Sponsor of the Day:
Jerkmate
https://www.rapid7.com/blog/post/etr-cve-2025-37164-critical-unauthenticated-rce-affecting-hewlett-packard-enterprise-oneview/
CVE-2025-37164: Critical unauthenticated RCE affecting Hewlett Packard Enterprise OneView
On December 17, 2025, Hewlett Packard Enterprise (HPE) published an advisory for CVE-2025-37164, a CVSS 10.0 vulnerability in HPE OneView.
hewlett packard enterprisecve 2025critical unauthenticatedrceaffecting
https://www.die-welt.net/2025/02/unauthenticated-rce-in-grandstream-ht802v2-and-probably-others-using-gs_test_server-dhcp-vendor-option/
Unauthenticated RCE in Grandstream HT802V2 and probably others using gs_test_server DHCP vendor...
The Grandstream HT802V2 uses busybox' udhcpc for DHCP. When a DHCP event occurs, udhcpc calls a script (/usr/share/udhcpc/default.script by default) to further...
unauthenticated rceothers usingtest servergrandstreamprobably
https://www.aikido.dev/blog/n8n-rce-vulnerability-cve-2026-21858
n8n Critical Vulnerability (CVE-2026-21858) | Unauthenticated RCE Explained
Jan 8, 2026 - A critical vulnerability in n8n (CVE-2026-21858) allows unauthenticated remote code execution on self-hosted instances. Learn who is affected and how to...
vulnerability cve 2026unauthenticated rcen8ncritical21858
https://www.rapid7.com/blog/post/etr-react2shell-cve-2025-55182-critical-unauthenticated-rce-affecting-react-server-components/
React2Shell, Critical unauthenticated RCE affecting React Server Components (CVE-2025-55182)
CVE-2025-55182 is a critical unauthenticated remote code execution vulnerability affecting React, a very popular library for building modern web applications.
react server componentscve 2025 55182critical unauthenticatedreact2shellrce
https://securityonline.info/weaver-ecology-rce-vulnerability-cve-2026-22679/
Critical Zero-Day: Unauthenticated RCE Exploited in Weaver E-cology 10.0
Weaver E-cology 10.0 faces a critical 9.3 CVSS RCE (CVE-2026-22679). Unauthenticated attackers can hijack servers via a debug endpoint. Patch immediately!
critical zerounauthenticated rce10 0dayexploited
https://thehackernews.com/2025/06/critical-rce-flaws-in-cisco-ise-and-ise.html
Critical RCE Flaws in Cisco ISE and ISE-PIC Allow Unauthenticated Attackers to Gain Root Access
Cisco fixes CVE-2025-20281 and CVE-2025-20282 in ISE, ISE-PIC to prevent remote code execution.
gain root accesscritical rcecisco iseflawspic
https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html
Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE
CVE-2026-32746 exposes telnetd via pre-auth flaw (CVSS 9.8), enabling root RCE through port 23, risking full system takeover.
flaw cve 2026criticalunpatchedenablesunauthenticated