Rce
CVE-2026-88771 & CVE-2026-88772: Unauthenticated RCE Zero-Days Hit Every NetScaler Deployment
Citrix confirms two NetScaler ADC/Gateway zero-days under active exploitation — one an unauthenticated command-execution bug present in every default configuration, the other a DTLS memory overflow enabled by default on VPN virtual servers.
CISA Adds SharePoint CVE-2026-65660 to KEV: SafeControls Bypass Enables Authenticated RCE
CISA confirmed active exploitation of CVE-2026-65660, a SharePoint code-injection bug that bypasses the SafeControls allowlist, letting a low-privilege authenticated user register arbitrary .NET classes and run code as the farm service account.
WordPress Core CVE-2026-87902: Unauthenticated Path Traversal to RCE via pearcmd, Exploited Within Hours
An unauthenticated path traversal bug in WordPress Core's page-template resolution (CVE-2026-87902) lets attackers include arbitrary PHP files and chain to RCE via pearcmd — mass scanning began within five hours of the patch, and CISA added it to KEV on September 25.
CVE-2026-94127: F5 BIG-IP APM OAuth Heap Overflow Lets Attackers Skip Login Entirely and Hit RCE
F5 has patched CVE-2026-94127, a CVSS 9.8 heap-based buffer overflow in BIG-IP Access Policy Manager's OAuth handling that lets an unauthenticated attacker corrupt memory in the data-plane microkernel and execute code — already exploited in the wild and on CISA's KEV list as of September 22.
SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key Enables Unauthenticated RCE
A hard-coded cryptographic key in SolarWinds Access Rights Manager (CVE-2026-28326, CVSS 8.8) lets an adjacent-network attacker run arbitrary code with no credentials. Patch to ARM 2026.2.1.
Plugin4Shell: SHA-Pinning Bypass Enables Zero-Click RCE Across Claude Code, Codex, Copilot, and Gemini CLI
A Git reference-resolution flaw dubbed Plugin4Shell lets a plugin repository owner silently swap the code behind a SHA-pinned install across all four major AI coding agents, achieving zero-click RCE on developer and CI machines that trust the pin.
CVE-2026-75754: Chained Flaw in ASUS Control Center Enterprise Gives Unauthenticated Root
CVE-2026-75754 (CVSS 10.0) chains a missing-auth SSRF flaw with hardcoded SSH credentials to hand unauthenticated attackers root on ASUS Control Center Enterprise servers — and everything those servers manage.
CVE-2026-89094: A Malicious Template Repository Gets You RCE on Forgejo — and Gitea
A crafted .forgejo/template file lets any low-privileged authenticated user turn 'create repository from template' into remote code execution as the Git-forge service account. Forgejo (CVE-2026-89094, CVSS 9.9) and upstream Gitea both shipped emergency patches.
CVE-2026-85102 & CVE-2026-85103: Dutch NCSC Warns Exploitation of Check Point VPN Certificate RCE Flaws Is Imminent
Two unauthenticated CVSS 9.8 RCE bugs in Check Point's VPN certificate handling have hotfixes since September 9 — the Dutch NCSC says active exploitation is likely imminent even though no public PoC exists yet.
CVE-2026-20079: CVSS 10 Auth Bypass in Cisco Secure FMC Exploited by Sandworm and Qilin Ransomware
A maximum-severity authentication bypass in Cisco Secure Firewall Management Center gives unauthenticated attackers root — Talos has tied active exploitation to Russia's Sandworm and to Qilin ransomware affiliates, and CISA's KEV deadline lands today.
CVE-2026-85706: Unauthenticated CVSS 10 Path Traversal in GitLab's Commits API Under Active Probing
A maximum-severity, unauthenticated path traversal in GitLab's repository commits API lets attackers read arbitrary server files; CISA added it to KEV and honeypots logged probing within hours of the patch.
cPanel CVE-2026-67401: EmailTrack SQL Injection Lets Mail Users Reach Root
A SQL injection in cPanel & WHM's EmailTrack feature lets any account with mail privileges write arbitrary files and execute code as root — CVSS 9.9, every supported version affected.
Dell Secure Connect Gateway: Five Chained Flaws Take an Unauthenticated Request to Root
Dell patched five chainable flaws in Secure Connect Gateway, including a token-replay auth bypass and a Docker-socket privilege escalation, that together let an unauthenticated network attacker reach root on the host.
StyleSmuggler: Unpatched Magento/Adobe Commerce Zero-Day Gives Unauthenticated RCE, No Fix Yet
Sansec disclosed StyleSmuggler, an unauthenticated remote code execution chain hitting all current Magento and Adobe Commerce builds, under active attack since September 4 with no CVE and no patch.
The WannaCry Bugs Never Left: Windows' Core Network Stack Just Had Its Worst Year Since EternalBlue
Netlogon, DNS Client, DHCP Server, DNS Server — four unauthenticated, network-reachable, CVSS-9.8-class memory corruption bugs in Windows' core infrastructure services in five months. This is not four unlucky patch cycles. It's a pattern, and most vulnerability-management programs are triaging it wrong.
PostGREShell (CVE-2026-6471): A 12-Year-Old PostgreSQL Flaw Turns Replication Access Into Root RCE
A missing-authorization bug in PostgreSQL logical decoding, present since version 9.4 in 2014, lets any account with REPLICATION privilege load an arbitrary library and execute code as the database server's OS user.
Cisco Nexus 9000 CVE-2026-20212: Unauthenticated Root RCE on Silicon One Data Center Switches
A CVSS 9.8 flaw lets unauthenticated attackers execute code as root on Cisco Nexus 9000 switches with Silicon One ASICs by reaching two hard-coded, unrestricted TCP ports.
CVE-2026-49869: Kestra OSS Auth-Bypass Lets Unauthenticated Attackers Get Root RCE, CISA Sets Today as Federal Deadline
A suffix-match flaw in Kestra OSS's AuthenticationFilter lets anyone skip Basic Auth entirely and reach unauthenticated remote code execution as root, CVSS 10.0, now on CISA's KEV list.
HPE Aruba AOS-CX: Two Independent Unauthenticated RCE Paths in the Same Switch OS (CVE-2026-73749, CVE-2026-73782)
HPE's September security bulletin for ArubaOS-CX patches 24 flaws, including two unrelated bugs that each let an unauthenticated attacker fully compromise a switch with a single crafted packet.
CVE-2026-0768: Unauthenticated Root RCE in Langflow's Validate Endpoint Under Mass Exploitation
CVE-2026-0768, an unauthenticated code-injection RCE in Langflow's custom component validator, is under active mass exploitation — VulnCheck honeypots logged 360 attacks since August 29 hunting for AWS and OpenAI keys.