (2026-34908/09/10) in UniFi OS Server chain from an Nginx auth bypass to root command injection — CISA added all three to KEV on June 23 amid Mirai/Gaafgyt botnet exploitation.
Ivanti Sentry CVE-2026-10520: Unauthenticated Root RCE via handleMessage, Now in CISA KEV
A CVSS 10.0 OS command injection in Ivanti Sentry's unauthenticated /mics/api/v2/sentry/mics-config/handleMessage endpoint yields remote code execution as root. watchTowr published a PoC on June 10, CISA added it to KEV on June 11 with a June 14 deadline, and exploitation has followed.
Cisco Catalyst SD-WAN Manager CVE-2026-20245: Root Command Execution, No Patch Yet
Cisco's seventh SD-WAN zero-day of 2026. CVE-2026-20245 lets a netadmin upload a crafted file and execute commands as root on SD-WAN Manager. Exploited in the wild, no fix at disclosure.
CVE-2026-3854: A Single Git Push Owned GitHub.com — and 88% of Enterprise Servers Were Still Vulnerable at Disclosure
Wiz disclosed a CVSS 8.7 RCE in GitHub's internal git push pipeline. Any authenticated user could execute arbitrary commands on backend servers with one git push. 88% of Enterprise Server instances were still unpatched on disclosure day.
Spinnaker Dual 10.0s: Echo SpEL and Clouddriver gitrepo RCE Gut Netflix's CD Platform (CVE-2026-32604, CVE-2026-32613)
Two critical (CVSS 10.0) RCE bugs in Spinnaker, disclosed April 21, 2026 with working PoCs: SpEL expression injection in Echo and shell injection in Clouddriver gitrepo artifacts. Any authenticated user pops the CD plane and walks out with every stored cloud credential.
Two Critical FortiSandbox Flaws Let Unauthenticated Attackers Execute Commands and Bypass Auth
Fortinet discloses CVE-2026-39808 and CVE-2026-39813 — two CVSS 9.1 flaws in FortiSandbox allowing unauthenticated command execution and authentication bypass via crafted HTTP requests.
Composer Command Injection (CVE-2026-40261, CVE-2026-40176): Any Malicious Repository Can Execute Code on Your Build Machines
Two high-severity command injection flaws in PHP's Composer package manager allow arbitrary command execution via malicious repository metadata — no Perforce installation required for the worst one.
Three High-Severity Command Injection Flaws in AWS Research and Engineering Studio Give Authenticated Users Root RCE
AWS patches three CVSS 8.8 command injection and privilege escalation bugs in Research and Engineering Studio (RES) — any authenticated user could get root on virtual desktop hosts or the cluster manager.