
One Request Can Hijack Your AI Gateway
A critical flaw in the Bifrost AI gateway lets attackers run any command without a password. This gives them full control over the server, exposing sensitive data and AI models.
38 verified briefings on Rce. Each story includes a plain-English summary, why it matters, and the concrete action engineering teams should take.

A critical flaw in the Bifrost AI gateway lets attackers run any command without a password. This gives them full control over the server, exposing sensitive data and AI models.

Researchers found critical security flaws in an open-source AI agent platform called Paperclip. The bugs could allow attackers to take over developer machines, exposing a fundamental trust issue in how AI agents are designed and deployed.

A security patch has been released for a critical GStreamer vulnerability affecting Ubuntu 16.04 LTS. Malicious AVI files could allow attackers to crash systems or run arbitrary code, making this update crucial for teams managing legacy infrastructure.

A security flaw has been discovered in the Texmaker LaTeX editor. The vulnerability stems from how the application handles TIFF image files, allowing a malicious image to cause a denial of service, leak sensitive information, or permit remote code execution on a user's system.

A remote code execution vulnerability was found in the Papers reference management app on Ubuntu. Attackers can exploit it by tricking users into opening a malicious PDF file, potentially allowing them to run arbitrary code. The flaw stems from how the application handles specific PDF actions.

A security vulnerability has been discovered in the libcaca library. The flaw stems from incorrect handling of malformed files, which could allow an attacker to crash an application, causing a denial of service. In a worst-case scenario, this could lead to remote code execution.

A security researcher found a critical vulnerability on an official AMD website. AMD dismissed the report without a reward, stating the third-party software was out of scope, raising questions about corporate security responsibility.

A security vulnerability has been discovered in LibreOffice, a popular open-source office suite. Specially crafted OOXML documents with mismatched encryption parameters can cause the application to crash, leading to a denial of service, and could potentially allow an attacker to execute arbitrary code on a user's system.

A vulnerability in the ngtcp2 library, used for QUIC/HTTP/3, could allow remote code execution. The flaw involves writing data to a fixed-size buffer without checks. Exploitation requires a non-standard logging configuration (qlog) to be enabled, which reduces the immediate risk for most users.

A vulnerability has been found in Dnsmasq, a common network service for DNS and DHCP. When configured with a specific option, mishandled BOOTREPLY packets can allow a remote attacker to crash the service, causing a denial of service, or potentially execute arbitrary code on the system.

A critical vulnerability in the Everest Forms Pro WordPress plugin is being actively exploited by hackers. The flaw allows attackers to execute code remotely and completely take over websites running versions up to 1.9.12.

A critical remote code execution (RCE) vulnerability has been discovered in self-hosted Flowise deployments. Researchers found the flaw in the AI tool's Model Context Protocol implementation, and the official patch is reportedly easy to bypass, increasing the risk for users of the popular open-source platform.

A critical remote code execution vulnerability has been patched in Redis. The flaw, which went unnoticed for over two years, allows authenticated users to run arbitrary commands. It was discovered by an autonomous AI tool designed to find bugs in large codebases.

A critical, unpatched vulnerability has been found in Gogs, a popular self-hosted Git service. The flaw allows for argument injection, potentially leading to remote code execution. The lack of a patch highlights risks associated with some open-source projects with limited maintainer support.

A vulnerability in the widely used 'shell-quote' library could let attackers execute malicious code on servers. Teams should check their project dependencies and apply updates to prevent potential system takeovers or service disruptions.

Multiple critical security flaws have been found in CUPS, the printing system used by Linux and macOS. Attackers could remotely overwrite files or gain unauthorized access, making immediate patching essential for system security.

A critical remote code execution (RCE) vulnerability has been found in Apache Commons BeanUtils, a popular Java library. The flaw allows attackers to access a specific property in Java enum objects, potentially letting them run arbitrary code on affected systems, requiring immediate attention.

Google's Mandiant team has detailed a critical zero-day vulnerability in the KnowledgeDeliver Learning Management System. The flaw, caused by insecure deserialization, allows unauthenticated attackers to achieve remote code execution on affected servers. The LMS is widely used in Japan, making this a significant regional security issue.

Exploit code for a critical flaw in Cisco's Unified Communications Manager is now public. This allows unauthenticated attackers to gain full control of systems, creating an urgent need for IT teams to apply the available patch immediately.

A critical security flaw has been found in Gogs, a popular self-hosted Git service. The vulnerability, rated 9.4 on the CVSS scale, allows any authenticated user to execute arbitrary code on the server. The issue does not yet have an official CVE identifier.

Multiple critical vulnerabilities have been discovered in the popular Vim text editor. These flaws, found in the netrw plugin and the :find command completion, could allow an attacker to execute arbitrary commands on a user's system. Users are strongly urged to update their Vim installations immediately.

A critical remote code execution vulnerability has been found in Rclone, a popular file sync tool. The flaw, affecting recent Ubuntu LTS versions, stems from improper handling of its remote control API, which could also lead to sensitive information disclosure. Users are urged to update immediately.

Ubuntu has released security updates for Samba, a widely used file-sharing software. The patches address multiple critical vulnerabilities that could allow remote code execution, denial of service, or privilege escalation. All users are advised to update their systems immediately.

Critical vulnerabilities in Apache Tomcat could let attackers crash servers or even run their own code. The flaws affect how the popular web server handles certain web requests, putting many applications at risk of downtime.

A significant security vulnerability has been identified in XZ Utils, a common data compression utility. The flaw stems from improper memory management, which could allow an attacker to crash the software, causing a denial of service, or potentially execute arbitrary code on affected systems.

A critical flaw in `protobuf.js`, a JavaScript library with 50 million weekly downloads, could allow attackers to run code remotely. The vulnerability affects countless apps that use it as an indirect dependency in major cloud ecosystems.

A critical vulnerability (CVSS 10.0) in the LiteSpeed cPanel plugin is being actively exploited. The flaw, CVE-2026-48172, allows attackers to run arbitrary scripts with root privileges, posing a severe and urgent risk to web hosting environments using the popular plugin.

Microsoft has released its largest-ever security update, fixing 206 vulnerabilities. The patch addresses three publicly known zero-day flaws and dozens of critical bugs that could allow remote code execution, requiring immediate attention from IT teams.

A critical, unpatched security flaw in the popular AI development tool Langflow is being actively exploited. The vulnerability allows attackers to take control of servers, posing an urgent risk to companies using the open-source platform.

A critical vulnerability has been discovered in 'age', a popular file encryption tool. The flaw allows for arbitrary code execution if an attacker provides a specially crafted recipient or identity string. This is due to improper validation of plugin names, posing a significant security risk.

Two critical vulnerabilities have been found in the popular Vim text editor. These flaws could allow an attacker to run malicious code on your system by tricking you into opening a specially crafted file.

A critical vulnerability has been found in strongSwan, a popular open-source VPN. Attackers could exploit it remotely to crash systems or potentially run their own code, making immediate patching essential for all users.

Critical vulnerabilities have been found in the SEPPMail Secure E-Mail Gateway, an enterprise email security solution. Attackers could exploit these flaws to execute code remotely, read all email traffic passing through the appliance, and potentially gain access to the company's internal network, posing a significant security risk.

A vulnerability has been found in GStreamer Good Plugins due to improper handling of specific MOV/MP4 media files. A remote attacker could exploit this flaw to crash the application, leading to a denial of service, or potentially gain the ability to execute arbitrary code on the affected system.

Drupal has issued security updates for a highly critical vulnerability in its Core software, tracked as CVE-2026-9082. The flaw affects sites using a PostgreSQL database and could allow attackers to execute remote code, escalate privileges, or access sensitive information. Immediate patching is strongly recommended.

The SGLang AI framework has three critical vulnerabilities, including two for remote code execution. An attacker with network access can exploit them if the multimodal mode is enabled. The project maintainers have not responded, and no patch is currently available for these significant security flaws.

A critical security flaw in NGINX Plus and NGINX Open is being actively exploited in the wild, just days after it was disclosed. The vulnerability, CVE-2026-42945, is a heap buffer overflow affecting a wide range of NGINX versions from 0.6.27 through 1.30.0.

A recently published guide demonstrates how a vulnerability in SAR2HTML version 3.2.1 can be exploited for remote code execution. The walkthrough, based on a TryHackMe challenge, shows how attackers can gain root privileges and full control over a target system by leveraging this specific software flaw.