https://www.pillar.security/blog/prompt-injection-leads-to-rce-and-sandbox-escape-in-antigravity
Prompt Injection leads to RCE and Sandbox Escape in Antigravity
prompt injectionleadsrcesandboxescape
https://www.csoonline.com/article/4024887/cisco-warns-of-another-critical-rce-flaw-in-ise-urges-immediate-patching.html
Cisco warns of another critical RCE flaw in ISE, urges immediate patching | CSO Online
Jul 22, 2025 - The newly disclosed flaw affects a specific API that suffers from insufficient input validation to allow unauthenticated RCE at the root.
cso onlineciscowarnsanothercritical
https://rcenetwork.org/copyright/
copyright – Global RCE Network
global rce networkcopyright
https://gbhackers.com/apache-syncope-rce-vulnerability/
Apache Syncope RCE Vulnerability Detailed After Public Exploit Code Release
Apr 21, 2026 - A working proof-of-concept (PoC) exploit for CVE-2025-57738, a high-severity remote code execution (RCE) vulnerability in Apache Syncope.
apachesyncopercevulnerabilitydetailed
https://rcenetwork.org/portal/rces-worldwide
Page not found – Global RCE Network
page not foundglobal rce network
https://rcenetwork.org/news-and-story/4985-2/
14th Africa Regional RCE Meeting – Global RCE Network
global network14thafricaregionalrce
https://unu.edu/ias/global-rce-network
Global RCE Network | United Nations University
Fostering learning and action for a more sustainable world
global rce networkunited nations university
https://www.aikido.dev/blog/react-nextjs-cve-2025-55182-rce
Critical React & Next.js RCE Vulnerability CVE-2025-55182 Fix Guide
Dec 5, 2025 - Learn how CVE-2025-55182 and the related Next.js RCE affect React Server Components. See impact, affected versions, and how to fix. Aikido now detects both...
next jscriticalreactrcevulnerability
https://securityonline.info/rclone-rce-vulnerability-poc-disclosure-cve/
Rclone Critical Vulnerability Alert: Public PoC Released for Administrative Auth Bypass and RCE
Apr 20, 2026 - Technical details and PoC for Rclone’s critical 9.2 CVSS vulnerabilities (CVE-2026-41176/41179) are now public. Patch to version 1.73.5 to prevent RCE.
rclonecriticalvulnerabilityalertpublic
https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/
Thirty-Six Malicious npm Strapi Packages Deploy Redis RCE, Database Theft, and Persistent C2 -...
A coordinated campaign of thirty-six malicious npm packages published by four sock-puppet accounts (umarbek1233, kekylf12, tikeqemif26, and umar_bektembiev1)...
sixnpmstrapipackagesdeploy
https://www.still.de/fahrzeuge/gabelstapler-und-lagertechnik/elektro-stapler/rce-25-35.html
RCE 25-35 Elektrostapler | STILL Deutschland
Wenn ein Job ansteht: Der neue Elektrostapler RCE ist bereit – stark, robust und effizient. Ihr zuverlässiger Helfer, genau wenn Sie ihn brauchen.
rcestilldeutschland
https://www.haproxy.com/blog/cve-2024-6387
July 2024 – CVE-2024-6387: RCE in OpenSSH server
Jul 8, 2024 - The latest versions of our products fix a vulnerability related to OpenSSH’s server (sshd), which is used in the public/private cloud images of HAProxy Enter...
july 2024cverceopensshserver
https://www.csoonline.com/article/4161382/prompt-injection-turned-googles-antigravity-file-search-into-rce.html
Prompt injection turned Google’s Antigravity file search into RCE | CSO Online
Apr 21, 2026 - A prompt injection flaw in Google’s Antigravity IDE turns a file search tool into a remote code execution vector, bypassing Secure Mode protections.
prompt injectionfile searchcso onlineturnedantigravity
https://balintmagyar.com/articles/google-web-designer-css-injection-client-rce
Client-side RCE via CSS Injection in Google Web Designer for Windows — Bálint Magyar
Fixed in version 16.4.0.0711 — $3,500 bug bounty
web designerfor windowsclientsiderce
https://rcenetwork.org/events/
Events – Global RCE Network
global rce networkevents
https://detection.fyi/sigmahq/sigma/emerging-threats/2020/exploits/cve-2020-1350/proc_creation_win_exploit_cve_2020_1350/
DNS RCE CVE-2020-1350 | Detection.FYI
Detects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
dnsrcecvedetectionfyi
https://foxtrotlabs.cc/tags/rce/
rce :: Foxtrotlabs — In the middle of somewhere
in thercemiddlesomewhere
https://www.aikido.dev/blog/n8n-rce-vulnerability-cve-2026-21858
n8n Critical Vulnerability (CVE-2026-21858) | Unauthenticated RCE Explained
Jan 8, 2026 - A critical vulnerability in n8n (CVE-2026-21858) allows unauthenticated remote code execution on self-hosted instances. Learn who is affected and how to...
n8ncriticalvulnerabilitycverce
https://www.picussecurity.com/resource/blog/react-flight-protocol-rce-vulnerability-cve-2025-55182-and-cve-2025-66478-explained
React2Shell RCE Vulnerability: CVE-2025-55182 and CVE-2025-66478 Explained
Dec 7, 2025 - Learn how the React CVE-2025-55182 and Next.js CVE-2025-66478 vulnerabilities work. Picus explains in detail how attackers exploit deserialization to achieve...
rcevulnerabilitycveexplained
https://www.nar.realtor/education/designations-and-certifications/realtor-association-certified-executive-rce
REALTOR® Association Certified Executive (RCE) |
The REALTOR® Association Certified Executive (RCE) is the only professional designation designed specifically for REALTOR® association executives.
associationcertifiedexecutiverce
https://osec.io/blog/2026-04-01-patch-gap-to-mobile-renderer-rce/
Patch Gap to Mobile Renderer RCE: Pwning Samsung Internet's V8 on the Galaxy S25
Samsung Internet on the Galaxy S25 shipped a six-month-old version of V8, exposing it to publicly known bugs. Learn how we exploited a bytecode interpreter...
samsung interneton thegalaxy s25patchgap
https://thehackernews.com/2026/04/threatsday-bulletin-17-year-old-excel.html
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More...
0 daybrute forceyear oldbulletindefender
https://rcenetwork.org/privacy-statement/
Privacy Statement – Global RCE Network
global rce networkprivacy statement
https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/
Attacking SSL VPN - Part 3: The Golden Pulse Secure SSL VPN RCE Chain, with Twitter as Case Study!...
7 vulnerabilities in Pulse Secure SSL VPN: CVE-2019-11510, CVE-2019-11542, CVE-2019-11539, CVE-2019-11538, CVE-2019-11508, CVE-2019-11540, CVE-2019-11507
ssl vpnpart 3pulse securewith twittercase study
https://events.rceevent.de/region/
RCE-Event Veranstaltungen | Veranstaltungen in der Region
Veranstaltungen in der Region - Konzerte, Ausstellungen, Musical, Theater, Lesungen, Flohmarkt etc. Diese Veranstaltungen in der Region dürfen Sie auf keinen...
in der regionrceeventveranstaltungen
https://rcenetwork.org/people/
People – Global RCE Network
global rce networkpeople
https://www.rcesecurity.com/
RCE Security | Penetration Tests. Source Code Reviews. IT Security Audits.
RCE Security provides penetration testing, source code reviews, bug bounty support, and offensive security services for web, mobile, APIs, and infrastructure.
source code reviewspenetration testssecurityaudits
https://www.computerweekly.com/news/366638837/SolarWinds-RCE-bug-makes-Cisa-list-as-exploitation-spreads
SolarWinds RCE bug makes Cisa list as exploitation spreads | Computer Weekly
Exploitation of CVE-2025-40551, an RCE flaw affecting SolarWinds Web Help Desk, appears to be spreading, with defenders on high alert.
computer weeklysolarwindsrcebugmakes
https://www.csoonline.com/article/4035274/researchers-uncover-rce-attack-chains-in-popular-enterprise-credential-vaults.html
Researchers uncover RCE attack chains in popular enterprise credential vaults | CSO Online
Aug 11, 2025 - Open-source credential management systems HashiCorp Vault and CyberArk Conjur had flaws enabled remote code execution among other attacks.
cso onlineresearchersuncoverrceattack
https://www.csoonline.com/article/4113980/critical-rce-flaw-allows-full-takeover-of-n8n-ai-workflow-platform.html
Critical RCE flaw allows full takeover of n8n AI workflow platform | CSO Online
Jan 7, 2026 - ‘A compromised n8n instance doesn’t just mean losing one system — it means handing attackers the keys to everything,’ security researchers wrote of the 10.0...
ai workflowcso onlinecriticalrceallows
https://www.rcesecurity.com/security-advisories/
Security Advisories | RCE Security
security advisoriesrce
https://blog.securelayer7.net/popojicms-2-0-1-rce-vulnerability-exposes-remote-command-execution-risks/
PopojiCMS 2.0.1 RCE Vulnerability: Remote Command Risks
Aug 23, 2024 - Analyze the RCE vulnerability in PopojiCMS 2.0.1 and its remote command execution risks. Discover mitigation strategies and secure your system with SecureLayer7
2 0rcevulnerabilityremotecommand
https://archive.rcenetwork.org/rce-bulletin
| RCE NETWORK
rcenetwork
https://social.ozymandias.club/c/cybersecurity/p/126368/flaw-in-microsoft-owned-github-repository-allowed-rce-via-issue-submission-new
Flaw in Microsoft-owned GitHub repository allowed RCE via issue submission | news | SC Media
I met a traveller from an antique land, Who said—“Two vast and trunkless legs of stone Stand in the desert. . . . Near them, on the sand, Half sunk a shattered...
github repositorymicrosoftownedallowedrce
https://rcenetwork.org/news-stories/
News & Stories – Global RCE Network
global rce networknews stories
https://thehackernews.com/2026/04/anthropic-mcp-design-vulnerability.html
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
MCP design flaw enables RCE across 7,000+ servers and 150M downloads, impacting AI SDKs and supply chains.
supply chainanthropicmcpdesignvulnerability
https://7asecurity.com/free-workshop-desktop-apps/b
Hacking Modern Desktop apps with XSS and RCE | Blog
Free course or pentest? Join our desktop app hacking workshop with RCE and XSS techniques | Blog. Learn more from 7ASecurity now.
desktop appshackingmodernxssrce
https://www.csoonline.com/article/4152658/5-month-old-f5-big-ip-dos-bug-becomes-critical-rce-exploited-in-the-wild.html
5-month-old F5 BIG-IP DoS bug becomes critical RCE exploited in the wild | CSO Online
Mar 31, 2026 - Reclassified as a remote code execution flaw, the F5 BIG-IP APM vulnerability has been upgraded to CVSS 9.8, requiring immediate patching and compromise...
in the wildcso onlinemontholdf5
https://www.theregister.com/2026/04/15/critical_fortinet_sandbox_bugs/
Critical Fortinet sandbox bugs allow auth bypass and RCE • The Register
Apr 15, 2026 - : No reports of active exploitation (yet)
the registercriticalfortinetsandboxbugs
https://zeropath.com/blog/spinnaker-rce-production-compromise
Critical Spinnaker Vulns Allow RCE And Production Compromise - ZeroPath Blog | ZeroPath
ZeroPath Research discovered two separate RCE vulnerabilities in Spinnaker (CVE-2026-32604 and CVE-2026-32613) that let low-privilege authenticated users...
criticalspinnakervulnsallowrce
https://www.aikido.dev/blog/storybooks-websockets-attack
Persistent XSS/RCE using WebSockets in Storybook (CVE-2026-27148)
Mar 6, 2026 - CVE-2026-27148 exposes a WebSocket hijacking flaw in Storybook that can escalate into supply chain compromise. Learn the attack path, impact, and how to...
using websocketspersistentxssrcestorybook
https://perfektblue.pcacybersecurity.com/
PerfektBlue – 1-Click RCE in Bluetooth
PCA Team uncovered critical over-the-air attack chain, enabling 1-click Remote Code Execution (RCE) in vulnerable devices. Affected manufacturers include...
rcebluetooth
https://www.csoonline.com/article/4157146/claude-uncovers-a-13%E2%80%91year%E2%80%91old-activemq-rce-bug-within-minutes.html
Claude uncovers a 13‑year‑old ActiveMQ RCE bug within minutes | CSO Online
Apr 10, 2026 - The decade-old ActiveMQ flaw was uncovered and weaponized in minutes, showing AI’s exploit-building potential amid the Mythos hype.
cso onlineclaudeactivemqrcebug
https://sekurak.pl/tag/rce/
rce - Sekurak
rcesekurak
https://www.theregister.com/2025/05/21/ivanti_rce_attacks_ongoing/
Ivanti RCE attacks 'ongoing,' exploitation hits clouds • The Register
May 21, 2025 - : Nothing like insecure code in security suites
the registerivantirceattacksongoing
https://www.computerweekly.com/news/366638863/Researchers-delve-inside-new-SolarWinds-RCE-attack-chain
Researchers delve inside new SolarWinds RCE attack chain | Computer Weekly
Researchers at Huntress and Microsoft have shared findings from their analysis of a new SolarWinds Web Help Desk vulnerability.
computer weeklyresearchersdelveinsidenew
https://7asecurity.com/free-workshop-web-apps/b
Hacking Modern Web apps with RCE and Prototype Pollution | Blog
Register free to learn RCE and prototype pollution attacks on modern web apps with live demos. |Blog| Learn more from 7ASecurity now.
modern webhackingappsrceprototype
https://rcenetwork.org/
Global RCE Network
global rce network
https://browsehappy.pl/bezpieczenstwo/co-to-jest-atak-rce-remote-code-execution-i-jak-sie-przed-nim-bronic/
Co to jest atak RCE (Remote Code Execution) i jak się przed nim bronić?
Apr 28, 2026 - Atak RCE (Remote Code Execution) to krytyczna podatność bezpieczeństwa, w której haker zdalnie uruchamia złośliwe polecenia na serwerze lub komputerze ofiary...
remote code executionjestatakrcejak
https://docs.escape.tech/documentation/reference/vulnerabilities/react2shell_2/
React2Shell CVE-2025-55182 - Javascript RCE - Escape Documentation
cvejavascriptrceescapedocumentation
https://www.fastly.com/blog/fastlys-proactive-protection-critical-react-rce-cve-2025-55182
React2Shell RCE (CVE-2025-55182) Protection | Fastly
Apr 1, 2026 - Protect your apps from the critical React RCE bugs (CVE-2025-55182/66478). Fastly's NGWAF Virtual Patch provides proactive defense.
rcecveprotectionfastly
https://www.rce.de/datenschutz/
Datenschutz Übersicht - rce.de - RCE Medien
datenschutzrcedemedien
https://www.csoonline.com/article/4159889/rce-by-design-mcp-architectural-choice-haunts-ai-agent-ecosystem.html
RCE by design: MCP architectural choice haunts AI agent ecosystem | CSO Online
Apr 16, 2026 - Unsafe defaults in MCP configs open servers to possible remote code execution, as evidenced by several commercial services and open-source projects.
by designai agentcso onlinercemcp
https://unu.edu/ias/announcement/open-call-host-2026-rce-regional-meetings
Open Call to Host 2026 RCE Regional Meetings | United Nations University
Mar 6, 2026 - The deadline for submissions is 8 April 2026.
united nations universityopen callregional meetingshostrce
https://jgkamat.gitlab.io/blog/next-rce.html
Next Browser RCE
nextbrowserrce
https://exploitnotes.org/exploit/web/php-rce-cheat-sheet
PHP RCE Cheat Sheet - Exploit Notes
A security research site.
cheat sheetphprceexploitnotes
https://archive.rcenetwork.org/
RCE NETWORK |
rcenetwork