Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: unauthenticated-rce (25 articles)Clear

Exploited Sangoma Switchvox flaw gives unauthenticated attackers reverse shells

Attackers are exploiting a critical flaw in Sangoma Switchvox, a widely used enterprise VoIP phone-system platform, to run code on servers without any credentials. Tracked as CVE-2026-9586 and scored 9.3, it is an unauthenticated SQL injection in an internet-facing endpoint that concatenates user-controlled input directly into database queries, letting an attacker execute commands as the database superuser and drop a reverse shell. Researchers at Horizon3 saw exploitation begin on August 30 and warn that most of the roughly 4,000 internet-exposed Switchvox systems may already have been targeted. Sangoma patched the flaw in version 8.4.0.2 back in July, but many systems remain unpatched and reachable.

Check
Update Sangoma Switchvox to 8.4.0.2 or later immediately, and because exploitation is active, review logs for the published indicators, reverse-shell activity, and process-enumeration commands on exposed systems.
Affected
Organizations running internet-exposed Sangoma Switchvox before 8.4.0.2 (CVE-2026-9586); an unauthenticated attacker can inject SQL, execute commands as the database superuser, gain a reverse shell, and take over the phone system.
Fix
Patch to 8.4.0.2, take the management interface off the public internet, hunt for reverse shells and unauthorized database changes, rotate credentials, and treat any exposed unpatched instance as potentially already compromised.

Critical GiveWP WordPress flaw lets unauthenticated attackers run server commands

A critical flaw in GiveWP, a WordPress donation and fundraising plugin installed on more than 100,000 sites, lets an unauthenticated attacker run commands on the hosting server. Tracked as CVE-2026-82222, it chains three weaknesses: an unsafe PHP deserialization helper, a donation flow that stores attacker-controlled serialized objects, and a gadget chain in bundled libraries that turns that into system command execution. Although exploitation normally needs an account, an exposed registration action lets an attacker create one even when registration is disabled, making it effectively unauthenticated. It affects versions up to 4.16.7.1 and is fixed in 4.16.7.2, which blocks serialized data during donation processing.

Check
Update the GiveWP plugin to 4.16.7.2 across all WordPress sites now, and check for unexpected accounts, files, or processes on servers running the donation plugin.
Affected
WordPress sites running GiveWP up to 4.16.7.1 (CVE-2026-82222); an attacker can chain PHP object injection into system command execution, and a registration bypass makes exploitation effectively unauthenticated even with signups disabled.
Fix
Patch the plugin, put a web application firewall in front of the site, scan for web shells and unauthorized files, and review hosting accounts and logs on donation-enabled sites.

Three critical ServiceNow flaws let unauthenticated attackers run code and SQL

ServiceNow patched four flaws in its widely used AI Platform, three of them scored 10.0 and exploitable by an unauthenticated attacker with no user interaction. The first, CVE-2026-18885, is a code injection in the GraphQL Composite Data API that allows arbitrary code execution and access to instance data. The second, CVE-2026-18886, is an access-control flaw in the configuration image-upload processor that lets an attacker create or modify data and escalate privileges. The third, CVE-2026-74820, is a SQL injection allowing arbitrary queries against the instance database. ServiceNow fixed hosted instances itself, but self-managed customers must apply the updates. No exploitation of these three has been reported yet.

Check
Self-hosted ServiceNow customers should apply the platform updates immediately, since ServiceNow only patched its own hosted instances, and confirm production instances are on a fixed version.
Affected
Organizations running the ServiceNow AI Platform, especially self-managed instances (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820); unauthenticated attackers can execute code, manipulate data, escalate privileges, or run arbitrary SQL with no interaction.
Fix
Patch self-hosted instances now, restrict network access to ServiceNow where possible, review logs for suspicious GraphQL requests, unexpected configuration or data changes, and anomalous database queries, and prioritize internet-reachable instances.

Next.js patches two critical flaws enabling unauthenticated remote code execution

Vercel patched two critical unauthenticated remote code execution flaws in Next.js, the popular React framework that sees tens of millions of downloads a week. One stems from the upstream libheif library used for image processing and triggers when the framework optimizes an attacker-supplied AVIF image; the patched releases disable AVIF optimization until the upstream fix lands. The second, CVE-2026-75604, is a path traversal affecting Next.js servers running on a Windows filesystem in certain router configurations, with no workaround. Fixes are in versions 15.5.24 and 16.3.3, and applications hosted on Vercel are already protected. No exploitation had been reported at disclosure.

Check
Update Next.js to 15.5.24 or 16.3.3, rebuild production containers, and refresh dependency lockfiles, since the AVIF flaw comes through an upstream image library bundled in your build.
Affected
Self-hosted Next.js applications using image optimization or running on Windows filesystems (CVE-2026-75604 and the AVIF flaw); an unauthenticated attacker can achieve remote code execution, though Vercel-hosted apps are already protected.
Fix
Patch and rebuild, disable AVIF optimization until updated, review exposure of the image optimization API and public upload paths, and watch logs for traversal patterns and unusual AVIF processing on Windows-hosted instances.

Unpatched Kaltura video player flaws allow unauthenticated file read and code execution

CERT/CC disclosed two unpatched flaws in Kaltura's HTML5 video player library that let a remote, unauthenticated attacker read files from a server and run code, with only network access to the endpoint required. Both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint, which takes a user-controlled ServiceUrl parameter and passes fetched data to PHP's unserialize without validating it. Supplying a file path lets an attacker read any file the web server can access, including credentials and API keys, while the deserialization also enables code execution. CERT/CC could not reach the vendor, and because the endpoint is exposed on Kaltura's shared multi-tenant infrastructure, the flaws can affect many tenants at once.

Check
Since there is no vendor patch, restrict or disable external access to the mwEmbedLoader.php endpoint and enforce a strict allow-list for the ServiceUrl parameter permitting only known backend API URLs.
Affected
Organizations running the Kaltura HTML5 player library exposing mwEmbedLoader.php (CVE-2026-19913, CVE-2026-19912); an unauthenticated attacker can read sensitive files and execute code, with shared-CDN exposure widening the impact.
Fix
Block or lock down the vulnerable endpoint, allow-list ServiceUrl values, monitor for suspicious file-read attempts, rotate any secrets that may have been exposed, and watch for a vendor fix.

Attackers exploit unauthenticated Zimbra SNMP flaw for remote code execution

Poland's national CERT warned that attackers are exploiting a now-patched flaw in Zimbra Collaboration to run commands on mail servers without authentication. Tracked as CVE-2026-73570 and scored 8.9, it is an OS command injection bug in Zimbra's SNMP monitoring feature: when the optional SNMP package is installed and notification traps are enabled, improper input handling lets an unauthenticated attacker send crafted requests that execute commands as the Zimbra user. The monitoring service involved is on by default where SNMP is used, widening exposure. Zimbra fixed it in version 10.1.20 in July, and Zimbra servers are a long-standing target, so unpatched instances should be treated as urgent.

Check
Update Zimbra Collaboration to 10.1.20 or later now, and check whether the SNMP package is installed with notifications enabled, which is the exposed configuration under active attack.
Affected
Organizations running Zimbra Collaboration before 10.1.20 with the SNMP package installed and notifications enabled (CVE-2026-73570); an unauthenticated attacker can execute operating-system commands as the Zimbra user, and exploitation is underway.
Fix
Patch to 10.1.20, and if you ran an exposed version, inspect the Zimbra log for suspicious service restarts and recently created files, since patching alone will not evict a foothold.

Critical Elementor Pro flaw lets unauthenticated visitors upload PHP and run code

Researchers disclosed a critical flaw in Elementor Pro, the widely used WordPress page builder, that lets an unauthenticated visitor upload a PHP file through a public form and run code on the server. Tracked as CVE-2026-32475 and scored 9.0, it is a desynchronization bug in the Forms module's file-upload field: the code that validates an upload and the code that saves it disagree about how to handle an empty file entry. By sending a crafted upload with an empty first part followed by a PHP payload, an attacker slips the file past validation into a public directory. It affects versions up to 4.2.1 and is fixed in 4.2.2.

Check
Update Elementor Pro to 4.2.2 across all WordPress sites, and because updating does not remove files already uploaded, inspect the Elementor forms upload directory for unexpected PHP files.
Affected
WordPress sites running Elementor Pro up to 4.2.1 with a published form containing a file-upload field (CVE-2026-32475); an unauthenticated visitor can upload a PHP file and execute code as the web server.
Fix
Patch to 4.2.2, scan for web shells and unexpected files in upload directories, put a web application firewall in front of the site, and restrict public upload forms until confirmed clean.

Unauthenticated Forminator flaw lets attackers upload PHP and take over WordPress sites

A critical flaw in Forminator Forms, a WordPress plugin with more than 600,000 installations, lets unauthenticated attackers upload executable PHP files and take over a site. Tracked as CVE-2026-15748 and scored 9.8, the bug chains weaknesses in the plugin's upload handling: an attacker smuggles a forged record through a Select field that declares itself a file upload, then slips a PHP file past a blocklist that only checks exact extensions. Exploitation requires a form with both a file upload field and a select field, and it affects all versions up to 1.56.1. Because it needs no authentication, automated scanners can hunt for vulnerable sites at scale.

Check
Update the Forminator plugin to a version newer than 1.56.1 across all WordPress sites, and check for unexpected PHP files in upload directories and unfamiliar administrator activity.
Affected
WordPress sites running Forminator 1.56.1 or earlier with a form containing both a file upload and a select field (CVE-2026-15748); an unauthenticated attacker can upload PHP and fully compromise the site.
Fix
Patch the plugin, put a web application firewall in front of the site, scan for web shells and unauthorized files, and remove or reconfigure vulnerable forms until the update is applied.

Critical SAP Commerce Cloud flaw exploited days after patch with no public exploit

Attackers began exploiting a critical SAP Commerce Cloud flaw within days of its patch, even though no public proof-of-concept exists. Tracked as CVE-2026-58231 and scored 10.0, the improper-authorization bug in the Data Hub Adapter lets an unauthenticated attacker abuse a default authentication client and send crafted input to reach arbitrary code execution. Threat intelligence firm Defused saw the first exploitation attempts hit its honeypots three days after SAP's August patch, classified as automated mass scanning of internet-facing deployments. Shadowserver tracks more than 4,200 exposed SAP Commerce Cloud systems, mostly in Europe and North America. Prior critical SAP flaws have been used by state actors and ransomware crews.

Check
Apply SAP's August patch for Commerce Cloud immediately per Security Note 3771065, then re-deploy the updated version, and prioritize any internet-facing or hybrid deployment as an emergency.
Affected
Organizations running unpatched SAP Commerce Cloud (CVE-2026-58231); an unauthenticated attacker can reach arbitrary code execution with low complexity, and exploitation is already underway despite no public exploit code.
Fix
Patch and re-deploy now, restrict access to Commerce Cloud from untrusted networks, review the Data Hub Adapter and application logs for suspicious requests and code execution, and monitor for follow-on compromise.

Critical TeamCity flaw lets unauthenticated attackers run commands on the CI server

JetBrains patched a critical flaw in TeamCity, its continuous integration and delivery server, that lets an unauthenticated attacker run operating-system commands. Tracked as CVE-2026-63077 and scored 9.8, the deserialization bug affects all on-premises versions and is reached through the agent polling protocol, letting an attacker with HTTP access bypass authentication and execute commands with the privileges of the server process. JetBrains warns that exploitation exposes stored credentials and can compromise the integrity of the build pipeline. It is fixed in versions 2025.11.7 and 2026.1.3, with a patch plugin for older releases, and TeamCity Cloud is already updated. No exploitation has been reported.

Check
Upgrade on-premises TeamCity to 2025.11.7 or 2026.1.3, or apply the security patch plugin if you cannot upgrade, and restrict network access to the server.
Affected
Organizations running any on-premises TeamCity version (CVE-2026-63077); an unauthenticated attacker with HTTP access can execute commands as the server process, steal stored credentials, and tamper with build pipelines.
Fix
Patch or apply the plugin, keep TeamCity off the public internet or behind a VPN, rotate credentials the server held, and review build configurations and logs for unauthorized changes.