Zimbra RCE Vulnerability Lets Remote Attackers Execute System Commands
An urgent alert regarding an actively exploited remote code execution vulnerability affecting the Zimbra Collaboration Suite, a widely used enterprise email ...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
497 articles found
An urgent alert regarding an actively exploited remote code execution vulnerability affecting the Zimbra Collaboration Suite, a widely used enterprise email ...
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remo...
The vulnerability, rated 9.4 under CVSS v4, was disclosed in November 2025 and allows attackers to exploit browsers like Firefox and Safari to achieve remote...
The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microso...
The U.S.
U.S.
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically desig...
The Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can har...
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to ...
View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string a...
View CSAF Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string a...
U.S.
UNISOC modem flaw enabled kernel-level code execution through video calls
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc mod...
A newly disclosed SQL injection vulnerability in GeoServer allows remote attackers to execute operating system commands on backend PostgreSQL hosts under hig...
Defused, a threat intelligence provider, reported exploitation attempts targeting CVE-2026-58231, a critical unauthenticated remote code execution vulnerabil...
ipTIME A3004T - Remote Code Execution
Joomla JCE_2.9.
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat in...
A newly disclosed, unpatched SQL injection vulnerability in GeoServer is currently being actively tested across the internet. Researchers have issued warning...