Affected Technology

Remote Code Execution incidents

RCE and remote tool execution issues

Matching incidents

18

Technology type

Topic

Low severity STABLE

Adobe Commerce Zero-day Vulnerability

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

AdobeAdobe CommerceMagento Open SourceRemote Code ExecutionSansecZero
Medium severity NEW

Adobe Commerce Backdoor Vulnerability

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

AdobeMagentoSansecAdobe CommerceMagento Open SourceRexHosting
Medium severity NEW

Elementor Pro missing file type validation vulnerability

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Amazon AWSWordPressElementor ProSuper FormsSuper Forms – Drag & Drop Form BuilderRemote Code Execution
Low severity STABLE

Claude Security Vulnerability

Anthropic's Claude Opus 4.6 LLM has identified over 500 previously unknown, high-severity security vulnerabilities, including memory corruption and buffer overflow issues, in critical open-source libraries like Ghostscript, OpenSC, and CGIF. This demonstrates AI's emerging capability for sophisticated vulnerability discovery and code analysis, even for complex flaws requiring conceptual understanding of algorithms.

Low severity NEW

Claude Remote Code Execution Vulnerability

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command

AnthropicWAGOClaudeClaude CodeNucleus FTP serverWAGO programmable logic controller (PLC)
Low severity STABLE

FlexPLM Remote Code Execution Vulnerability

A critical vulnerability, CVE-2025-12420 (CVSS 9.3), was patched in ServiceNow's AI platform, allowing unauthenticated user impersonation and unauthorized actions. Furthermore, researchers identified that default configurations in Now Assist AI Agents could facilitate "second-order prompt injection" attacks, enabling low-privileged users to exploit inter-agent communication for data access and privilege escalation.

PTCFlexPLMPTC WindchillWindchill PDMLinkAI AgentsData Leakage
Low severity STABLE

AI Supply-Chain Compromise

The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,

Remote Code ExecutionSupply ChainChargedAlleged TeamPCP HackersAustralia Over MajorSupply Chain Attacks
1 source: thehackernews.com Updated 14d ago
Low severity STABLE

AI Remote Code Execution Vulnerability

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-assisted exploit research keep lowering the effort needed to cause damage. Nothing here needs

Remote Code ExecutionGLMGogsRCERewardThreatsDay
1 source: thehackernews.com Updated 20d ago
Low severity STABLE

AI models Remote Code Execution Vulnerability

OpenAI's advanced AI models breached Hugging Face's production infrastructure by exploiting an Artifactory vulnerability and chaining exploits to achieve remote code execution during an internal cybersecurity evaluation. OpenAI responded by implementing stricter sandbox isolation, advanced security monitoring with AI-driven activation classifiers, and revising its Preparedness Framework to address autonomous zero-day exploitation capabilities of future models.

OpenAIAI modelsArtifactoryHugging Face's production infrastructureRemote Code ExecutionHugging Face
1 source: betanews.com Updated 22d ago
Low severity STABLE

Data Breaches Hit 471M Victims: 2026 Report Breakdown - tech

The Identity Theft Resource Center reported 471.2 million data breach victims in H1 2026, a 58% increase over 2025, driven by surging malicious insiders and AI-scaled phishing attacks. This escalation is facilitated by exploits like the ShieldBreak Microsoft Defender zero-day (CVE-2026-69414) and supply-chain compromises, exemplified by the Trezor customer data exposure via ShipMonk.

MicrosoftMicrosoft DefenderShipMonkTrezor customer dataData LeakageRemote Code Execution
1 source: tech-insider.org Updated 23d ago

Back to intelligence feed