Check Point Root RCE via Management Server Login Flaw
September 18, 2026 Check Point Software has disclosed a critical vulnerability that lets unauthenticated attackers execute code with root privileges on Security Management Server and Log Server systems. The flaw, tracked as CVE-2026-91843, stems from a…
Critical Unbound DNSSEC Validator RCE via Malicious DNS Zone
September 18, 2026 A critical heap overflow vulnerability in the Unbound DNS resolver enables remote code execution through malicious DNS zones. The flaw, tracked as CVE-2026-81642, affects every Unbound release before version 1.26.1 and carries a CVSS…
Ransomware Gangs Exploit Critical VMware vCenter RCE CVE
September 16, 2026 Ransomware gangs have joined attacks exploiting a critical VMware vCenter remote code execution flaw. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities catalog to flag…
Critical HPE ArubaOS-CX RCE CVE: Unauthenticated Remote Code Execution in Enterprise Switches
September 3, 2026 HPE has patched a critical unauthenticated remote code execution vulnerability in ArubaOS-CX, the network operating system powering its enterprise-grade switches. Tracked as CVE-2026-73749, the flaw could allow remote attackers to take…
Critical Windows IKE Extension RCE CVE-2026-33824 Under Active Exploitation
August 19, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Windows Internet Key Exchange (IKE) vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on August 18, 2026. Threat actors are actively…
Critical Pre-Auth RCE Flaw Enables Remote Code Execution
July 28, 2026 A critical pre-authentication remote code execution vulnerability in vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code on affected servers. The flaw, tracked as CVE-2026-61511, impacts versions 5.7.5…
XBOW Bing Images RCE: SVG Command Injection Yields SYSTEM Shells
July 24, 2026 XBOW, an autonomous offensive security startup, disclosed two critical remote code execution vulnerabilities in Microsoft Bing’s image processing pipeline. The flaws, tracked as CVE-2026-32194 and CVE-2026-32191, both carry a CVSS…