#RemoteCodeExec
Critical RCE vulnerability (CVE-2026-3844) found in Breeze Cache WordPress plugin allows unauthenticated file uploads via fetch_gravatar_from_remote when Gravatars add-on is enabled. Patch 2.4.5 released. #WordPressPlugin #RemoteCodeExec #India
Hackers exploit file upload bug in Breeze Cache WordPress plugin
A critical RCE vulnerability in the Breeze Cache WordPress plugin (CVE-2026-3844) allows unauthenticated attackers to upload arbitrary files via the fetch_gravatar_from_remote function when the "Host Files Locally - Gravatars" add-on is enabled. Cloudways released version 2.4.5 to patch the flaw after Wordfence observed active exploitation attempts, and site owners should update immediately or disable the add-on to mitigate risk. #BreezeCache #CVE-2026-3844
www.hendryadrian.com
April 24, 2026 at 12:15 AM
Varonis Threat Labs uncovered an Azure Cosmos for PostgreSQL flaw allowing attackers to bypass server validation and inject config values via Azure API, enabling remote code execution. Microsoft fixed it in summer 2025. #RemoteCodeExec #CloudSecurity
Feeding Frenzy: RCE on Azure Cosmos for PostgreSQL
Varonis Threat Labs found an Azure Cosmos for PostgreSQL flaw that let attackers bypass server-side validation and inject arbitrary PostgreSQL configuration values through the Azure management API, leading to remote code execution. Microsoft confirmed the issue as an important RCE and released a fix in summer 2025, with the report emphasizing...
www.hendryadrian.com
May 11, 2026 at 6:30 PM
Google patches a critical remote code execution flaw (CVE-2026-0073) in Android’s adbd. Exploitation requires no user interaction. No Wear OS, Pixel Watch, or Android Automotive fixes yet. #AndroidSecurity #RemoteCodeExec #USA
Critical Remote Code Execution Vulnerability Patched in Android
Google released an Android update to patch a critical remote code execution vulnerability in the System component tracked as CVE-2026-0073. The flaw affects adbd, requires no user interaction to exploit, and there are currently no reports of in-the-wild exploitation; patches for Wear OS, Pixel Watch, Android XR, and Android Automotive were...
www.hendryadrian.com
May 5, 2026 at 2:45 PM
A critical unauthenticated RCE (CVE-2026-22679) exploited since March in Weaver E-cology 10.0 via an exposed debug API allowed remote command execution. Patch released March 12 removes the vulnerable endpoint. #WeaverEcology #RemoteCodeExec #China
Weaver E-cology critical bug exploited in attacks since March
Researchers at Vega documented attacks exploiting CVE-2026-22679 in Weaver E-cology 10.0 beginning mid-March that allowed unauthenticated remote command execution via an exposed debug API. Attackers ran discovery commands and attempted PowerShell payloads and a target-aware MSI (fanwei0324.msi), but endpoint defenses blocked execution and the vendor's March 12 fix removes the vulnerable endpoint; users should apply the update immediately. #CVE-2026-22679 #WeaverE-cology
www.hendryadrian.com
May 5, 2026 at 1:45 AM
A critical RCE flaw in protobuf.js allows JS code execution via unsafe dynamic function creation from schemas. Affects versions ≤ 8.0.0/7.5.4; upgrade to 8.0.1 or 7.5.5. #RemoteCodeExec #JavaScriptFlaw #EndorLabs
Critical flaw in Protobuf library enables JavaScript code execution
Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js that stems from unsafe dynamic function generation from schemas. Users should upgrade to protobuf.js 8.0.1 or 7.5.5, audit schema sources, and avoid loading untrusted schemas to mitigate the risk. #protobufjs #EndorLabs
www.hendryadrian.com
April 18, 2026 at 7:00 PM
CISA mandates patching of Ivanti EPMM critical flaw CVE-2026-1340 by April 11 following active exploitation risk. Nearly 950 exposed IPs remain online despite January fixes. #IvantiEPMM #RemoteCodeExec #USA
CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday
Ivanti Endpoint Manager Mobile has a critical, actively exploited code injection vulnerability (CVE-2026-1340) that can allow unauthenticated remote code execution on Internet-exposed, unpatched appliances. CISA added the flaw to its KEV catalog, ordered federal agencies to patch by April 11 under BOD 22-01, and urged all organizations to apply Ivanti’s January 29 fixes as Shadowserver reports nearly 950 exposed EPMM IPs still online. #CVE-2026-1340 #IvantiEPMM
www.hendryadrian.com
April 8, 2026 at 10:45 PM
Two critical FortiClientEMS vulnerabilities are actively exploited: CVE-2026-21643 (unauthenticated SQL injection) and CVE-2026-35616 (improper access control/API bypass). Patch updates released by Fortinet. #FortinetFlaw #RemoteCodeExec #Singapore
FortiClientEMS Vulnerabilities Under Active Exploitation, Expose Systems to RCE
Two actively exploited vulnerabilities in Fortinet’s FortiClientEMS allow unauthenticated remote code execution: a critical SQL Injection (CVE-2026-21643) and an improper access control/API bypass (CVE-2026-35616). Fortinet has issued hotfixes and upgrades (upgrade 7.4.4→7.4.5+ for the SQLi; apply the hotfix and move to 7.4.7+ for the access control issue) while CISA and Singapore’s...
www.hendryadrian.com
April 7, 2026 at 12:30 PM
Two chained vulnerabilities (CVE-2026-2699 & CVE-2026-2701) in Progress ShareFile Storage Zones Controller enable unauthenticated file access and remote code execution. Patch version 5.12.4 fixes the issues. #ShareFile #RemoteCodeExec #USA
New Progress ShareFile flaws can be chained in pre-auth RCE attacks
Two vulnerabilities in Progress ShareFile's Storage Zones Controller can be chained to enable unauthenticated file exfiltration and remote code execution on affected systems. The flaws (CVE-2026-2699 and CVE-2026-2701) were reported by watchTowr and fixed in Progress ShareFile 5.12.4 on March 10, but exposed instances should be patched immediately. #ProgressShareFile #StorageZoneController
www.hendryadrian.com
April 2, 2026 at 6:00 PM
PTC warns of a critical deserialization bug (CVE-2026-4681) in Windchill and FlexPLM leading to remote code execution risks across most versions. German authorities issue emergency alerts. Patches and mitigations underway. #Windchill #RemoteCodeExec
PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
PTC Inc. disclosed a critical deserialization vulnerability (CVE-2026-4681) in Windchill and FlexPLM that could allow remote code execution. German authorities have issued emergency warnings while PTC develops patches and provides mitigations, IoCs, and detection guidance. #Windchill #CVE-2026-4681
www.hendryadrian.com
March 25, 2026 at 4:20 AM
Oracle releases urgent patch for CVE-2026-21992, a critical unauthenticated remote code execution flaw in Oracle Identity Manager 12.2.1.4.0 exploitable via HTTP. #OraclePatch #RemoteCodeExec #USA
Oracle Issues Emergency Patch for Critical Flaw Enabling Remote Code Execution
Oracle released an emergency out‑of‑band patch for a critical unauthenticated remote code execution vulnerability tracked as CVE‑2026‑21992 that affects Oracle Identity Manager and Oracle Web Services Manager. Organizations should apply the Security Alert patches immediately for supported versions to mitigate the high‑severity risk posed by remote attackers. #OracleIdentityManager #OracleWebServicesManager...
www.hendryadrian.com
March 24, 2026 at 12:20 PM
Oracle patches critical CVE-2026-21992 in Identity Manager and Web Services Manager allowing unauthenticated remote code execution via HTTP. CVSS score 9.8 highlights severity. #OraclePatch #RemoteCodeExec #USA
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
Oracle has released security updates to fix a critical, remotely exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager that could allow unauthenticated remote code execution. Oracle and the NVD warn the flaw is easily exploitable over HTTP and urge affected users to apply the updates immediately. #CVE-2026-21992...
www.hendryadrian.com
March 21, 2026 at 3:00 PM