Tag: RCE

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: RCE vulnerability in SolarWinds WHD

Cybersecurity Threat Advisory: RCE vulnerability in SolarWinds WHD

A critical remote code execution (RCE) vulnerability, CVE-2025-26399, has been identified in SolarWinds Web Help Desk (WHD) and remains exploitable despite previous fixes. The flaw allows unauthenticated attackers to execute arbitrary code on vulnerable servers, leading to a full system...

/ September 24, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Severe GoAnywhere MFT vulnerability

Cybersecurity Threat Advisory: Severe GoAnywhere MFT vulnerability

Fortra disclosed a critical vulnerability in GoAnywhere Managed File Transfer (MFT), tracked as CVE-2025-10035, with a CVSS score of 10.0. The flaw allows attackers to execute remote code without authentication. Review this Cybersecurity Threat Advisory to keep your systems safe....

/ September 24, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical WatchGuard firewall flaw

Cybersecurity Threat Advisory: Critical WatchGuard firewall flaw

A critical remote-code execution (RCE) vulnerability in WatchGuard Firebox, tracked as CVE-2025-9242 with a CVSS score of 9.3, allows unauthenticated attackers to execute arbitrary code. Review the information in this Cybersecurity Threat Advisory to learn more. What is the threat?...

/ September 19, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical flaw in DELMIA Apriso MOM software

Cybersecurity Threat Advisory: Critical flaw in DELMIA Apriso MOM software

CISA has added CVE-2025-5086, a critical remote code execution (RCE) vulnerability in Dassault Systèmes DELMIA Apriso Manufacturing Operations Management (MOM) software, to its catalog following confirmed active exploitation. Review the details of this Cybersecurity Threat Advisory to keep your system...

/ September 18, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical FreePBX zero-day vulnerability

Cybersecurity Threat Advisory: Critical FreePBX zero-day vulnerability

Researchers have discovered a zero-day vulnerability in Sangoma FreePBX, identified as CVE-2025-57819. This flaw allows unauthenticated remote attackers to take control of affected PBX systems, potentially resulting in remote code execution (RCE), arbitrary database manipulation, and full system compromise. Review...

/ September 3, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Citrix patches NetScaler flaws

Cybersecurity Threat Advisory: Citrix patches NetScaler flaws

Citrix has issued patches for three zero-day vulnerabilities affecting NetScaler ADC and Gateway, including one that attackers have already begun exploiting. Review the details in this Cybersecurity Threat Advisory to reduce your risk from these threats. What is the threat?...

/ August 28, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical SAP NetWeaver vulnerabilities

Cybersecurity Threat Advisory: Critical SAP NetWeaver vulnerabilities

Researchers have uncovered a chained vulnerability in SAP NetWeaver Visual Composer involving authentication bypass and insecure deserialization. These critical flaws—tracked as CVE-2025-31324 and CVE-2025-42999—are currently being exploited in an active threat campaign targeting exposed Visual Composer servers. Review the details...

/ August 20, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical PaperCut NG/MF CSRF flaw

Cybersecurity Threat Advisory: Critical PaperCut NG/MF CSRF flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2023-2533, a critical PaperCut NG/MF print management software vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog. Attackers are actively exploiting this cross-site request forgery (CSRF) flaw in the wild. Review...

/ July 31, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft SharePoint zero-day vulnerability

Cybersecurity Threat Advisory: Microsoft SharePoint zero-day vulnerability

Attackers are actively exploiting CVE-2025-53770, a critical zero-day vulnerability in Microsoft SharePoint, to execute remote code without authentication. This flaw allows attackers to deploy persistent malware and potentially exfiltrate sensitive data from unpatched on-premises environments. Review the full details in...

/ July 22, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: FortiWeb critical SQL injection vulnerability

Cybersecurity Threat Advisory: FortiWeb critical SQL injection vulnerability

A high-severity SQL injection vulnerability, CVE-2025-25257, in Fortinet FortiWeb enables pre-authenticated remote code execution (RCE). It has a  a CVSS score of 9.8. Review the details in this Cybersecurity Threat Advisory to keep your environment safe. What is the threat?...

/ July 17, 2025