Robuta

Sponsor of the Day: Jerkmate
https://www.rapid7.com/blog/post/etr-cve-2025-37164-critical-unauthenticated-rce-affecting-hewlett-packard-enterprise-oneview/ CVE-2025-37164: Critical unauthenticated RCE affecting Hewlett Packard Enterprise OneView On December 17, 2025, Hewlett Packard Enterprise (HPE) published an advisory for CVE-2025-37164, a CVSS 10.0 vulnerability in HPE OneView. hewlett packard enterprisecve 2025critical unauthenticatedrceaffecting https://snowbit.io/security/mongobleed-cve-2025-14847-critical-unauthenticated-mongodb-memory-disclosure/ MongoBleed (CVE-2025-14847): Critical Unauthenticated MongoDB Memory Disclosure - Snowbit Dec 29, 2025 - The broadest, cloud-native cybersecurity offering available cve 2025 14847critical unauthenticatedmemory disclosuremongobleedmongodb https://www.rapid7.com/blog/post/etr-cve-2026-1731-critical-unauthenticated-remote-code-execution-rce-beyondtrust-remote-support-rs-privileged-remote-access-pra/ CVE-2026-1731: Critical Unauthenticated Remote Code Execution in BeyondTrust Remote Support (RS)... remote code executioncve 2026critical unauthenticatedsupport rs1731 https://www.rapid7.com/blog/post/etr-react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/ React2Shell, Critical unauthenticated RCE affecting React Server Components (CVE-2025-55182) CVE-2025-55182 is a critical unauthenticated remote code execution vulnerability affecting React, a very popular library for building modern web applications. react server componentscve 2025 55182critical unauthenticatedreact2shellrce https://thehackernews.com/2025/06/critical-rce-flaws-in-cisco-ise-and-ise.html Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access Cisco fixes CVE-2025-20281 and CVE-2025-20282 in ISE, ISE-PIC to prevent remote code execution. gain root accesscritical rcecisco iseflawspic https://www.aikido.dev/blog/n8n-rce-vulnerability-cve-2026-21858 n8n Critical Vulnerability (CVE-2026-21858) | Unauthenticated RCE Explained Jan 8, 2026 - A critical vulnerability in n8n (CVE-2026-21858) allows unauthenticated remote code execution on self-hosted instances. Learn who is affected and how to... vulnerability cve 2026unauthenticated rcen8ncritical21858 https://thehackernews.com/2026/03/citrix-urges-patching-critical.html Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks Citrix fixes CVE-2026-3055 memory flaw in NetScaler, enabling data leaks in SAML setups, raising risk of imminent exploitation. flaw allowingdata leakscitrixurgespatching https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE CVE-2026-32746 exposes telnetd via pre-auth flaw (CVSS 9.8), enabling root RCE through port 23, risking full system takeover. flaw cve 2026criticalunpatchedenablesunauthenticated https://securityonline.info/weaver-ecology-rce-vulnerability-cve-2026-22679/ Critical Zero-Day: Unauthenticated RCE Exploited in Weaver E-cology 10.0 Weaver E-cology 10.0 faces a critical 9.3 CVSS RCE (CVE-2026-22679). Unauthenticated attackers can hijack servers via a debug endpoint. Patch immediately! critical zerounauthenticated rce10 0dayexploited