CVE-2026-16723: Critical RCE in Fastjson 1.x
A critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for Java, affecting versions 1.2.68 through 1.2.83. The flaw allows…
A critical remote code execution vulnerability in Alibaba's Fastjson 1.x JSON library for Java, affecting versions 1.2.68 through 1.2.83. The flaw allows…
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit for a remote code execution (RCE) vulnerability in self-managed…
CVE-2026-25243 is a Redis RCE vulnerability patched in May 2026. It is part of the same vulnerability family as the July 2026…
RedisBloom is a Redis module that provides probabilistic data structures like Bloom filters and TDigest. It was involved in the out-of-bounds write…
On July 23, 2026, Redis shipped seven security releases after researchers published authenticated remote code execution (RCE) proof-of-concept (PoC) exploits for stock…
A high-severity unauthenticated path traversal flaw in Windmill's get_log_file endpoint allows arbitrary file read. Exploitation can expose SUPERADMIN_SECRET leading to RCE. Patched…
A critical remote code execution vulnerability in Microsoft SharePoint Server, CVE-2026-50522 (CVSS 9.8), is being actively exploited in the wild following the…
A lightweight AI model fine-tuned to find, validate, and patch software vulnerabilities. In tests, it found 55 unique confirmed V8 issues and…
A critical unauthenticated remote code execution vulnerability has been discovered in WordPress core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.…
Marimo is a reactive notebook for Python. CVE-2026-39987 is a pre-auth RCE vulnerability in Marimo notebooks before version 0.23.0.