Skip to content

Topic

Remote Code Execution Surfaces

Documented APIs that permit file access and command execution on hosts, functioning as RCE surfaces when exposed.

Current stories

security3 publishers

CISA warns a single unauthenticated request can root MikroTik RouterOS below 7.24

CISA says an integer underflow in MikroTik RouterOS web management gives an unauthenticated attacker root with one crafted request on versions below 7.24. No exploitation has been reported, but MikroTik's fix advice sets a 7.23 floor that CISA's own affected range still covers.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 66%
Investor
Investor 7%

Reality

Evidence64
Adoption70
Hype gap+8
Incentives
Insufficient
Confidence62
build1 publisher

HFS leaks the Math.random() state that signs its admin cookies

Rejetto HFS 3.0.0 through 3.2.0 signs session cookies with a Math.random() key, and five leaked PRNG outputs let an attacker forge an admin session. Exploitation began on October 1, and version 3.2.1 restores secure key generation.

Publishers:dev.to

Reality

Evidence70
Adoption72
Hype gap0
Incentives50
Confidence65
security7 publishers

WordPress patched a comment flaw that uses an admin's session to plant a web shell

CVE-2026-93485 was fixed on September 17 in WordPress 7.1.1. An anonymous comment plants a script, an administrator opens the page, and the script uploads a plugin carrying a web shell. Affected versions go back to 4.7.

Perspective Coverage

7 publishers
Builder
Builder 35%
Operator
Operator 62%
Investor
Investor 3%

Reality

Evidence79
Adoption42
Hype gap+14
Incentives67
Confidence70
security4 publishers

Two loops, one blocklist bypass: Elementor Pro's upload field becomes unauthenticated RCE

CVE-2026-32475 carries a CVSS of 9.0 and needs nothing more than a published form with a file upload field. Patchstack says version 4.2.2 fixes it.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 59%
Investor
Investor 7%

Reality

Evidence70
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence68
security7 publishers

Default self-registration hands unauthenticated attackers Gitea's exploited RCE on 8,393 servers

Gitea shipped a fix for CVE-2026-60004 on July 27 and CISA gave federal agencies until August 28, yet a month later Shadowserver still counts 8,393 exposed instances, and on shipped defaults the bug needs no credentials.

Perspective Coverage

7 publishers
Builder
Builder 22%
Operator
Operator 67%
Investor
Investor 11%

Reality

Evidence62
Adoption40
Hype gap+20
Incentives
Insufficient
Confidence58
security4 publishers

Two chained flaws reach root on Unitree's G1 humanoid from Bluetooth range

Olivier Laflamme walked an unpaired Bluetooth write up to root on the G1 EDU's Locomotion PC by way of a Unitree cloud API that decrypted key material for any logged-in account. Unitree fixed that check in July, but no patched firmware has been named.

Publishers:boschko.cascworld.comsecurityaffairs.comthehackernews.com

Perspective Coverage

4 publishers
Builder
Builder 38%
Operator
Operator 50%
Investor
Investor 12%

Reality

Evidence72
Adoption38
Hype gap+8
Incentives45
Confidence62
security3 publishers

GiveWP issues accounts to unauthenticated attackers on sites where registration is off

Patchstack chained an unsafe unserialize helper, a donation form and a bundled gadget chain into command execution on more than 100,000 installs. Version 4.16.7.2 closes the execution path and leaves the registration hole.

Perspective Coverage

3 publishers
Builder
Builder 40%
Operator
Operator 52%
Investor
Investor 8%

Reality

Evidence68
Adoption45
Hype gap+15
Incentives30
Confidence70
security3 publishers

Crafted packets execute code on ArubaOS-CX switches without a login

CVE-2026-73749 lets an unauthenticated attacker run privileged code on HPE Aruba switches by sending malformed packets to a daemon the bulletin never names. The oldest affected branch is already out of maintenance.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 67%
Investor
Investor 10%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives50
Confidence70
security4 publishers

Any PostgreSQL replication account can load a shared library as the postgres OS user

CVE-2026-6471 has sat in every PostgreSQL release since 9.4 shipped in 2014. Cyera says the plugin name in a replication slot request reaches dlopen() unvalidated, which makes the fix a privilege audit as much as a patch.

Perspective Coverage

4 publishers
Builder
Builder 32%
Operator
Operator 59%
Investor
Investor 9%

Reality

Evidence74
Adoption55
Hype gap+24
Incentives58
Confidence72
security3 publishers

A hand-debugged Python toolkit turned marimo CVE-2026-39987 into bastion SSH in eight seconds

Sysdig's threat research team watched one operator work a marimo notebook host for nine hours with hand-written scripts, and the eight-second jump to a bastion host at the end ran on tooling already staged on disk.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 60%
Investor
Investor 7%

Reality

Evidence68
Adoption66
Hype gap+8
Incentives72
Confidence70

Earlier coverage

  1. Click2Shell runs attacker PHP on WordPress servers after a single administrator click

    Security · September 21, 2026 · 2 publishers

  2. SolarWinds's critical Observability RCE needs a configuration the vendor calls non-default and non-secure

    Security · September 24, 2026 · 1 publisher

  3. Click2Shell turns a 5.3-rated WordPress selector injection into PHP on the server

    Build · September 22, 2026 · 1 publisher

  4. A fake branch name defeats the commit pin four AI coding agents rely on

    Product · September 21, 2026 · 1 publisher

  5. Plugin4Shell turned a pinned commit into attacker code in four AI coding agents

    Leadership · September 20, 2026 · 1 publisher

  6. Confirmed exploitation moves the Adobe Commerce RCE to the front of CERT-In's patch queue

    Build · September 19, 2026 · 1 publisher

  7. Conductor OSS runs a stranger's inline JavaScript as root in its default container

    Build · September 18, 2026 · 1 publisher

  8. WordPress 7.1.1 blocks a crafted link that makes an admin's browser install the attacker's theme

    Security · September 18, 2026 · 1 publisher

  9. Semantic Kernel ran a model-controlled search filter through eval() at query time

    Build · September 17, 2026 · 1 publisher

  10. A Fastjson RCE walks in through the annotation check, not the type blacklist

    Build · September 16, 2026 · 1 publisher

  11. YARD's --load flag ran uploaded gem code inside RubyDoc.info's build workers

    Build · September 15, 2026 · 1 publisher

  12. Adobe's out-of-band Magento hotfix lands after attackers installed backdoors disguised as kworker

    Security · September 10, 2026 · 1 publisher

  13. StyleSmuggler runs its PHP inside Magento's failed-payment email renderer

    Build · September 8, 2026 · 1 publisher

  14. Attacker PHP executes when Magento renders its failed-payment reminder email

    Build · September 8, 2026 · 1 publisher

  15. StyleSmuggler turns a Magento payment-reminder email into unauthenticated code execution

    Security · September 8, 2026 · 1 publisher

  16. CVE-2025-62593: A Ray Developer's Browser Is Now the Attack Surface

    Security · August 19, 2026 · 1 publisher