Skip to content

Topic

Command Injection

A vulnerability class where untrusted input is passed to an OS command interpreter, letting attackers execute arbitrary system commands.

Current stories

security4 publishers

Crafted emails give attackers shells on Zimbra servers running SNMP notifications

Microsoft says attackers are using CVE-2026-73570 to run commands on Zimbra mail servers with one crafted email and no login. Zimbra shipped the fix in 10.1.20 on July 20, 24 days before disclosure, so anyone who waited for the advisory to patch was already late.

Perspective Coverage

4 publishers
Builder
Builder 21%
Operator
Operator 68%
Investor
Investor 11%

Reality

Evidence80
Adoption40
Hype gap+5
Incentives
Insufficient
Confidence75
build1 publisher

One COPY line runs a shell despite AWS's read-only Postgres MCP filter

AWS published CVE-2026-87911, a CVSS 9.6 command injection in its own postgres-mcp-server, where one COPY ... TO PROGRAM line runs a shell on the host. The read-only promise lives in a regex filter that lets the COPY keyword through.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+25
Incentives40
Confidence50
security1 publisher

CVE-2026-22755 opens 37 VIVOTEK camera models to remote command execution

CISA lists 37 VIVOTEK camera models open to CVE-2026-22755, a command injection bug that can give attackers remote command execution, potentially as root. Exploit code was public before the advisory, so the first job for owners is finding out which of their cameras are on the list.

Publishers:cisa.gov

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence60