Tag: RCE

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical SAP NetWeaver vulnerabilities

Cybersecurity Threat Advisory: Critical SAP NetWeaver vulnerabilities

Researchers have uncovered a chained vulnerability in SAP NetWeaver Visual Composer involving authentication bypass and insecure deserialization. These critical flaws—tracked as CVE-2025-31324 and CVE-2025-42999—are currently being exploited in an active threat campaign targeting exposed Visual Composer servers. Review the details...

/ August 20, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical PaperCut NG/MF CSRF flaw

Cybersecurity Threat Advisory: Critical PaperCut NG/MF CSRF flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2023-2533, a critical PaperCut NG/MF print management software vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog. Attackers are actively exploiting this cross-site request forgery (CSRF) flaw in the wild. Review...

/ July 31, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft SharePoint zero-day vulnerability

Cybersecurity Threat Advisory: Microsoft SharePoint zero-day vulnerability

Attackers are actively exploiting CVE-2025-53770, a critical zero-day vulnerability in Microsoft SharePoint, to execute remote code without authentication. This flaw allows attackers to deploy persistent malware and potentially exfiltrate sensitive data from unpatched on-premises environments. Review the full details in...

/ July 22, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: FortiWeb critical SQL injection vulnerability

Cybersecurity Threat Advisory: FortiWeb critical SQL injection vulnerability

A high-severity SQL injection vulnerability, CVE-2025-25257, in Fortinet FortiWeb enables pre-authenticated remote code execution (RCE). It has a  a CVSS score of 9.8. Review the details in this Cybersecurity Threat Advisory to keep your environment safe. What is the threat?...

/ July 17, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Severe WebDAV vulnerability

Cybersecurity Threat Advisory: Severe WebDAV vulnerability

Microsoft has disclosed a serious zero-day vulnerability in the Web Distributed Authoring and Versioning (WebDAV) protocol, identified as CVE-2025-33053, with a CVSS score of 8.8. Actively exploited by the Stealth Falcon APT group, this vulnerability enables remote code execution (RCE)...

/ June 30, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ivanti EPMM vulnerability

Cybersecurity Threat Advisory: Ivanti EPMM vulnerability

Ivanti has released updates for Endpoint Manager Mobile (EPMM) that address one medium and one high-severity vulnerability. When chained together, these vulnerabilities can enable unauthenticated remote code execution (RCE). Review the details in this Cybersecurity Threat Advisory for information on...

/ May 21, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical zero-day vulnerability in Fortinet

Cybersecurity Threat Advisory: Critical zero-day vulnerability in Fortinet

A critical zero-day vulnerability affecting several Fortinet products, most notably FortiVoice enterprise phone systems, has recently been patched. Attackers are actively exploiting CVE-2025-32756 in the wild. Read the details of this Cybersecurity Threat Advisory to learn how to keep your...

/ May 15, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Commvault Command Center vulnerability

Cybersecurity Threat Advisory: Critical Commvault Command Center vulnerability

Commvault Command Center has been impacted by a critical security vulnerability, CVE-2025-34028, with a CVSS score of 10. This vulnerability enables remote code execution (RCE). Review the details of this Cybersecurity Threat Advisory to minimize the risk from this threat....

/ May 7, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Craft CMS exploited

Cybersecurity Threat Advisory: Craft CMS exploited

Threat actors have been actively exploiting two Craft CMS vulnerabilities, CVE-2025-32432 and CVE-2024-58136, to breach web servers and gain unauthorized access. Review the details in this Cybersecurity Threat Advisory to safeguard your devices. What is the threat? Threat actors are...

/ April 30, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical RCE flaw in Apache Roller blog server

Cybersecurity Threat Advisory: Critical RCE flaw in Apache Roller blog server

Researchers have discovered a critical session management vulnerability within Apache Roller. It is being tracked as CVE-2025-24859 and has been assigned the maximum CVSS score of 10.0. Review the details in this Cybersecurity Threat Advisory to mitigate your risks. What...

/ April 17, 2025