Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here’s how the eval() injection works and who still needs to patch.
A public proof-of-concept for the vBulletin RCE vulnerability CVE-2026-61511 is now live. Here’s how the eval() injection works and who still needs to patch.
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution.
A three-line SVG gave XBOW SYSTEM access on Bing’s servers through a default ImageMagick setting. Here’s the exploit chain and a checklist for anyone running a similar image pipeline.
A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate it before a patch exists.
The critical libssh2 CVE-2026-55200 flaw inverts SSH security: the remote server attacks the connecting client, no credentials needed. A public PoC is out and the official patched release has not shipped.
CVE-2026-48907 in the Joomla JCE plugin lets unauthenticated attackers drop PHP web shells with a single crafted request. Here is how the attack works and how to check if your site was hit.
CVE-2026-20253 is a CVSS 9.8 pre-auth flaw in Splunk Enterprise’s PostgreSQL sidecar service. An unauthenticated attacker can write files and chain the primitive to RCE. A public PoC exists; no workaround, patch only.
Microsoft has rolled out a huge Patch Tuesday update bundle for October 2025, addressing 175…
Microsoft has released the scheduled Patch Tuesday updates for September 2025, addressing 81 security vulnerabilities…
Microsoft has released the scheduled Patch Tuesday updates for August 2025. This month’s update bundle…